最新预警列表

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-15588:glib2 security update

glib2 security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-15588:glib2 security update

glib2 security update

HIGH NVD Recent 2026-08-07

CVE-2026-66032:libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server respo

CRITICAL Cisco PSIRT 2026-08-07

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address m

MEDIUM CISA KEV 2026-08-07

CVE-2026-8037:Progress Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

CRITICAL CERT/CC VU 2026-08-06

VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively

MEDIUM NVD Recent 2026-08-06

CVE-2026-54894:Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary b

MEDIUM NVD Recent 2026-08-06

CVE-2026-55733:Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binari

MEDIUM NVD Recent 2026-08-06

CVE-2026-55734:Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a

Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is associated with program file lib/guardian/permissions.

HIGH NVD Recent 2026-08-06

CVE-2026-55735:Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no sig

MEDIUM openEuler 安全公告 OSV 2026-08-06

CVE-2026-57062:gnupg2 security update

gnupg2 security update

MEDIUM openEuler 安全公告 OSV 2026-08-06

CVE-2026-40612:jq security update

jq security update

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2026-31958:python-tornado security update

python-tornado security update

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2025-45582:tar security update

tar security update

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2025-50181:python-pip security update

python-pip security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。