最新预警列表

MEDIUM NVD Recent 2026-09-11

CVE-2026-82469:Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a

MEDIUM NVD Recent 2026-09-11

CVE-2026-82468:Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF t

MEDIUM NVD Recent 2026-09-11

CVE-2026-82467:Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browse

CRITICAL NVD Recent 2026-09-11

CVE-2026-82466:Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account

HIGH NVD Recent 2026-09-11

CVE-2026-17615:A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unaut

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an end

HIGH NVD Recent 2026-09-11

CVE-2026-20293:A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-ba

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or a

HIGH NVD Recent 2026-09-11

CVE-2026-67277:RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized ta

HIGH NVD Recent 2026-09-11

CVE-2026-23855:Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions pri

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.

MEDIUM NVD Recent 2026-09-10

CVE-2026-16941:IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper au

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

MEDIUM NVD Recent 2026-09-10

CVE-2026-16660:IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bound

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

HIGH NVD Recent 2026-09-10

CVE-2026-73699:FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arb

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used i

HIGH NVD Recent 2026-09-10

CVE-2026-73693:FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authen

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attacke

MEDIUM NVD Recent 2026-09-10

CVE-2026-52097:An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (u

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

CRITICAL NVD Recent 2026-09-10

CVE-2026-88044:rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/ser

HIGH NVD Recent 2026-09-10

CVE-2026-85228:An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。