最新预警列表

MEDIUM CERT/CC VU 2026-08-12

VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An

CRITICAL CERT/CC VU 2026-08-11

VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure

Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. U

CRITICAL CERT/CC VU 2026-08-10

VU#614868: Opencart ecommerce platform contains directory traversal vulnerability

Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved pa

MEDIUM CERT/CC VU 2026-08-07

VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability

Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. D

CRITICAL CERT/CC VU 2026-08-06

VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations

Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively

HIGH CERT/CC VU 2026-08-05

VU#360868: Local Privilege escalation vulnerability in Analog Way Picturall Quad Compact Mark II version 3.5.8

Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. De

CRITICAL CERT/CC VU 2026-07-31

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

Overview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual

CRITICAL CERT/CC VU 2026-07-30

VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure

Overview Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation doe

CRITICAL CERT/CC VU 2026-07-30

VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities

Overview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is

CRITICAL CERT/CC VU 2026-07-29

VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)

Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and uns

CRITICAL CERT/CC VU 2026-07-28

VU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface

Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modi

CRITICAL CERT/CC VU 2026-07-23

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can tri

CRITICAL CERT/CC VU 2026-07-23

VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA

CRITICAL CERT/CC VU 2026-07-22

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability

Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execut

CRITICAL CERT/CC VU 2026-07-21

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other works

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。