最新预警列表

CRITICAL CERT/CC VU 2026-09-23

VU#273940: Enterprise Access Management EAM does not rotate RSA keys

Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its

MEDIUM NVD Recent 2026-09-23

CVE-2026-90557:Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processin

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity inde

MEDIUM NVD Recent 2026-09-23

CVE-2026-55073:WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restri

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or

CRITICAL NVD Recent 2026-09-23

CVE-2026-90558:sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header val

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fiel

HIGH NVD Recent 2026-09-23

CVE-2026-90556:Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with decl

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the

CRITICAL CERT/CC VU 2026-09-23

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

Overview Two vulnerabilities in MLflow’s dspy and statsmodels model flavors allow unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file exten

HIGH NVD Recent 2026-09-23

CVE-2026-42784:A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags su

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass t

CRITICAL CERT/CC VU 2026-09-22

VU#889462: Casdoor authentication server is vulnerable to authorization bypass

Overview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions up to v4.2.0. The vulnerability allows a non-global organization administrator to perform u

MEDIUM NVD Recent 2026-09-22

CVE-2025-70819:Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

LOW NVD Recent 2026-09-22

CVE-2025-45480:Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

CRITICAL NVD Recent 2026-09-22

CVE-2026-90647:ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validatio

LOW NVD Recent 2026-09-22

CVE-2026-79300:SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, whi

MEDIUM NVD Recent 2026-09-22

CVE-2020-15875:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects

HIGH NVD Recent 2026-09-22

CVE-2026-90616:In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whi

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app d

HIGH NVD Recent 2026-09-22

CVE-2026-78807:An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。