最新预警列表

HIGH NVD Recent 2026-09-08

CVE-2026-16233:There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerabi

HIGH NVD Recent 2026-09-08

CVE-2026-16234:There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerabi

HIGH NVD Recent 2026-09-07

CVE-2026-81295:Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

HIGH NVD Recent 2026-09-05

CVE-2026-81773:Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

HIGH NVD Recent 2026-09-04

CVE-2026-52022:An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registr

An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components

HIGH NVD Recent 2026-09-04

CVE-2026-58566:Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentiall

Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

HIGH NVD Recent 2026-09-04

CVE-2026-81776:Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-84752:Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-84736:In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federato

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environm

HIGH NVD Recent 2026-09-03

CVE-2026-81300:Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

HIGH NVD Recent 2026-09-03

CVE-2026-81292:Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

HIGH NVD Recent 2026-09-03

CVE-2020-15878:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.

HIGH NVD Recent 2026-09-03

CVE-2020-15876:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address

HIGH NVD Recent 2026-09-03

CVE-2020-15874:An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary s

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

HIGH NVD Recent 2026-09-03

CVE-2026-19913:The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP sch

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。