最新预警列表

HIGH NVD Recent 2026-07-15

CVE-2026-20158:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20157:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20156:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20153:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

HIGH NVD Recent 2026-07-15

CVE-2026-20150:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple interna

MEDIUM NVD Recent 2026-07-15

CVE-2025-32781:Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID thro

CRITICAL CERT/CC VU 2026-07-15

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker

CRITICAL CERT/CC VU 2026-07-15

VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations

Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attacke

MEDIUM NVD Recent 2026-07-15

CVE-2026-15703:A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It

HIGH NVD Recent 2026-07-15

CVE-2026-15701:A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Lo

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow.

LOW NVD Recent 2026-07-15

CVE-2026-15509:A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON

A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely

CRITICAL NVD Recent 2026-07-15

CVE-2026-61500:Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generato

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of

LOW NVD Recent 2026-07-15

CVE-2026-15702:A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file co

A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly controlled modification of object prototype attributes. The attack may

LOW NVD Recent 2026-07-15

CVE-2026-15700:A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th

A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album Publishing Feature. The manipulation of the argument filename results in path trave

CRITICAL Cisco PSIRT 2026-07-15

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated,

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。