最新预警列表

MEDIUM NVD Recent 2026-07-09

CVE-2026-48951:Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

MEDIUM NVD Recent 2026-07-08

CVE-2026-14355:In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operat

HIGH NVD Recent 2026-07-08

CVE-2026-43825:Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document c

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStre

HIGH NVD Recent 2026-07-08

CVE-2026-14904:AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the A

HIGH NVD Recent 2026-07-08

CVE-2026-23698:Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager

HIGH NVD Recent 2026-07-08

CVE-2026-23697:Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension den

CRITICAL NVD Recent 2026-07-08

CVE-2026-12481:A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard

MEDIUM NVD Recent 2026-07-07

CVE-2026-40257:OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated

LOW NVD Recent 2026-07-07

CVE-2026-41434:OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion can crash the

HIGH NVD Recent 2026-07-07

CVE-2026-40141:A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated

HIGH NVD Recent 2026-07-07

CVE-2026-40140:BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the

BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigg

CRITICAL NVD Recent 2026-07-07

CVE-2026-40139:A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized a

CRITICAL NVD Recent 2026-07-07

CVE-2026-40138:A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and

MEDIUM NVD Recent 2026-07-07

CVE-2026-12154:The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sa

MEDIUM NVD Recent 2026-07-07

CVE-2026-14620:webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。