最新预警列表

LOW NVD Recent 2026-07-21

CVE-2026-16131:A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remote

MEDIUM NVD Recent 2026-07-21

CVE-2026-16093:Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client cre

MEDIUM CISA KEV 2026-07-21

CVE-2021-27137:DD-WRT DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

HIGH CISA KEV 2026-07-21

CVE-2026-0770:Langflow Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

HIGH CISA KEV 2026-07-21

CVE-2026-63030:WordPress WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

HIGH CISA KEV 2026-07-21

CVE-2026-60137:WordPress WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordP

MEDIUM NVD Recent 2026-07-20

CVE-2026-12724:The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into

MEDIUM NVD Recent 2026-07-20

CVE-2026-12723:The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identi

HIGH NVD Recent 2026-07-20

CVE-2026-12592:The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the

MEDIUM NVD Recent 2026-07-20

CVE-2026-11868:The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.

HIGH NVD Recent 2026-07-20

CVE-2026-11349:The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated

LOW NVD Recent 2026-07-20

CVE-2026-16133:A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spaw

A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires

MEDIUM NVD Recent 2026-07-20

CVE-2026-16312:Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

MEDIUM NVD Recent 2026-07-20

CVE-2026-16154:A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerabi

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. Th

LOW NVD Recent 2026-07-20

CVE-2026-16130:A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of th

A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local access is required

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。