最新预警列表

MEDIUM NVD Recent 2026-08-27

CVE-2021-47998:Rejected reason: This CVE ID has been rejected.

Rejected reason: This CVE ID has been rejected.

MEDIUM NVD Recent 2026-08-27

CVE-2021-47997:Rejected reason: This CVE ID has been rejected.

Rejected reason: This CVE ID has been rejected.

HIGH CISA KEV 2026-08-27

CVE-2026-66384:JFrog JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

MEDIUM CISA KEV 2026-08-27

CVE-2026-53362:Linux Linux Kernel Unspecified Vulnerability

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

MEDIUM CISA KEV 2026-08-27

CVE-2023-49105:ownCloud ownCloud Improper Authentication Vulnerability

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

HIGH NVD Recent 2026-08-26

CVE-2026-35445:Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to inv

LOW NVD Recent 2026-08-26

CVE-2026-78144:A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vuln

A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the ar

MEDIUM NVD Recent 2026-08-26

CVE-2026-32593:Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditio

LOW NVD Recent 2026-08-26

CVE-2026-78054:A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched re

HIGH NVD Recent 2026-08-26

CVE-2026-78122:docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs,

HIGH NVD Recent 2026-08-26

CVE-2026-32258:Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LES

MEDIUM NVD Recent 2026-08-26

CVE-2026-80153:Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CRITICAL NVD Recent 2026-08-26

CVE-2026-73041:SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access

MEDIUM NVD Recent 2026-08-26

CVE-2026-13478:The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by p

The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) treats it

MEDIUM NVD Recent 2026-08-26

CVE-2026-13217:The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLR

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return value. W

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。