最新预警列表

CRITICAL NVD Recent 2026-07-10

CVE-2026-51597:MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat

MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new co

CRITICAL CERT/CC VU 2026-07-10

VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs

Overview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlle

CRITICAL NVD Recent 2026-07-09

CVE-2026-48316:ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scop

CRITICAL CERT/CC VU 2026-07-09

VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities

Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is availab

CRITICAL NVD Recent 2026-07-09

CVE-2026-13019:Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CRITICAL openEuler 安全公告 OSV 2026-07-09

CVE-2026-49432:activemq security update

activemq security update

CRITICAL openEuler 安全公告 OSV 2026-07-09

CVE-2026-14164:libarchive security update

libarchive security update

CRITICAL openEuler 安全公告 OSV 2026-07-09

CVE-2026-14164:libarchive security update

libarchive security update

CRITICAL CERT/CC VU 2026-07-09

VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE

Overview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory

CRITICAL NVD Recent 2026-07-08

CVE-2026-12481:A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard

CRITICAL CERT/CC VU 2026-07-08

VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls

Overview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo applica

CRITICAL Cisco PSIRT 2026-07-08

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is

CRITICAL NVD Recent 2026-07-07

CVE-2026-40139:A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized a

CRITICAL NVD Recent 2026-07-07

CVE-2026-40138:A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and

CRITICAL NVD Recent 2026-07-06

CVE-2026-48614:An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。