最新预警列表

HIGH NVD Recent 2026-08-04

CVE-2026-17107:A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removin

HIGH CISA KEV 2026-08-04

CVE-2026-9198:IBM IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

MEDIUM CISA KEV 2026-08-04

CVE-2026-34486:Apache Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

MEDIUM CISA KEV 2026-08-04

CVE-2026-18556:N-able N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

MEDIUM NVD Recent 2026-08-03

CVE-2025-15675:The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, allowing users with a high-privilege campaign-management role to perform Stored Cross-Site Script

MEDIUM NVD Recent 2026-08-03

CVE-2026-9335:A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `

HIGH NVD Recent 2026-08-03

CVE-2026-3245:A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

MEDIUM NVD Recent 2026-08-03

CVE-2026-57978:Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-57989:Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-57990:Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

HIGH NVD Recent 2026-08-03

CVE-2026-17568:Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API requ

MEDIUM CISA KEV 2026-08-03

CVE-2026-18577:N-able N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

MEDIUM NVD Recent 2026-08-01

CVE-2026-17002:Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CRITICAL openEuler 安全公告 OSV 2026-08-01

CVE-2025-71273:kernel security update

kernel security update

MEDIUM openEuler 安全公告 OSV 2026-08-01

CVE-2026-9499:qt6-qt5compat security update

qt6-qt5compat security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。