最新预警列表

MEDIUM NVD Recent 2026-08-07

CVE-2025-6508:The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b

The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can

CRITICAL NVD Recent 2026-08-07

CVE-2025-14561:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability a

MEDIUM NVD Recent 2026-08-07

CVE-2025-12317:When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges eve

MEDIUM NVD Recent 2026-08-07

CVE-2024-6541:The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be i

HIGH NVD Recent 2026-08-07

CVE-2024-39024:In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

LOW NVD Recent 2026-08-07

CVE-2025-15674:The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from

The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contrib

MEDIUM NVD Recent 2026-08-07

CVE-2026-12501:The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowin

CRITICAL NVD Recent 2026-08-07

CVE-2026-11976:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`

MEDIUM NVD Recent 2026-08-07

CVE-2026-11361:The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content

HIGH NVD Recent 2026-08-07

CVE-2026-10599:The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthen

HIGH NVD Recent 2026-08-07

CVE-2026-10524:The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price

The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product

HIGH NVD Recent 2026-08-07

CVE-2026-17630:IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.

HIGH NVD Recent 2026-08-07

CVE-2026-66032:libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server respo

HIGH NVD Recent 2026-08-06

CVE-2026-17623:IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to i

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.

HIGH NVD Recent 2026-08-06

CVE-2026-17626:IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。