| Tenable (Nessus) [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| f622afac802264599c17241afaec88de |
CVE-2026-19904 |
2026-08-15 18:31:18  |
A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability... |
详情 |
| ef5a514def43f47028b2ba18dfc18c91 |
CVE-2026-19903 |
2026-08-15 17:45:07  |
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
详情 |
| 89507a9e77ac901adbe05e89ff4a7e3d |
CVE-2026-19598 |
2026-08-15 17:25:26  |
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON meta-box-loader compatibility path only writes failures to the PHP error log and returns false instead of terminating the request, rendering all guards ineffective. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, enabling complete site takeover, or perform another administrator action. |
详情 |
| 177bd0cbffa21564c3cf9c4953140b75 |
CVE-2026-19900 |
2026-08-15 17:16:24  |
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. |
详情 |
| c22f4d30e6c4da22f7f028d6267ac54f |
CVE-2026-19899 |
2026-08-15 17:16:23  |
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
详情 |
| 50adfacc964ec10112d913c2cd1d01dd |
CVE-2026-19901 |
2026-08-15 17:15:07  |
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. |
详情 |
| e7dbb61329a4ea73e7c9794b734248e9 |
CVE-2026-19898 |
2026-08-15 16:16:39  |
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been made public and could be used. Upgrading to version 1.147.0 is recommended to address this issue. The patch is named 119ba0fb5be8024d50c5ba946599b2e69e8803ea. Upgrading the affected component is recommended. |
详情 |
| 56f30d3d2d4f2c816902d48ea3ec8ff8 |
CVE-2026-19897 |
2026-08-15 16:16:38  |
A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
详情 |
| f84fa15b33d48c522a1d46501beadbe5 |
CVE-2026-19896 |
2026-08-15 15:16:37  |
A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance. |
详情 |
| 5392596a35a2ef0bea95d96d952dca18 |
CVE-2026-19895 |
2026-08-15 14:17:07  |
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
详情 |
| 63501a8e843a471c2492ccfe63cabfd4 |
CVE-2026-73846 |
2026-08-14 17:20:36  |
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime a shared cache with a response for a victim's distinct query. This issue is fixed in version 0.4.112. |
详情 |
| f19218b379271ded44f9707434459b12 |
CVE-2026-73845 |
2026-08-14 17:20:36  |
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-host and URL-userinfo values to target an attacker-controlled host and return a spoofed response. This issue is fixed in version 0.4.112. |
详情 |
| 5f46974d78b042ac56a47af926e05c22 |
CVE-2026-73844 |
2026-08-14 17:20:36  |
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response, or when an internal exception occurs, the caller receives verbatim upstream content and internal detail (hostnames, internal IPs, DB errors, stack fragments). This vulnerability is fixed in 0.4.112. |
详情 |
| e1cd9cd8eda562aa9ebf6bcdfa9a048a |
CVE-2026-73107 |
2026-08-14 17:20:32  |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
详情 |
| 53a53d8b4eb58b7c7c11149fcf9d4ad2 |
CVE-2026-49989 |
2026-08-14 17:18:27  |
CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob storage: SQL (`SELECT ... FROM blob.` and friends) and the blob HTTP API (`GET|PUT|DELETE /_blobs/{table}/{digest}`). The SQL path goes through `AccessControl`, which is what enforces privilege grants; that's why `SELECT digest FROM blob.secret_blobs` fails for a user who has no grants on the table. The HTTP path authenticates the request but never asks `AccessControl` whether the authenticated user is allowed to touch the table. So a user with no grants gets `MissingPrivilegeException` from SQL and `200 OK` plus the blob bytes from `GET /_blobs/secret_blobs/`. Deployments that don't use `BLOB TABLE` are unaffected. Authentication itself still works; the bug is strictly that being authenticated as anyone is treated as sufficient for any blob op. Versions 6.2.8 and 6.3.2 fix the issue.
