最新预警列表

MEDIUM NVD Recent 2026-08-07

CVE-2026-12501:The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowin

CRITICAL NVD Recent 2026-08-07

CVE-2026-11976:The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`

MEDIUM NVD Recent 2026-08-07

CVE-2026-11361:The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme

The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content

HIGH NVD Recent 2026-08-07

CVE-2026-10599:The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact

The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthen

HIGH NVD Recent 2026-08-07

CVE-2026-10524:The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price

The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product

MEDIUM CERT/CC VU 2026-08-07

VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability

Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. D

HIGH NVD Recent 2026-08-07

CVE-2026-17630:IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.

MEDIUM openEuler 安全公告 OSV 2026-08-07

CVE-2026-56389:bison security update

bison security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-58216:samba security update

samba security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-47180:python-zeroconf security update

python-zeroconf security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-59878:activemq security update

activemq security update

HIGH openEuler 安全公告 OSV 2026-08-07

CVE-2026-17572:hdf5 security update

hdf5 security update

HIGH openEuler 安全公告 OSV 2026-08-07

CVE-2026-17572:hdf5 security update

hdf5 security update

HIGH openEuler 安全公告 OSV 2026-08-07

CVE-2026-17572:hdf5 security update

hdf5 security update

MEDIUM openEuler 安全公告 OSV 2026-08-07

CVE-2026-15003:gdb security update

gdb security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。