最新预警列表

MEDIUM CISA KEV 2026-09-11

CVE-2026-42018:JFrog JFrog Artifactory Improper Authentication Vulnerability

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

MEDIUM CISA KEV 2026-09-11

CVE-2026-42016:JFrog JFrog Artifactory Incorrect Authorization Vulnerability

JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

HIGH CISA KEV 2026-09-11

CVE-2026-84869:ConnectWise ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.

MEDIUM NVD Recent 2026-09-10

CVE-2026-16941:IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper au

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

MEDIUM NVD Recent 2026-09-10

CVE-2026-16660:IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bound

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

HIGH NVD Recent 2026-09-10

CVE-2026-73699:FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arb

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used i

HIGH NVD Recent 2026-09-10

CVE-2026-73693:FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authen

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attacke

MEDIUM NVD Recent 2026-09-10

CVE-2026-52097:An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (u

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

CRITICAL NVD Recent 2026-09-10

CVE-2026-88044:rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/ser

HIGH NVD Recent 2026-09-10

CVE-2026-85228:An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of

CRITICAL NVD Recent 2026-09-10

CVE-2026-68488:A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privileg

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

CRITICAL NVD Recent 2026-09-10

CVE-2026-68487:Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

CRITICAL NVD Recent 2026-09-10

CVE-2026-65639:OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who contro

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The

CRITICAL NVD Recent 2026-09-10

CVE-2026-65638:Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to exe

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software ori

MEDIUM NVD Recent 2026-09-10

CVE-2026-82465:pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.val

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allowing an unauthentic

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。