最新预警列表

MEDIUM NVD Recent 2026-08-19

CVE-2026-48744:Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in sale

Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channe

CRITICAL CERT-EU 2026-08-19

2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

HIGH NVD Recent 2026-08-19

CVE-2026-19628:A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify applica

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations ar

CRITICAL NVD Recent 2026-08-19

CVE-2026-19626:A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during serv

HIGH NVD Recent 2026-08-19

CVE-2026-50577:ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU

HIGH NVD Recent 2026-08-19

CVE-2026-49224:Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access revisions for posts owned by another Author. The admin

CRITICAL Cisco PSIRT 2026-08-19

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access contro

HIGH Cisco PSIRT 2026-08-19

Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condit

HIGH Cisco PSIRT 2026-08-19

Cisco IOS XE Software SNMP Denial of Service Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability i

HIGH Cisco PSIRT 2026-08-19

Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper ha

MEDIUM Cisco PSIRT 2026-08-19

Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vu

MEDIUM Cisco PSIRT 2026-08-19

Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due t

MEDIUM Cisco PSIRT 2026-08-19

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient

CRITICAL Cisco PSIRT 2026-08-19

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 C

MEDIUM CISA KEV 2026-08-19

CVE-2026-64849:MLflow MLflow Server-Side Request Forgery Vulnerability

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。