最新预警列表

LOW NVD Recent 2026-08-26

CVE-2026-55984:Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

CRITICAL NVD Recent 2026-08-26

CVE-2026-55982:OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

HIGH NVD Recent 2026-08-26

CVE-2026-54481:Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

MEDIUM NVD Recent 2026-08-26

CVE-2026-50105:RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

MEDIUM NVD Recent 2026-08-26

CVE-2026-42931:Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

HIGH NVD Recent 2026-08-26

CVE-2026-24791:Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

MEDIUM NVD Recent 2026-08-26

CVE-2026-24059:The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request.

LOW NVD Recent 2026-08-26

CVE-2026-23603:Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

CRITICAL NVD Recent 2026-08-26

CVE-2026-78183:DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infini

LOW NVD Recent 2026-08-26

CVE-2026-19565:Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, each over a fresh Time::HiRes reading format

MEDIUM NVD Recent 2026-08-26

CVE-2026-75922:Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has beco

CRITICAL NVD Recent 2026-08-26

CVE-2026-13051:Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTM

HIGH NVD Recent 2026-08-26

CVE-2026-13048:Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by ap

CRITICAL NVD Recent 2026-08-26

CVE-2022-4993:HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_e

HIGH NVD Recent 2026-08-25

CVE-2026-0551:The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。