最新预警列表

HIGH openEuler 安全公告 OSV 2026-07-24

CVE-2026-13221:perl security update

perl security update

MEDIUM openEuler 安全公告 OSV 2026-07-24

CVE-2025-68146:python-filelock security update

python-filelock security update

CRITICAL openEuler 安全公告 OSV 2026-07-24

CVE-2026-54059:python-pillow security update

python-pillow security update

MEDIUM openEuler 安全公告 OSV 2026-07-24

CVE-2026-58010:glib2 security update

glib2 security update

CRITICAL openEuler 安全公告 OSV 2026-07-24

CVE-2025-70067:assimp security update

assimp security update

CRITICAL NVD Recent 2026-07-23

CVE-2026-65761:Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and s

CRITICAL NVD Recent 2026-07-23

CVE-2026-65760:Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

HIGH NVD Recent 2026-07-23

CVE-2026-65759:Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulat

HIGH NVD Recent 2026-07-23

CVE-2026-44909:Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate

Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing

MEDIUM NVD Recent 2026-07-23

CVE-2026-65697:Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Pages dashboard by supplying a crafted hostname and pathname

HIGH NVD Recent 2026-07-23

CVE-2026-65695:Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended workin

HIGH NVD Recent 2026-07-23

CVE-2026-47743:Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent mode

MEDIUM NVD Recent 2026-07-23

CVE-2025-68640:The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T

The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownershi

HIGH NVD Recent 2026-07-23

CVE-2026-12484:A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)`

HIGH NVD Recent 2026-07-23

CVE-2026-12228:A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (l

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side sanitizatio

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。