最新预警列表

MEDIUM NVD Recent 2026-07-23

CVE-2026-57848:Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the devic

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent.extra.STREAM ex

CRITICAL CERT-EU 2026-07-23

2026-009: Critical Vulnerabilities in Microsoft SharePoint

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed

HIGH NVD Recent 2026-07-22

CVE-2026-42566:Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The

MEDIUM NVD Recent 2026-07-22

CVE-2026-7328:Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverifie

MEDIUM NVD Recent 2026-07-22

CVE-2026-16454:In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allows an authenticated device to escalate its permissions a

HIGH NVD Recent 2026-07-22

CVE-2026-15829:A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecastin

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_c

HIGH NVD Recent 2026-07-22

CVE-2026-15432:When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a

MEDIUM NVD Recent 2026-07-22

CVE-2026-53364:In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 without freeing it when neither pa_sync_term

CRITICAL CERT/CC VU 2026-07-22

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability

Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execut

LOW NVD Recent 2026-07-22

CVE-2026-16451:A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipu

MEDIUM NVD Recent 2026-07-22

CVE-2026-34346:Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

MEDIUM NVD Recent 2026-07-22

CVE-2026-34328:Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

MEDIUM NVD Recent 2026-07-22

CVE-2026-33842:Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

MEDIUM NVD Recent 2026-07-22

CVE-2026-16152:A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of th

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out

LOW NVD Recent 2026-07-22

CVE-2026-16129:A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction

A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to inco

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。