最新预警列表

MEDIUM NVD Recent 2026-07-21

CVE-2026-16108:A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm

MEDIUM NVD Recent 2026-07-21

CVE-2026-1562:Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

MEDIUM NVD Recent 2026-07-21

CVE-2026-1563:Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

CRITICAL CERT/CC VU 2026-07-21

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other works

MEDIUM NVD Recent 2026-07-21

CVE-2026-16103:A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitte

LOW NVD Recent 2026-07-21

CVE-2026-16131:A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remote

MEDIUM NVD Recent 2026-07-21

CVE-2026-16093:Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client cre

MEDIUM CISA KEV 2026-07-21

CVE-2021-27137:DD-WRT DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

HIGH CISA KEV 2026-07-21

CVE-2026-0770:Langflow Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

HIGH CISA KEV 2026-07-21

CVE-2026-63030:WordPress WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

HIGH CISA KEV 2026-07-21

CVE-2026-60137:WordPress WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordP

MEDIUM NVD Recent 2026-07-20

CVE-2026-12724:The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into

MEDIUM NVD Recent 2026-07-20

CVE-2026-12723:The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identi

HIGH NVD Recent 2026-07-20

CVE-2026-12592:The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the

MEDIUM NVD Recent 2026-07-20

CVE-2026-11868:The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。