最新预警列表

MEDIUM NVD Recent 2026-08-03

CVE-2026-9335:A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `

CRITICAL NVD Recent 2026-08-03

CVE-2026-41452:Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLH

CRITICAL NVD Recent 2026-08-03

CVE-2026-39932:OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by injecting PHP payloads

HIGH NVD Recent 2026-08-03

CVE-2026-3245:A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

MEDIUM NVD Recent 2026-08-03

CVE-2026-57978:Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-57989:Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-57990:Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-17568:Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API requ

MEDIUM NVD Recent 2026-08-01

CVE-2026-17002:Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

MEDIUM NVD Recent 2026-08-01

CVE-2026-20316:A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted syst

MEDIUM NVD Recent 2026-08-01

CVE-2026-54707:OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionsh

CRITICAL NVD Recent 2026-07-31

CVE-2026-52855:Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, a

CRITICAL NVD Recent 2026-07-31

CVE-2026-67822:Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restr

HIGH NVD Recent 2026-07-31

CVE-2026-66731:facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single P

HIGH NVD Recent 2026-07-31

CVE-2026-66730:facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。