最新预警列表

LOW NVD Recent 2026-08-12

CVE-2026-18581:A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th

A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead t

CRITICAL NVD Recent 2026-08-12

CVE-2026-8457:The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without

HIGH NVD Recent 2026-08-12

CVE-2026-18352:The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary

HIGH NVD Recent 2026-08-12

CVE-2026-13339:The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary f

MEDIUM CERT/CC VU 2026-08-12

VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An

HIGH Cisco PSIRT 2026-08-12

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate

CRITICAL Cisco PSIRT 2026-08-12

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple i

CRITICAL CERT/CC VU 2026-08-11

VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure

Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. U

MEDIUM Cisco PSIRT 2026-08-11

Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of ne

HIGH CISA KEV 2026-08-11

CVE-2026-72898:Metabase Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change

MEDIUM CISA KEV 2026-08-11

CVE-2026-68820:Microsoft Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

HIGH CISA KEV 2026-08-11

CVE-2026-20349:Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial

MEDIUM NVD Recent 2026-08-10

CVE-2026-21662:Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34490:Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34495:Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。