最新预警列表

LOW NVD Recent 2026-08-12

CVE-2026-18784:A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a r

LOW NVD Recent 2026-08-12

CVE-2026-18775:A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery.

LOW NVD Recent 2026-08-12

CVE-2026-18774:A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The att

MEDIUM NVD Recent 2026-08-12

CVE-2025-35987:Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives

Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attac

MEDIUM NVD Recent 2026-08-12

CVE-2025-35973:Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow a

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of

MEDIUM NVD Recent 2026-08-12

CVE-2025-31938:Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(

Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may

HIGH NVD Recent 2026-08-12

CVE-2025-31936:Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R)

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may en

MEDIUM NVD Recent 2026-08-12

CVE-2025-31356:Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H

Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexit

LOW NVD Recent 2026-08-12

CVE-2026-70395:Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f

Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is used

HIGH NVD Recent 2026-08-12

CVE-2025-8087:A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges

A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.

LOW NVD Recent 2026-08-12

CVE-2025-61970:Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to

Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.

MEDIUM NVD Recent 2026-08-12

CVE-2025-48506:Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into t

Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.

LOW NVD Recent 2026-08-12

CVE-2025-48505:Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to

Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code execution.

MEDIUM NVD Recent 2026-08-12

CVE-2025-0041:Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a

Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.

MEDIUM NVD Recent 2026-08-12

CVE-2026-48550:Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, ex

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。