最新预警列表

CRITICAL NVD Recent 2026-07-09

CVE-2026-48316:ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scop

CRITICAL NVD Recent 2026-07-09

CVE-2026-13019:Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CRITICAL NVD Recent 2026-07-08

CVE-2026-12481:A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard

CRITICAL NVD Recent 2026-07-07

CVE-2026-40139:A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized a

CRITICAL NVD Recent 2026-07-07

CVE-2026-40138:A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and

CRITICAL NVD Recent 2026-07-06

CVE-2026-48614:An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.

CRITICAL NVD Recent 2026-07-06

CVE-2026-52955:In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algori

CRITICAL NVD Recent 2026-07-06

CVE-2026-44935:Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

CRITICAL NVD Recent 2026-07-02

CVE-2022-50973:Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and f

CRITICAL NVD Recent 2026-07-02

CVE-2024-14037:Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with

CRITICAL NVD Recent 2026-07-01

CVE-2026-11720:A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string

CRITICAL NVD Recent 2026-07-01

CVE-2026-5366:Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--`

CRITICAL NVD Recent 2026-06-30

CVE-2026-58053:Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options suc

CRITICAL NVD Recent 2026-06-29

CVE-2026-54636:Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; -

CRITICAL NVD Recent 2026-06-26

CVE-2026-45408:Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-re

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。