最新预警列表

CRITICAL NVD Recent 2026-09-11

CVE-2026-54047:Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior t

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side sta

CRITICAL NVD Recent 2026-09-11

CVE-2026-82466:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account

CRITICAL NVD Recent 2026-09-10

CVE-2026-88044:rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/ser

CRITICAL NVD Recent 2026-09-10

CVE-2026-68488:A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privileg

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

CRITICAL NVD Recent 2026-09-10

CVE-2026-68487:Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

CRITICAL NVD Recent 2026-09-10

CVE-2026-65639:OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who contro

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The

CRITICAL NVD Recent 2026-09-10

CVE-2026-65638:Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to exe

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software ori

CRITICAL NVD Recent 2026-09-10

CVE-2026-47156:MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP

MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowing their username)

CRITICAL CERT-EU 2026-09-10

2026-012: Critical Vulnerabilities in Check Point Products

On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-

CRITICAL NVD Recent 2026-09-09

CVE-2026-78997:UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulner

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL

CRITICAL CERT/CC VU 2026-09-09

VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

Overview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Description Calix GS7 XGS GS5239XG

CRITICAL NVD Recent 2026-09-09

CVE-2026-79570:mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbCon

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

CRITICAL NVD Recent 2026-09-09

CVE-2026-79569:Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. Th

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

CRITICAL CERT-EU 2026-09-09

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerabi

CRITICAL NVD Recent 2026-09-09

CVE-2026-86480:In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。