最新预警列表

HIGH NVD Recent 2026-07-24

CVE-2026-15724:In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or

HIGH NVD Recent 2026-07-23

CVE-2026-65759:Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulat

HIGH NVD Recent 2026-07-23

CVE-2026-44909:Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate

Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing

HIGH NVD Recent 2026-07-23

CVE-2026-65695:Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended workin

HIGH NVD Recent 2026-07-23

CVE-2026-47743:Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent mode

HIGH NVD Recent 2026-07-23

CVE-2026-12484:A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)`

HIGH NVD Recent 2026-07-23

CVE-2026-12228:A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (l

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side sanitizatio

HIGH NVD Recent 2026-07-23

CVE-2026-33327:libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. Thi

HIGH NVD Recent 2026-07-23

CVE-2026-65013:Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures includ

HIGH NVD Recent 2026-07-22

CVE-2026-42566:Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The

HIGH NVD Recent 2026-07-22

CVE-2026-15829:A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecastin

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_c

HIGH NVD Recent 2026-07-22

CVE-2026-15432:When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a

HIGH NVD Recent 2026-07-21

CVE-2026-32825:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unl

HIGH NVD Recent 2026-07-21

CVE-2026-32824:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authentica

HIGH NVD Recent 2026-07-21

CVE-2026-32821:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。