最新预警列表

LOW NVD Recent 2026-07-14

CVE-2026-15505:A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra

A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of the argument p_metaData causes cross site scripting. The

MEDIUM NVD Recent 2026-07-14

CVE-2026-15479:A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file

A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in w

LOW NVD Recent 2026-07-14

CVE-2026-15473:A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of th

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack

HIGH NVD Recent 2026-07-14

CVE-2026-58281:Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ove

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

HIGH NVD Recent 2026-07-14

CVE-2026-53657:Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, whic

LOW NVD Recent 2026-07-14

CVE-2026-15191:A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettl

A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a manipulation can

HIGH CISA KEV 2026-07-14

CVE-2026-15410:SonicWall SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

HIGH CISA KEV 2026-07-14

CVE-2026-15409:SonicWall SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

MEDIUM CISA KEV 2026-07-14

CVE-2026-56164:Microsoft Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

MEDIUM CISA KEV 2026-07-14

CVE-2026-56155:Microsoft Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

LOW NVD Recent 2026-07-13

CVE-2026-15477:A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /op

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injecti

LOW NVD Recent 2026-07-13

CVE-2026-15471:A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci

A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploi

CRITICAL NVD Recent 2026-07-13

CVE-2026-61462:mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended

HIGH NVD Recent 2026-07-13

CVE-2026-61463:Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with

LOW NVD Recent 2026-07-13

CVE-2026-15472:A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. T

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。