最新预警列表

CRITICAL NVD Recent 2026-09-28

CVE-2024-58385:Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitiza

CRITICAL NVD Recent 2026-09-28

CVE-2026-20234:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This re

CRITICAL NVD Recent 2026-09-24

CVE-2023-54398:Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageS

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST

CRITICAL NVD Recent 2026-09-23

CVE-2026-90558:sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header val

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fiel

CRITICAL NVD Recent 2026-09-22

CVE-2026-90647:ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validatio

CRITICAL NVD Recent 2026-09-18

CVE-2026-20331:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has

CRITICAL NVD Recent 2026-09-18

CVE-2026-75156:Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because t

CRITICAL NVD Recent 2026-09-17

CVE-2026-46488:motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authenti

CRITICAL NVD Recent 2026-09-17

CVE-2026-20307:A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to exec

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have

CRITICAL NVD Recent 2026-09-17

CVE-2026-20306:A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform comman

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must

CRITICAL NVD Recent 2026-09-17

CVE-2026-20305:A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perfor

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the

CRITICAL NVD Recent 2026-09-15

CVE-2026-53710:MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sa

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_b

CRITICAL NVD Recent 2026-09-15

CVE-2026-52098:An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoin

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

CRITICAL NVD Recent 2026-09-15

CVE-2026-20353:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in softwar

CRITICAL NVD Recent 2026-09-15

CVE-2026-20279:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering t

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。