最新预警列表

CRITICAL NVD Recent 2026-09-22

CVE-2026-90647:ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validatio

LOW NVD Recent 2026-09-22

CVE-2026-79300:SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, whi

MEDIUM NVD Recent 2026-09-22

CVE-2020-15875:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects

HIGH NVD Recent 2026-09-22

CVE-2026-90616:In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whi

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app d

HIGH NVD Recent 2026-09-22

CVE-2026-78807:An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

HIGH NVD Recent 2026-09-22

CVE-2026-18111:Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validate

HIGH NVD Recent 2026-09-22

CVE-2026-19780:Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists withi

HIGH NVD Recent 2026-09-22

CVE-2026-18110:Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates onl

HIGH NVD Recent 2026-09-21

CVE-2026-71179:Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vul

CRITICAL NVD Recent 2026-09-18

CVE-2026-20331:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has

CRITICAL NVD Recent 2026-09-18

CVE-2026-75156:Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because t

CRITICAL NVD Recent 2026-09-17

CVE-2026-46488:motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authenti

LOW NVD Recent 2026-09-17

CVE-2026-44778:Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to

MEDIUM NVD Recent 2026-09-17

CVE-2026-67278:MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificat

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting a

HIGH NVD Recent 2026-09-17

CVE-2026-21587:This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended a

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。