最新预警列表

HIGH NVD Recent 2026-09-05

CVE-2026-81773:Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

MEDIUM NVD Recent 2026-09-05

CVE-2026-81281:Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

HIGH NVD Recent 2026-09-04

CVE-2026-52022:An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registr

An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components

HIGH NVD Recent 2026-09-04

CVE-2026-58566:Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentiall

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

HIGH NVD Recent 2026-09-04

CVE-2026-81776:Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

MEDIUM NVD Recent 2026-09-04

CVE-2026-81282:Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

HIGH CISA KEV 2026-09-04

CVE-2026-85046:Google Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not

HIGH NVD Recent 2026-09-03

CVE-2026-84752:Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-84736:In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federato

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environm

MEDIUM NVD Recent 2026-09-03

CVE-2026-84215:Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-81300:Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-81292:Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

HIGH NVD Recent 2026-09-03

CVE-2020-15878:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.

HIGH NVD Recent 2026-09-03

CVE-2020-15876:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address

HIGH NVD Recent 2026-09-03

CVE-2020-15874:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary s

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。