最新预警列表

MEDIUM NVD Recent 2026-06-25

CVE-2025-13162:Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affect

Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.

LOW NVD Recent 2026-06-25

CVE-2026-13350:Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b

Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

HIGH NVD Recent 2026-06-25

CVE-2026-13164:Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap

Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where re

HIGH NVD Recent 2026-06-25

CVE-2026-45233:HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re

HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the oldfile parameter at the admin autosave endpoint. Attackers ca

HIGH NVD Recent 2026-06-25

CVE-2025-61027:An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

HIGH CISA KEV 2026-06-25

CVE-2026-20230:Cisco Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write

HIGH CISA KEV 2026-06-25

CVE-2026-12569:PTC PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

LOW NVD Recent 2026-06-24

CVE-2026-12770:A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper au

LOW NVD Recent 2026-06-24

CVE-2026-12771:A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be lau

LOW NVD Recent 2026-06-24

CVE-2026-12772:A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in se

CRITICAL NVD Recent 2026-06-24

CVE-2026-52949:In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on b

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure Apply the same fix as b2ed01e7ad ("drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure") to the ttm_bo_sh

CRITICAL NVD Recent 2026-06-24

CVE-2026-10789:A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to ex

MEDIUM openEuler 安全公告 OSV 2026-06-24

CVE-2026-49261:mariadb security update

mariadb security update

CRITICAL openEuler 安全公告 OSV 2026-06-24

CVE-2026-49853:python-tornado security update

python-tornado security update

MEDIUM openEuler 安全公告 OSV 2026-06-24

CVE-2025-58063:coredns security update

coredns security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。