最新预警列表

CRITICAL NVD Recent 2026-08-31

CVE-2026-82460:Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files ou

CRITICAL NVD Recent 2026-08-31

CVE-2025-36939:Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack

CRITICAL openEuler 安全公告 OSV 2026-08-30

CVE-2026-68743:sssd security update

sssd security update

CRITICAL openEuler 安全公告 OSV 2026-08-30

CVE-2026-44024:rubygem-fluentd security update

rubygem-fluentd security update

CRITICAL openEuler 安全公告 OSV 2026-08-30

CVE-2026-71217:iperf3 security update

iperf3 security update

CRITICAL CERT/CC VU 2026-08-28

VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

Overview The Kaltura HTML5 Player V2 Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.

CRITICAL NVD Recent 2026-08-27

CVE-2026-66906:Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download

CRITICAL NVD Recent 2026-08-27

CVE-2026-71300:Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects

CRITICAL NVD Recent 2026-08-26

CVE-2026-73041:SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endp

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access

CRITICAL NVD Recent 2026-08-26

CVE-2026-73042:SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to ex

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that clo

CRITICAL NVD Recent 2026-08-26

CVE-2026-55982:OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

CRITICAL NVD Recent 2026-08-26

CVE-2026-78183:DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infini

CRITICAL NVD Recent 2026-08-26

CVE-2026-13051:Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTM

CRITICAL NVD Recent 2026-08-26

CVE-2022-4993:HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_e

CRITICAL CERT/CC VU 2026-08-24

VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow

Overview Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitrary code on lobby members' machines through specially craft

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。