最新预警列表

HIGH openEuler 安全公告 OSV 2026-08-30

CVE-2026-31962:htslib security update

htslib security update

MEDIUM NVD Recent 2026-08-29

CVE-2026-32639:Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single

HIGH NVD Recent 2026-08-28

CVE-2026-19685:NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) c

CRITICAL CERT/CC VU 2026-08-28

VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

Overview The Kaltura HTML5 Player V2 Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.

MEDIUM NVD Recent 2026-08-28

CVE-2026-24168:NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code exe

MEDIUM NVD Recent 2026-08-28

CVE-2026-24167:NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator co

NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalati

MEDIUM NVD Recent 2026-08-28

CVE-2026-24166:NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-c

NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and esca

HIGH NVD Recent 2026-08-28

CVE-2026-15469:The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5

The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.  A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protoco

HIGH NVD Recent 2026-08-28

CVE-2026-66908:Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through

HIGH NVD Recent 2026-08-28

CVE-2026-50768:File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to ex

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

HIGH NVD Recent 2026-08-27

CVE-2026-66907:Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud

CRITICAL NVD Recent 2026-08-27

CVE-2026-66906:Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download

MEDIUM NVD Recent 2026-08-27

CVE-2026-63621:Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Ca

CRITICAL NVD Recent 2026-08-27

CVE-2026-71300:Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects

MEDIUM NVD Recent 2026-08-27

CVE-2026-60093:Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Came

Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake component can do

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。