最新预警列表

HIGH NVD Recent 2026-09-16

CVE-2026-67211:OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain the affected code.)

HIGH NVD Recent 2026-09-16

CVE-2026-55416:Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticat

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Cus

HIGH NVD Recent 2026-09-16

CVE-2026-55072:Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objec

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefin

HIGH NVD Recent 2026-09-16

CVE-2026-79639:Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnera

HIGH NVD Recent 2026-09-16

CVE-2026-80166:Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerabil

HIGH NVD Recent 2026-09-15

CVE-2026-20280:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineer

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address mul

HIGH NVD Recent 2026-09-15

CVE-2026-20278:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-20277:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-20276:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-20275:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-72708:SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows u

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an

HIGH NVD Recent 2026-09-15

CVE-2026-73698:FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate ra

HIGH NVD Recent 2026-09-15

CVE-2026-82209:When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Co

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by

HIGH NVD Recent 2026-09-15

CVE-2026-82208:With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by

HIGH NVD Recent 2026-09-15

CVE-2026-80255:A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTT

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。