最新预警列表

MEDIUM NVD Recent 2026-07-23

CVE-2026-65696:Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId

CRITICAL CERT/CC VU 2026-07-23

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can tri

MEDIUM NVD Recent 2026-07-23

CVE-2026-65012:InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo

InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary serv

MEDIUM NVD Recent 2026-07-23

CVE-2026-33328:libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.1

libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.

HIGH NVD Recent 2026-07-23

CVE-2026-33327:libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. Thi

MEDIUM NVD Recent 2026-07-23

CVE-2026-35217:NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the fi

NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malformed packet and install the subscription into internal br

CRITICAL CERT/CC VU 2026-07-23

VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA

MEDIUM NVD Recent 2026-07-23

CVE-2026-15342:Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID.

MEDIUM NVD Recent 2026-07-23

CVE-2026-65011:Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de

Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdef

HIGH NVD Recent 2026-07-23

CVE-2026-65013:Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows a

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures includ

MEDIUM NVD Recent 2026-07-23

CVE-2026-57848:Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the devic

Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent.extra.STREAM ex

CRITICAL CERT-EU 2026-07-23

2026-009: Critical Vulnerabilities in Microsoft SharePoint

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed

HIGH NVD Recent 2026-07-22

CVE-2026-42566:Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The

MEDIUM NVD Recent 2026-07-22

CVE-2026-7328:Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverifie

MEDIUM NVD Recent 2026-07-22

CVE-2026-16454:In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allows an authenticated device to escalate its permissions a

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。