最新预警列表

CRITICAL NVD Recent 2026-09-28

CVE-2026-20234:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This re

CRITICAL CERT-EU 2026-09-27

2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citri

MEDIUM CISA KEV 2026-09-27

CVE-2026-88771:Citrix Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

HIGH CISA KEV 2026-09-27

CVE-2026-88772:Citrix Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

MEDIUM CERT/CC VU 2026-09-25

VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise

Overview ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. Description ViewSonic ViewBoards are widely used smart display devices

CRITICAL CERT/CC VU 2026-09-25

VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned

MEDIUM NVD Recent 2026-09-25

CVE-2026-7298:Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0.

HIGH openEuler 安全公告 OSV 2026-09-25

CVE-2026-17705:libxml2 security update

libxml2 security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-11856:curl security update

curl security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-92005:firefox security update

firefox security update

HIGH openEuler 安全公告 OSV 2026-09-25

CVE-2026-72522:xmlrpc-c security update

xmlrpc-c security update

MEDIUM openEuler 安全公告 OSV 2026-09-25

CVE-2026-9499:qt6-qt5compat security update

qt6-qt5compat security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-84732:openvpn security update

openvpn security update

CRITICAL openEuler 安全公告 OSV 2026-09-25

CVE-2026-86320:flatpak-builder security update

flatpak-builder security update

MEDIUM openEuler 安全公告 OSV 2026-09-25

CVE-2026-85504:freeipmi security update

freeipmi security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。