最新预警列表

HIGH NVD Recent 2026-07-22

CVE-2026-42566:Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The

HIGH NVD Recent 2026-07-22

CVE-2026-15829:A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecastin

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_c

HIGH NVD Recent 2026-07-22

CVE-2026-15432:When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a

HIGH NVD Recent 2026-07-21

CVE-2026-32825:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unl

HIGH NVD Recent 2026-07-21

CVE-2026-32824:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authentica

HIGH NVD Recent 2026-07-21

CVE-2026-32821:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user

HIGH NVD Recent 2026-07-21

CVE-2026-32820:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and stati

HIGH NVD Recent 2026-07-21

CVE-2026-32806:dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can

HIGH NVD Recent 2026-07-21

CVE-2026-10081:The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe

The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malici

HIGH NVD Recent 2026-07-20

CVE-2026-12592:The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu

The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the

HIGH NVD Recent 2026-07-20

CVE-2026-11349:The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0

The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated

HIGH NVD Recent 2026-07-17

CVE-2026-12691:Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

HIGH NVD Recent 2026-07-17

CVE-2026-13397:HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attribu

HIGH NVD Recent 2026-07-17

CVE-2026-10666:parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the

parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LEN + 1]) using a length of str_len - end - 1, where str_l

HIGH NVD Recent 2026-07-17

CVE-2026-13401:XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attribut

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。