最新预警列表

HIGH CISA KEV 2026-09-24

CVE-2026-5430:WSO2 WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

HIGH NVD Recent 2026-09-23

CVE-2026-90556:Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with decl

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the

HIGH NVD Recent 2026-09-23

CVE-2026-42784:A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags su

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass t

HIGH NVD Recent 2026-09-22

CVE-2026-90616:In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whi

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app d

HIGH NVD Recent 2026-09-22

CVE-2026-78807:An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

HIGH NVD Recent 2026-09-22

CVE-2026-18111:Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validate

HIGH NVD Recent 2026-09-22

CVE-2026-19780:Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists withi

HIGH NVD Recent 2026-09-22

CVE-2026-18110:Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates onl

HIGH CISA KEV 2026-09-22

CVE-2026-85102:Check Point Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

HIGH CISA KEV 2026-09-22

CVE-2026-94127:F5 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

HIGH CISA KEV 2026-09-22

CVE-2026-93952:Arista Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentialit

HIGH NVD Recent 2026-09-21

CVE-2026-71179:Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vul

HIGH openEuler 安全公告 OSV 2026-09-20

CVE-2026-72522:xmlrpc-c security update

xmlrpc-c security update

HIGH Cisco PSIRT 2026-09-18

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RAD

HIGH Cisco PSIRT 2026-09-18

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。