最新预警列表

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-56209:aom security update

aom security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-53466:ImageMagick security update

ImageMagick security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-12087:perl security update

perl security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-54273:python-aiohttp security update

python-aiohttp security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-48487:python-zeroconf security update

python-zeroconf security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-2923:gstreamer1-plugins-bad-free security update

gstreamer1-plugins-bad-free security update

CRITICAL openEuler 安全公告 OSV 2026-07-06

CVE-2026-42055:nginx security update

nginx security update

CRITICAL NVD Recent 2026-07-02

CVE-2022-50973:Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and f

CRITICAL NVD Recent 2026-07-02

CVE-2024-14037:Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with

CRITICAL CERT/CC VU 2026-07-02

VU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat

Overview The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attack

CRITICAL NVD Recent 2026-07-01

CVE-2026-11720:A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string

CRITICAL NVD Recent 2026-07-01

CVE-2026-5366:Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--`

CRITICAL NVD Recent 2026-06-30

CVE-2026-58053:Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options suc

CRITICAL NVD Recent 2026-06-29

CVE-2026-54636:Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; -

CRITICAL NVD Recent 2026-06-26

CVE-2026-45408:Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-re

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。