最新预警列表

MEDIUM openEuler 安全公告 OSV 2026-08-07

CVE-2026-16313:sg3_utils security update

sg3_utils security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-15588:glib2 security update

glib2 security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-15588:glib2 security update

glib2 security update

HIGH NVD Recent 2026-08-07

CVE-2026-66032:libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server respo

CRITICAL Cisco PSIRT 2026-08-07

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address m

MEDIUM CISA KEV 2026-08-07

CVE-2026-8037:Progress Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

HIGH NVD Recent 2026-08-06

CVE-2026-17623:IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to i

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.

HIGH NVD Recent 2026-08-06

CVE-2026-17626:IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.

HIGH NVD Recent 2026-08-06

CVE-2026-20263:A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauth

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper

HIGH NVD Recent 2026-08-06

CVE-2026-20200:A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with lo

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbs

MEDIUM NVD Recent 2026-08-06

CVE-2026-20198:A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is du

HIGH NVD Recent 2026-08-06

CVE-2026-20124:A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerabilit

MEDIUM NVD Recent 2026-08-06

CVE-2026-20028:A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of

MEDIUM NVD Recent 2026-08-06

CVE-2026-54894:Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection and session namespace keys by passing arbitrary b

MEDIUM NVD Recent 2026-08-06

CVE-2026-55733:Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission scopes by passing arbitrary binari

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。