最新预警列表

HIGH NVD Recent 2026-07-21

CVE-2026-32824:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authentica

MEDIUM NVD Recent 2026-07-21

CVE-2026-32823:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes ser

HIGH NVD Recent 2026-07-21

CVE-2026-32821:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user

HIGH NVD Recent 2026-07-21

CVE-2026-32820:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and stati

MEDIUM NVD Recent 2026-07-21

CVE-2026-32819:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumera

HIGH NVD Recent 2026-07-21

CVE-2026-32806:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can

LOW NVD Recent 2026-07-21

CVE-2026-10755:The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

MEDIUM NVD Recent 2026-07-21

CVE-2026-10724:The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages tha

HIGH NVD Recent 2026-07-21

CVE-2026-10081:The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malici

MEDIUM NVD Recent 2026-07-21

CVE-2026-24232:NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

MEDIUM NVD Recent 2026-07-21

CVE-2026-16108:A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm

MEDIUM NVD Recent 2026-07-21

CVE-2026-1562:Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

MEDIUM NVD Recent 2026-07-21

CVE-2026-1563:Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u

Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

CRITICAL CERT/CC VU 2026-07-21

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other works

MEDIUM NVD Recent 2026-07-21

CVE-2026-16103:A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handler but were omitte

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。