最新预警列表

CRITICAL NVD Recent 2026-09-09

CVE-2026-86478:In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

CRITICAL NVD Recent 2026-09-09

CVE-2026-67276:RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attac

CRITICAL Cisco PSIRT 2026-09-09

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected de

CRITICAL NVD Recent 2026-09-08

CVE-2023-42179:Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, pass

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.

CRITICAL NVD Recent 2026-09-08

CVE-2026-86219:Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified n

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against

CRITICAL NVD Recent 2026-09-08

CVE-2026-26084:A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8,

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via cr

CRITICAL CERT/CC VU 2026-09-08

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

Overview The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI

CRITICAL CERT/CC VU 2026-09-08

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before init

CRITICAL NVD Recent 2026-09-07

CVE-2026-84238:Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

CRITICAL openEuler 安全公告 OSV 2026-09-05

CVE-2025-37979:kernel security update

kernel security update

CRITICAL openEuler 安全公告 OSV 2026-09-05

CVE-2021-47358:kernel security update

kernel security update

CRITICAL openEuler 安全公告 OSV 2026-09-05

CVE-2026-68742:sssd security update

sssd security update

CRITICAL openEuler 安全公告 OSV 2026-09-05

CVE-2026-18307:gimp security update

gimp security update

CRITICAL openEuler 安全公告 OSV 2026-09-05

CVE-2026-56209:aom security update

aom security update

CRITICAL openEuler 安全公告 OSV 2026-09-05

CVE-2026-73072:vim security update

vim security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。