最新预警列表

HIGH NVD Recent 2026-09-15

CVE-2026-73698:FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate ra

HIGH NVD Recent 2026-09-15

CVE-2026-82209:When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Co

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by

HIGH NVD Recent 2026-09-15

CVE-2026-82208:With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by

HIGH NVD Recent 2026-09-15

CVE-2026-80255:A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTT

HIGH NVD Recent 2026-09-15

CVE-2026-80231:A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a diffe

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

HIGH NVD Recent 2026-09-15

CVE-2026-80230:When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VER

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presen

HIGH NVD Recent 2026-09-15

CVE-2026-80229:When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handl

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to Ope

CRITICAL NVD Recent 2026-09-15

CVE-2026-19931:A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, w

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated

CRITICAL NVD Recent 2026-09-15

CVE-2026-18924:A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with othe

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

HIGH NVD Recent 2026-09-15

CVE-2026-13608:A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpre

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or short

CRITICAL NVD Recent 2026-09-15

CVE-2026-72710:SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attac

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter re

CRITICAL NVD Recent 2026-09-15

CVE-2026-72709:SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission

MEDIUM NVD Recent 2026-09-14

CVE-2026-15923:The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O l

The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_size is decoded dire

LOW NVD Recent 2026-09-14

CVE-2026-90574:A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be perf

MEDIUM NVD Recent 2026-09-14

CVE-2026-90571:A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functio

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。