最新预警列表

HIGH NVD Recent 2026-07-09

CVE-2026-20216:A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning

HIGH NVD Recent 2026-07-09

CVE-2026-20217:A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do

A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due t

HIGH NVD Recent 2026-07-09

CVE-2026-20243:A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to i

HIGH NVD Recent 2026-07-09

CVE-2026-20244:A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to i

HIGH NVD Recent 2026-07-09

CVE-2026-20214:A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c

A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to i

HIGH NVD Recent 2026-07-09

CVE-2026-20215:A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co

A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to im

HIGH NVD Recent 2026-07-09

CVE-2026-20213:A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co

A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to im

CRITICAL NVD Recent 2026-07-09

CVE-2026-48316:ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scop

CRITICAL CERT/CC VU 2026-07-09

VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities

Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is availab

HIGH NVD Recent 2026-07-09

CVE-2026-59731:Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() oper

MEDIUM NVD Recent 2026-07-09

CVE-2025-12799:A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded Undertow and Jastow, a server might be vulnerable to improper input handling

CRITICAL NVD Recent 2026-07-09

CVE-2026-13019:Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

HIGH NVD Recent 2026-07-09

CVE-2026-13020:A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism.

MEDIUM NVD Recent 2026-07-09

CVE-2026-48947:An improper access check allows privileged users to overwrite media files without editing permissions.

An improper access check allows privileged users to overwrite media files without editing permissions.

MEDIUM NVD Recent 2026-07-09

CVE-2026-48948:An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。