最新预警列表

HIGH NVD Recent 2026-08-04

CVE-2026-18718:Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attac

HIGH NVD Recent 2026-08-04

CVE-2026-59643:In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affect

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

HIGH NVD Recent 2026-08-04

CVE-2026-59642:In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X seri

HIGH NVD Recent 2026-08-04

CVE-2026-59641:In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips

HIGH NVD Recent 2026-08-04

CVE-2026-59640:In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series)

HIGH NVD Recent 2026-08-04

CVE-2026-59639:In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series)

CRITICAL NVD Recent 2026-08-04

CVE-2026-59638:In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1

MEDIUM NVD Recent 2026-08-04

CVE-2026-15055:In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.

HIGH NVD Recent 2026-08-04

CVE-2026-12185:In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

HIGH NVD Recent 2026-08-04

CVE-2026-18577:An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

HIGH NVD Recent 2026-08-04

CVE-2026-13697:undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be

HIGH NVD Recent 2026-08-04

CVE-2026-17107:A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removin

HIGH NVD Recent 2026-08-03

CVE-2026-39931:OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application databa

MEDIUM NVD Recent 2026-08-03

CVE-2026-18243:Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat

Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.

MEDIUM NVD Recent 2026-08-03

CVE-2025-15675:The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Script

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。