最新预警列表

LOW NVD Recent 2026-07-13

CVE-2026-15477:A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /op

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injecti

LOW NVD Recent 2026-07-13

CVE-2026-15471:A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci

A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploi

CRITICAL NVD Recent 2026-07-13

CVE-2026-61462:mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended

HIGH NVD Recent 2026-07-13

CVE-2026-61463:Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with

LOW NVD Recent 2026-07-13

CVE-2026-15472:A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. T

LOW NVD Recent 2026-07-13

CVE-2026-15470:A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona

A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploi

LOW NVD Recent 2026-07-13

CVE-2026-15377:A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown fun

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes improper authorization. The attack may be initiated remotely. The

LOW NVD Recent 2026-07-13

CVE-2026-15376:A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been

LOW NVD Recent 2026-07-13

CVE-2026-15510:A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. T

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made public and could

LOW NVD Recent 2026-07-13

CVE-2026-15508:A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file

A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. Executing a manipulation of the argument extracted_path_an

LOW NVD Recent 2026-07-13

CVE-2026-15478:A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports

A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to s

LOW NVD Recent 2026-07-13

CVE-2026-15476:A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in

A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be p

MEDIUM NVD Recent 2026-07-13

CVE-2026-42505:Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

LOW NVD Recent 2026-07-13

CVE-2026-15475:A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in t

A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be

LOW NVD Recent 2026-07-13

CVE-2026-15507:A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file

A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing authorization. Remote exploitation of the

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。