最新预警列表

HIGH NVD Recent 2026-07-28

CVE-2026-64830:FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allo

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than t

CRITICAL NVD Recent 2026-07-28

CVE-2026-17552:Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten

Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call. When the rewrite base is a plain string, the REQUEST_URI is appended to it, with no check that the path starts with a f

LOW NVD Recent 2026-07-28

CVE-2026-17531:A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Re

HIGH NVD Recent 2026-07-28

CVE-2026-63720:datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-

HIGH NVD Recent 2026-07-28

CVE-2026-65707:Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogi

HIGH NVD Recent 2026-07-28

CVE-2026-24252:NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

LOW NVD Recent 2026-07-27

CVE-2026-17433:A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorizati

HIGH NVD Recent 2026-07-27

CVE-2026-15962:The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level acces

HIGH NVD Recent 2026-07-27

CVE-2026-17497:NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|

HIGH NVD Recent 2026-07-27

CVE-2026-17496:NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content tha

HIGH NVD Recent 2026-07-27

CVE-2026-65711:sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupS

HIGH NVD Recent 2026-07-27

CVE-2026-65710:sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting t

HIGH NVD Recent 2026-07-27

CVE-2026-65709:sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-accoun

HIGH NVD Recent 2026-07-27

CVE-2026-65708:sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorizat

MEDIUM NVD Recent 2026-07-27

CVE-2026-12982:The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploit

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。