最新预警列表

HIGH NVD Recent 2026-09-10

CVE-2026-82461:pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization

HIGH NVD Recent 2026-09-10

CVE-2026-18147:A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerabi

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password rese

HIGH NVD Recent 2026-09-09

CVE-2026-19233:CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and dis

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized command execution and disclosure of server data when an attacker with a privileged account sends crafted, unvalidated parameters to a server endpoint.

HIGH NVD Recent 2026-09-09

CVE-2026-45730:Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnera

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypa

HIGH NVD Recent 2026-09-09

CVE-2025-56798:Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.

HIGH NVD Recent 2026-09-09

CVE-2026-86479:In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restric

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

HIGH NVD Recent 2026-09-08

CVE-2026-51974:An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 throu

An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata of an uploaded imag

HIGH NVD Recent 2026-09-08

CVE-2025-29419:CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

HIGH NVD Recent 2026-09-08

CVE-2026-0799:In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit i

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted fil

HIGH NVD Recent 2026-09-08

CVE-2026-82751:Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the cli

HIGH NVD Recent 2026-09-08

CVE-2026-82750:Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the c

HIGH NVD Recent 2026-09-08

CVE-2026-47625:NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

HIGH NVD Recent 2026-09-08

CVE-2026-16497:NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A s

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.

HIGH NVD Recent 2026-09-08

CVE-2026-86207:An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

HIGH NVD Recent 2026-09-08

CVE-2026-13297:IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。