最新预警列表

CRITICAL Cisco PSIRT 2026-08-17

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access contro

CRITICAL Cisco PSIRT 2026-08-17

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 C

CRITICAL NVD Recent 2026-08-12

CVE-2026-8457:The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without

CRITICAL Cisco PSIRT 2026-08-12

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple i

CRITICAL CERT/CC VU 2026-08-11

VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure

Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. U

CRITICAL CERT/CC VU 2026-08-10

VU#614868: Opencart ecommerce platform contains directory traversal vulnerability

Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved pa

CRITICAL NVD Recent 2026-08-07

CVE-2026-58048:Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-58216:samba security update

samba security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-47180:python-zeroconf security update

python-zeroconf security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-59878:activemq security update

activemq security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-15588:glib2 security update

glib2 security update

CRITICAL openEuler 安全公告 OSV 2026-08-07

CVE-2026-15588:glib2 security update

glib2 security update

CRITICAL Cisco PSIRT 2026-08-07

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address m

CRITICAL CERT/CC VU 2026-08-06

VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively

CRITICAL openEuler 安全公告 OSV 2026-08-06

CVE-2026-31958:python-tornado security update

python-tornado security update

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。