最新预警列表

HIGH NVD Recent 2026-08-27

CVE-2026-66907:Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud

HIGH NVD Recent 2026-08-27

CVE-2026-32257:Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the

HIGH NVD Recent 2026-08-26

CVE-2026-35445:Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to inv

HIGH NVD Recent 2026-08-26

CVE-2026-78122:docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS en

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs,

HIGH NVD Recent 2026-08-26

CVE-2026-32258:Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LES

HIGH NVD Recent 2026-08-26

CVE-2026-9771:The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USE

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output bu

HIGH NVD Recent 2026-08-26

CVE-2026-54481:Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

HIGH NVD Recent 2026-08-26

CVE-2026-24791:Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

HIGH NVD Recent 2026-08-26

CVE-2026-13048:Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by ap

HIGH NVD Recent 2026-08-25

CVE-2026-0551:The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible

HIGH NVD Recent 2026-08-24

CVE-2026-16149:The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's user-enumeration protection, which is enabled by default, hooks the rest_endpoints

HIGH NVD Recent 2026-08-24

CVE-2026-78050:A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-b

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_ena

HIGH NVD Recent 2026-08-24

CVE-2026-47895:In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

HIGH NVD Recent 2026-08-20

CVE-2026-20320:A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are impro

HIGH NVD Recent 2026-08-20

CVE-2026-20319:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multipl

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。