最新预警列表

HIGH NVD Recent 2026-09-08

CVE-2026-13297:IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

MEDIUM NVD Recent 2026-09-08

CVE-2026-16693:IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

MEDIUM NVD Recent 2026-09-08

CVE-2026-16892:IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.

MEDIUM NVD Recent 2026-09-08

CVE-2026-17207:IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.

MEDIUM NVD Recent 2026-09-08

CVE-2026-86481:In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

CRITICAL CERT/CC VU 2026-09-08

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

Overview The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI

MEDIUM CERT/CC VU 2026-09-08

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

Overview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirma

HIGH NVD Recent 2026-09-08

CVE-2026-16233:There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerabi

MEDIUM NVD Recent 2026-09-08

CVE-2026-18445:There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This

There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a

MEDIUM NVD Recent 2026-09-08

CVE-2026-18444:There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered

There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW.  This may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to

HIGH NVD Recent 2026-09-08

CVE-2026-16234:There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerabi

CRITICAL CERT/CC VU 2026-09-08

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before init

MEDIUM NVD Recent 2026-09-08

CVE-2026-14350:IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

HIGH Cisco PSIRT 2026-09-08

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible. This vulnerability is due t

MEDIUM CISA KEV 2026-09-08

CVE-2026-85880:Microsoft Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。