最新预警列表

HIGH NVD Recent 2026-07-14

CVE-2026-58281:Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ove

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

HIGH NVD Recent 2026-07-14

CVE-2026-53657:Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, whic

LOW NVD Recent 2026-07-14

CVE-2026-15191:A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettl

A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can

LOW NVD Recent 2026-07-13

CVE-2026-15477:A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /op

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injecti

LOW NVD Recent 2026-07-13

CVE-2026-15471:A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci

A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploi

CRITICAL NVD Recent 2026-07-13

CVE-2026-61462:mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended

HIGH NVD Recent 2026-07-13

CVE-2026-61463:Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with

LOW NVD Recent 2026-07-13

CVE-2026-15472:A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. T

LOW NVD Recent 2026-07-13

CVE-2026-15470:A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona

A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploi

LOW NVD Recent 2026-07-13

CVE-2026-15377:A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown fun

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The

LOW NVD Recent 2026-07-13

CVE-2026-15376:A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been

LOW NVD Recent 2026-07-13

CVE-2026-15510:A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. T

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could

LOW NVD Recent 2026-07-13

CVE-2026-15508:A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file

A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. Executing a manipulation of the argument extracted_path_an

LOW NVD Recent 2026-07-13

CVE-2026-15478:A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports

A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to s

LOW NVD Recent 2026-07-13

CVE-2026-15476:A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in

A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be p

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。