最新预警列表

HIGH CISA KEV 2026-07-22

CVE-2026-16232:Check Point Check Point SmartConsole Improper Authentication Vulnerability

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

HIGH NVD Recent 2026-07-21

CVE-2026-32825:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unl

HIGH NVD Recent 2026-07-21

CVE-2026-32824:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authentica

HIGH NVD Recent 2026-07-21

CVE-2026-32821:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user

HIGH NVD Recent 2026-07-21

CVE-2026-32820:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and stati

HIGH NVD Recent 2026-07-21

CVE-2026-32806:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can

HIGH NVD Recent 2026-07-21

CVE-2026-10081:The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malici

HIGH CISA KEV 2026-07-21

CVE-2026-0770:Langflow Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

HIGH CISA KEV 2026-07-21

CVE-2026-63030:WordPress WordPress Core Interpretation Conflict Vulnerability

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

HIGH CISA KEV 2026-07-21

CVE-2026-60137:WordPress WordPress Core SQL Injection Vulnerability

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordP

HIGH NVD Recent 2026-07-20

CVE-2026-12592:The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the

HIGH NVD Recent 2026-07-20

CVE-2026-11349:The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated

HIGH openEuler 安全公告 OSV 2026-07-19

CVE-2026-10805:NetworkManager security update

NetworkManager security update

HIGH NVD Recent 2026-07-17

CVE-2026-12691:Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

HIGH NVD Recent 2026-07-17

CVE-2026-13397:HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attribu

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。