最新预警列表

MEDIUM NVD Recent 2026-08-07

CVE-2026-17599:Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th

Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence o

MEDIUM NVD Recent 2026-08-07

CVE-2026-17598:Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled tas

MEDIUM NVD Recent 2026-08-07

CVE-2026-17596:Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in

HIGH NVD Recent 2026-08-07

CVE-2026-17594:Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific re

CRITICAL NVD Recent 2026-08-07

CVE-2026-58048:Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

MEDIUM NVD Recent 2026-08-07

CVE-2026-58047:HTTP Smuggling in cPanel allows potential leak of credentials.

HTTP Smuggling in cPanel allows potential leak of credentials.

HIGH NVD Recent 2026-08-07

CVE-2026-17603:Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitra

HIGH NVD Recent 2026-08-07

CVE-2026-17601:A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional a

MEDIUM NVD Recent 2026-08-07

CVE-2026-17597:Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f

Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification

MEDIUM NVD Recent 2026-08-07

CVE-2025-6508:The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b

The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can

CRITICAL NVD Recent 2026-08-07

CVE-2025-14561:In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability a

MEDIUM NVD Recent 2026-08-07

CVE-2025-12317:When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue

When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges eve

MEDIUM NVD Recent 2026-08-07

CVE-2024-6541:The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be i

HIGH NVD Recent 2026-08-07

CVE-2024-39024:In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

LOW NVD Recent 2026-08-07

CVE-2025-15674:The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from

The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contrib

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。