最新预警列表

HIGH NVD Recent 2026-07-28

CVE-2026-64830:FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allo

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than t

HIGH NVD Recent 2026-07-28

CVE-2026-63720:datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-

HIGH NVD Recent 2026-07-28

CVE-2026-65707:Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogi

HIGH NVD Recent 2026-07-28

CVE-2026-24252:NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

HIGH NVD Recent 2026-07-27

CVE-2026-15962:The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level acces

HIGH NVD Recent 2026-07-27

CVE-2026-17497:NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|

HIGH NVD Recent 2026-07-27

CVE-2026-17496:NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content tha

HIGH NVD Recent 2026-07-27

CVE-2026-65711:sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupS

HIGH NVD Recent 2026-07-27

CVE-2026-65710:sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting t

HIGH NVD Recent 2026-07-27

CVE-2026-65709:sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-accoun

HIGH NVD Recent 2026-07-27

CVE-2026-65708:sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorizat

HIGH NVD Recent 2026-07-27

CVE-2026-12493:The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allow

HIGH NVD Recent 2026-07-27

CVE-2026-12255:The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a val

HIGH NVD Recent 2026-07-27

CVE-2025-15662:The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arb

HIGH NVD Recent 2026-07-27

CVE-2026-15928:XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。