最新预警列表

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-12087:perl security update

perl security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-54273:python-aiohttp security update

python-aiohttp security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-48487:python-zeroconf security update

python-zeroconf security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-2923:gstreamer1-plugins-bad-free security update

gstreamer1-plugins-bad-free security update

MEDIUM openEuler 安全公告 OSV 2026-07-06

CVE-2026-47770:jq security update

jq security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-42055:nginx security update

nginx security update

HIGH NVD Recent 2026-07-03

CVE-2026-12912:A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLo

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a sp

HIGH NVD Recent 2026-07-02

CVE-2026-50281:Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw

Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through t

CRITICAL NVD Recent 2026-07-02

CVE-2022-50973:Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and f

MEDIUM NVD Recent 2026-07-02

CVE-2026-50282:Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and

Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without d

CRITICAL NVD Recent 2026-07-02

CVE-2024-14037:Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with

MEDIUM NVD Recent 2026-07-02

CVE-2026-13211:The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption ke

The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role.

HIGH NVD Recent 2026-07-02

CVE-2026-58166:OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by supplying a malicious multipart filename in the file upload endpoint. Attack

HIGH NVD Recent 2026-07-02

CVE-2024-58352:Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr

Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attack

HIGH NVD Recent 2026-07-02

CVE-2026-58165:OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated

OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。