最新预警列表

CRITICAL NVD Recent 2026-09-28

CVE-2024-58385:Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitiza

CRITICAL NVD Recent 2026-09-28

CVE-2026-20234:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This re

CRITICAL CERT-EU 2026-09-27

2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citri

CRITICAL CERT/CC VU 2026-09-25

VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-11856:curl security update

curl security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-92005:firefox security update

firefox security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-84732:openvpn security update

openvpn security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-86320:flatpak-builder security update

flatpak-builder security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-84375:nodejs-js-yaml security update

nodejs-js-yaml security update

CRITICAL NVD Recent 2026-09-24

CVE-2023-54398:Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageS

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST

CRITICAL CERT/CC VU 2026-09-23

VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by suppl

CRITICAL CERT/CC VU 2026-09-23

VU#273940: Enterprise Access Management EAM does not rotate RSA keys

Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its

CRITICAL NVD Recent 2026-09-23

CVE-2026-90558:sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header val

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fiel

CRITICAL CERT/CC VU 2026-09-23

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

Overview Two vulnerabilities in MLflow’s dspy and statsmodels model flavors allow unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file exten

CRITICAL CERT/CC VU 2026-09-22

VU#889462: Casdoor authentication server is vulnerable to authorization bypass

Overview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions up to v4.2.0. The vulnerability allows a non-global organization administrator to perform u

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。