最新预警列表

HIGH NVD Recent 2026-06-30

CVE-2026-58050:libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication

LOW NVD Recent 2026-06-30

CVE-2026-13512:A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulati

HIGH NVD Recent 2026-06-30

CVE-2026-58051:libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry.

MEDIUM NVD Recent 2026-06-30

CVE-2026-58052:7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because it

7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record nam

MEDIUM NVD Recent 2026-06-30

CVE-2026-58055:nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim

HIGH NVD Recent 2026-06-30

CVE-2026-49048:The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenati

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

MEDIUM NVD Recent 2026-06-30

CVE-2026-58058:Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scann

LOW NVD Recent 2026-06-30

CVE-2026-13590:A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength

A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/header/ModbusLayer.h of the component Modbus Protocol Handler. The manipulation of the argument length results

HIGH NVD Recent 2026-06-30

CVE-2026-11940:tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location

MEDIUM NVD Recent 2026-06-30

CVE-2026-13751:Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retrieved at runtime without sufficient

MEDIUM NVD Recent 2026-06-30

CVE-2026-13752:Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac

Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulnerable command paths, causing Snowflake CLI to execute unintended SQL in the

HIGH NVD Recent 2026-06-30

CVE-2026-36848:Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

CRITICAL NVD Recent 2026-06-30

CVE-2026-58053:Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options suc

HIGH NVD Recent 2026-06-30

CVE-2026-42127:The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory

HIGH NVD Recent 2026-06-30

CVE-2026-50168:Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows remote attacke

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。