最新预警列表

CRITICAL NVD Recent 2026-09-15

CVE-2026-20274:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

CRITICAL NVD Recent 2026-09-15

CVE-2026-19931:A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, w

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated

CRITICAL NVD Recent 2026-09-15

CVE-2026-18924:A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with othe

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

CRITICAL NVD Recent 2026-09-15

CVE-2026-72710:SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attac

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter re

CRITICAL NVD Recent 2026-09-15

CVE-2026-72709:SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission

CRITICAL NVD Recent 2026-09-11

CVE-2026-54047:Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior t

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side sta

CRITICAL NVD Recent 2026-09-11

CVE-2026-82466:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account

CRITICAL NVD Recent 2026-09-10

CVE-2026-88044:rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/ser

CRITICAL NVD Recent 2026-09-10

CVE-2026-68488:A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privileg

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

CRITICAL NVD Recent 2026-09-10

CVE-2026-68487:Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

CRITICAL NVD Recent 2026-09-10

CVE-2026-65639:OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who contro

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The

CRITICAL NVD Recent 2026-09-10

CVE-2026-65638:Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to exe

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software ori

CRITICAL NVD Recent 2026-09-10

CVE-2026-47156:MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP

MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowing their username)

CRITICAL NVD Recent 2026-09-09

CVE-2026-78997:UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulner

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL

CRITICAL NVD Recent 2026-09-09

CVE-2026-79570:mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbCon

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。