最新预警列表

CRITICAL NVD Recent 2026-08-12

CVE-2026-12571:An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

CRITICAL NVD Recent 2026-08-11

CVE-2026-71951:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_va

CRITICAL NVD Recent 2026-08-11

CVE-2026-71946:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the

MEDIUM NVD Recent 2026-08-11

CVE-2026-18247:A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could al

A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.

MEDIUM NVD Recent 2026-08-11

CVE-2026-17595:Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engin

MEDIUM NVD Recent 2026-08-11

CVE-2026-12624:Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra

Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerat

CRITICAL NVD Recent 2026-08-11

CVE-2026-71954:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the

CRITICAL NVD Recent 2026-08-11

CVE-2026-71949:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdVal

CRITICAL NVD Recent 2026-08-11

CVE-2026-71944:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into

MEDIUM NVD Recent 2026-08-10

CVE-2026-21662:Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34490:Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34495:Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34497:Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

HIGH NVD Recent 2026-08-10

CVE-2026-17617:IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insuffici

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

CRITICAL NVD Recent 2026-08-10

CVE-2026-71955:D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSs

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。