最新预警列表

CRITICAL NVD Recent 2026-08-20

CVE-2026-20315:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multipl

CRITICAL NVD Recent 2026-08-20

CVE-2026-20231:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multipl

CRITICAL NVD Recent 2026-08-20

CVE-2026-20318:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multipl

CRITICAL NVD Recent 2026-08-20

CVE-2026-20317:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multipl

CRITICAL NVD Recent 2026-08-20

CVE-2026-18963:A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process f

CRITICAL NVD Recent 2026-08-20

CVE-2026-20030:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple inte

CRITICAL NVD Recent 2026-08-20

CVE-2026-18855:The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers

CRITICAL NVD Recent 2026-08-20

CVE-2026-19598:The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access ch

CRITICAL NVD Recent 2026-08-19

CVE-2026-19626:A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authentica

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during serv

CRITICAL NVD Recent 2026-08-18

CVE-2026-71947:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands in

CRITICAL NVD Recent 2026-08-17

CVE-2026-71952:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the ol

CRITICAL NVD Recent 2026-08-14

CVE-2026-20267:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple i

CRITICAL NVD Recent 2026-08-12

CVE-2026-8457:The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without

CRITICAL NVD Recent 2026-08-12

CVE-2026-12571:An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

CRITICAL NVD Recent 2026-08-11

CVE-2026-71951:D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_va

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。