最新预警列表

MEDIUM NVD Recent 2026-07-15

CVE-2026-14646:Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets re

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compro

MEDIUM NVD Recent 2026-07-15

CVE-2026-14645:Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to inte

MEDIUM NVD Recent 2026-07-15

CVE-2026-61503:Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the

Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including the default admin a

MEDIUM NVD Recent 2026-07-15

CVE-2026-60103:Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or rea

Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted .blend file with a malicious signed short member_index value in the SDNA block. The membe

HIGH NVD Recent 2026-07-15

CVE-2026-20187:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20158:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20157:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20156:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20153:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20150:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

MEDIUM NVD Recent 2026-07-15

CVE-2025-32781:Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID thro

CRITICAL CERT/CC VU 2026-07-15

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker

CRITICAL CERT/CC VU 2026-07-15

VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations

Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attacke

MEDIUM NVD Recent 2026-07-15

CVE-2026-15703:A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It

HIGH NVD Recent 2026-07-15

CVE-2026-15701:A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。