最新预警列表

CRITICAL NVD Recent 2026-09-01

CVE-2026-51724:Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta

Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CRITICAL NVD Recent 2026-09-01

CVE-2026-51722:Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated

Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device to an attacker-controlled upstream Wi-Fi via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CRITICAL NVD Recent 2026-09-01

CVE-2026-51721:Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker

Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairing state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CRITICAL NVD Recent 2026-08-31

CVE-2026-51725:Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att

Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CRITICAL NVD Recent 2026-08-31

CVE-2026-51720:Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate

Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CRITICAL NVD Recent 2026-08-31

CVE-2026-82460:Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files ou

CRITICAL NVD Recent 2026-08-31

CVE-2025-36939:Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack

CRITICAL NVD Recent 2026-08-27

CVE-2026-66906:Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download

CRITICAL NVD Recent 2026-08-27

CVE-2026-71300:Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects

CRITICAL NVD Recent 2026-08-26

CVE-2026-73041:SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access

CRITICAL NVD Recent 2026-08-26

CVE-2026-73042:SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to ex

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that clo

CRITICAL NVD Recent 2026-08-26

CVE-2026-55982:OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

CRITICAL NVD Recent 2026-08-26

CVE-2026-78183:DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infini

CRITICAL NVD Recent 2026-08-26

CVE-2026-13051:Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTM

CRITICAL NVD Recent 2026-08-26

CVE-2022-4993:HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_e

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。