最新预警列表

HIGH NVD Recent 2026-09-15

CVE-2026-20277:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-20276:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-20275:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

HIGH NVD Recent 2026-09-15

CVE-2026-72708:SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows u

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an

HIGH NVD Recent 2026-09-15

CVE-2026-73698:FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate ra

HIGH NVD Recent 2026-09-15

CVE-2026-82209:When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Co

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by

HIGH NVD Recent 2026-09-15

CVE-2026-82208:With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by

HIGH NVD Recent 2026-09-15

CVE-2026-80255:A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTT

HIGH NVD Recent 2026-09-15

CVE-2026-80231:A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a diffe

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

HIGH NVD Recent 2026-09-15

CVE-2026-80230:When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VER

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presen

HIGH NVD Recent 2026-09-15

CVE-2026-80229:When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handl

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to Ope

HIGH NVD Recent 2026-09-15

CVE-2026-13608:A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpre

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or short

HIGH NVD Recent 2026-09-14

CVE-2026-55451:gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2

gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each s

HIGH NVD Recent 2026-09-14

CVE-2026-54156:node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNon

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces

HIGH NVD Recent 2026-09-14

CVE-2026-54155:node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentic

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trai

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。