最新预警列表

HIGH NVD Recent 2026-09-22

CVE-2026-18111:Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validate

CRITICAL CERT-EU 2026-09-22

2026-013: Critical Vulnerability in F5 BIG-IP APM

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

HIGH NVD Recent 2026-09-22

CVE-2026-19780:Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists withi

HIGH NVD Recent 2026-09-22

CVE-2026-18110:Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates onl

CRITICAL CERT/CC VU 2026-09-22

VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash i

HIGH CISA KEV 2026-09-22

CVE-2026-85102:Check Point Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

MEDIUM CISA KEV 2026-09-22

CVE-2026-93616:Check Point Check Point Multiple Products Path Traversal Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

HIGH CISA KEV 2026-09-22

CVE-2026-94127:F5 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

HIGH CISA KEV 2026-09-22

CVE-2026-93952:Arista Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentialit

HIGH NVD Recent 2026-09-21

CVE-2026-71179:Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vul

MEDIUM CISA KEV 2026-09-21

CVE-2026-7273:Zyxel Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

MEDIUM openEuler 安全公告 OSV 2026-09-20

CVE-2026-82455:ruby security update

ruby security update

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2026-53612:util-linux security update

util-linux security update

MEDIUM openEuler 安全公告 OSV 2026-09-20

CVE-2026-16615:rest security update

rest security update

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2026-82397:python-tornado security update

python-tornado security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。