最新预警列表

MEDIUM NVD Recent 2026-08-10

CVE-2026-34490:Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34495:Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.

MEDIUM NVD Recent 2026-08-10

CVE-2026-34497:Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

CRITICAL CERT/CC VU 2026-08-10

VU#614868: Opencart ecommerce platform contains directory traversal vulnerability

Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved pa

HIGH NVD Recent 2026-08-10

CVE-2026-10848:The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1

HIGH NVD Recent 2026-08-07

CVE-2026-15314:Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causi

CRITICAL NVD Recent 2026-08-07

CVE-2026-58048:Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

MEDIUM NVD Recent 2026-08-07

CVE-2026-58047:HTTP Smuggling in cPanel allows potential leak of credentials.

HTTP Smuggling in cPanel allows potential leak of credentials.

MEDIUM CERT/CC VU 2026-08-07

VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability

Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. D

MEDIUM openEuler 安全公告 OSV 2026-08-07

CVE-2026-56389:bison security update

bison security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-58216:samba security update

samba security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-47180:python-zeroconf security update

python-zeroconf security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-59878:activemq security update

activemq security update

HIGH openEuler 安全公告 OSV 2026-08-07

CVE-2026-17572:hdf5 security update

hdf5 security update

HIGH openEuler 安全公告 OSV 2026-08-07

CVE-2026-17572:hdf5 security update

hdf5 security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。