最新预警列表

CRITICAL CERT/CC VU 2026-07-06

VU#226679: Microsoft WinRE allows for bypass of UEFI/BIOS password enforcement

Overview Microsoft Windows Recovery Environment (WinRE) provides a mechanism for recovering and repairing Windows systems using an alternate boot environment. Under certain platform implementations, access to WinRE may allow an attacker to bypass firmware

CRITICAL CERT/CC VU 2026-07-06

VU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability

Overview HP Printers in the Deskjet 2800 Series running firmware version

CRITICAL NVD Recent 2026-07-06

CVE-2026-52955:In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algori

CRITICAL NVD Recent 2026-07-06

CVE-2026-44935:Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-56209:aom security update

aom security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-53466:ImageMagick security update

ImageMagick security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-12087:perl security update

perl security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-54273:python-aiohttp security update

python-aiohttp security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-48487:python-zeroconf security update

python-zeroconf security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-2923:gstreamer1-plugins-bad-free security update

gstreamer1-plugins-bad-free security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-42055:nginx security update

nginx security update

CRITICAL NVD Recent 2026-07-02

CVE-2022-50973:Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and f

CRITICAL NVD Recent 2026-07-02

CVE-2024-14037:Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with

CRITICAL CERT/CC VU 2026-07-02

VU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat

Overview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attack

CRITICAL NVD Recent 2026-07-01

CVE-2026-11720:A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。