最新预警列表

CRITICAL NVD Recent 2026-07-23

CVE-2026-65760:Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system.

CRITICAL CERT/CC VU 2026-07-23

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can tri

CRITICAL CERT/CC VU 2026-07-23

VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA

CRITICAL CERT-EU 2026-07-23

2026-009: Critical Vulnerabilities in Microsoft SharePoint

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed

CRITICAL CERT/CC VU 2026-07-22

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability

Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execut

CRITICAL NVD Recent 2026-07-21

CVE-2026-35048:The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it chec

CRITICAL CERT/CC VU 2026-07-21

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other works

CRITICAL openEuler 安全公告 OSV 2026-07-19

CVE-2026-56366:ImageMagick security update

ImageMagick security update

CRITICAL openEuler 安全公告 OSV 2026-07-19

CVE-2026-48855:erlang security update

erlang security update

CRITICAL openEuler 安全公告 OSV 2026-07-19

CVE-2026-12610:sssd security update

sssd security update

CRITICAL openEuler 安全公告 OSV 2026-07-19

CVE-2026-10649:pacemaker security update

pacemaker security update

CRITICAL NVD Recent 2026-07-17

CVE-2026-3031:Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.

CRITICAL NVD Recent 2026-07-17

CVE-2026-12694:Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

CRITICAL NVD Recent 2026-07-17

CVE-2026-12693:Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

CRITICAL NVD Recent 2026-07-17

CVE-2026-12692:Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。