最新预警列表

HIGH NVD Recent 2026-08-04

CVE-2026-17107:A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removin

MEDIUM NVD Recent 2026-08-03

CVE-2025-15675:The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Script

MEDIUM NVD Recent 2026-08-03

CVE-2026-9335:A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `

HIGH NVD Recent 2026-08-03

CVE-2026-3245:A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

MEDIUM NVD Recent 2026-08-03

CVE-2026-57978:Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-57989:Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-57990:Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-17568:Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API requ

MEDIUM NVD Recent 2026-08-01

CVE-2026-17002:Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

MEDIUM NVD Recent 2026-08-01

CVE-2026-20316:A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted syst

MEDIUM NVD Recent 2026-08-01

CVE-2026-54707:OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionsh

CRITICAL NVD Recent 2026-07-31

CVE-2026-52855:Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, a

CRITICAL NVD Recent 2026-07-31

CVE-2026-67822:Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restr

HIGH NVD Recent 2026-07-31

CVE-2026-66731:facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single P

HIGH NVD Recent 2026-07-31

CVE-2026-66730:facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。