最新预警列表

MEDIUM CISA KEV 2026-07-22

CVE-2026-50522:Microsoft Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

HIGH CISA KEV 2026-07-22

CVE-2026-16232:Check Point Check Point SmartConsole Improper Authentication Vulnerability

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CRITICAL NVD Recent 2026-07-21

CVE-2026-35048:The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it chec

MEDIUM NVD Recent 2026-07-21

CVE-2026-45138:CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` v

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator passe

HIGH NVD Recent 2026-07-21

CVE-2026-32825:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unl

HIGH NVD Recent 2026-07-21

CVE-2026-32824:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authentica

MEDIUM NVD Recent 2026-07-21

CVE-2026-32823:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes ser

HIGH NVD Recent 2026-07-21

CVE-2026-32821:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user

HIGH NVD Recent 2026-07-21

CVE-2026-32820:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and stati

MEDIUM NVD Recent 2026-07-21

CVE-2026-32819:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumera

HIGH NVD Recent 2026-07-21

CVE-2026-32806:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can

LOW NVD Recent 2026-07-21

CVE-2026-10755:The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

MEDIUM NVD Recent 2026-07-21

CVE-2026-10724:The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages tha

HIGH NVD Recent 2026-07-21

CVE-2026-10081:The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malici

MEDIUM NVD Recent 2026-07-21

CVE-2026-24232:NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。