| 详情 |
| 0785ed94e24d03931a0a2f1cc0e07094 |
CVE-2026-49986 |
2026-08-14 17:18:27  |
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is invoked, `_find_dev_source()` resolves the user's active project directory as a candidate Cortex source root. The only validation performed by `_is_cortex_root()` is a check for the presence of an `mcp_server/` subdirectory and a `ui/unified-viz.html` file. An attacker who places these two marker files in a malicious repository can cause Cortex to execute an arbitrary `mcp_server/server/visualize_bootstrap.py` from that directory via `subprocess.run([sys.executable, ...])`, achieving code execution with the privileges of the victim's local user process. Version 3.17.1 fixes the issue. |
详情 |
| 922a0972b7714125d4bd67fff95dd0f6 |
CVE-2026-49826 |
2026-08-14 17:18:27  |
Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available. |
详情 |
| cc4e59226b337d749e9b82bb030bff13 |
CVE-2026-47766 |
2026-08-14 17:18:18  |
crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and creates the default device nodes and stdio symlinks at the symlink target outside the container rootfs. In a local rootful crun replay, this created fixed device nodes and symlinks outside the rootfs before crun returned failure. A pre-existing file named `ptmx` in the target directory was also replaced by crun's forced `ptmx -> pts/ptmx` symlink. Version 1.28 fixes the issue. |
详情 |
| 79cae1ed9dd5fba62eb4946f655373f0 |
CVE-2026-47192 |
2026-08-14 17:18:15  |
kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository with one under the control of an attacker under very specific conditions. First of all, the attacker must have gained control of a repository that a kas file of the victim is referencing. Furthermore, the following conditions must be fulfilled: the victim's kas configuration must include a configuration file from the attacked repository; the repository state is referenced by tag, and no commit ID is specified (this is triggering a warning, though); the key used for validating the tag or commit signature is stored as file in a repository; no fingerprint for the key is specified; and the `_source_dir` key must not be set by the victim when calling kas (e.g. by avoiding a local `.config.yaml`). Given these conditions, the attacker could modify the included kas configuration in way that the key used to validate the tag signature of the attacker's repository could be replaced by an attacker-chosen key. No other exploit possibilities have been identified so far, but this does not rule out that those may exist. All patches have been released along with kas version 5.3. As a workaround, pin the expected signature key via its fingerprint, also when storing it as file in a repository. |
详情 |
| 598d113dafae4586ba93fb70945ce69d |
CVE-2026-47191 |
2026-08-14 17:18:15  |
kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository. This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5.3 fixes the issue. As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party. If available, additional validate cryptographically signed commits or tags. Alternatively, mirror the repository to a save place, validate its integrity, and use this instead of the original one. |
详情 |
| f664e82ac62d7a9b71f1c9aef5395d27 |
CVE-2026-73557 |
2026-08-13 15:20:18 |
vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and restore state can be raced by concurrent prompt_embeds parts submitted to POST /v1/chat/completions through AsyncMultiModalItemTracker.resolve_items, asyncio.gather, and the default executor, allowing an invalid sparse tensor to reach tensor.to_dense despite the CVE-2025-62164 guard when enable_prompt_embeds is enabled. This issue is fixed in version 0.26.0. |
详情 |
| a35918316bdb7a026fb1d73934fa0a96 |
CVE-2026-73556 |
2026-08-13 15:20:17 |
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_output_request_lm_format_enforcer, allowing an unauthenticated /v1/completions request against the lm-format-enforcer backend to consume a CPU core and stall the structured-output engine path with a catastrophic regular expression. This issue is fixed in version 0.26.0. |
详情 |
| de82edc4c38378ab667ff89dc66ee727 |
CVE-2026-73509 |
2026-08-13 15:20:17 |
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renameObject.SrcName, supplied as src_name, before concatenating it with the authorized path and passing the result to fs.Rename. A user with rename permission can use traversal segments in src_name to make path normalization select a file outside the authorized directory and configured base path, resulting in cross-user file integrity loss, limited availability impact, and file-existence disclosure through success or error responses. This issue is fixed in version 4.2.4. |
详情 |
| 415bf674469d9d8baea3a205bc652239 |
CVE-2026-73505 |
2026-08-13 15:20:16 |
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current user whenever the prompt rendered inside that directory or a descendant. This issue is fixed in version 29.35.1. |
详情 |
| 2f053d73bb4b2247d8e989182b27a620 |
CVE-2026-70464 |
2026-08-13 15:20:01 |
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients. |
详情 |
| 8efb182308629661017ea0987d02a812 |
CVE-2026-70463 |
2026-08-13 15:20:01 |
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing. |
详情 |
| 9f48b36618b1288757e81864734911ea |
CVE-2026-70460 |
2026-08-13 15:19:59 |
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent. |
详情 |
| 2cd13d0634a3dc2ab5173772cc9d1670 |
CVE-2026-70459 |
2026-08-13 15:19:59 |
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection. |
详情 |
| 4125947c5b6e43d8088167a05b47c745 |
CVE-2026-70456 |
2026-08-13 15:19:59 |
rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory. |
详情 |
| 01d7092f0564674aa8f207dc717025ec |
CVE-2026-70455 |
2026-08-13 15:19:59 |
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources. |
详情 |
| 国家信息安全漏洞共享平台(CNVD) [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| 8686fda9b2b49e4e1666b54e2248f935 |
CNVD-2021-74882 |
2021-11-14 16:43:52 |
四创科技有限公司建站系统存在SQL注入漏洞 |
详情 |
| 8f6972d84ad188b05ff9cc14d4334949 |
CNVD-2021-87021 (CVE-2020-4690) |
2021-11-12 12:43:14 |
IBM Security Guardium硬编码凭证漏洞 |
详情 |
| 3bfe7b053a0c59d8a3d38c18f86aa143 |
CNVD-2021-87022 (CVE-2021-38870) |
2021-11-12 12:43:12 |
IBM Aspera跨站脚本漏洞 |
详情 |
| a4649bb17f4db4d1c7f879ebceb46ed0 |
CNVD-2021-87011 (CVE-2021-29753) |
2021-11-12 12:43:11 |
IBM Business Automation Workflow存在未明漏洞 |
详情 |
| 094c613f9ed4b8b9d887dc912789043c |
CNVD-2021-87025 (CVE-2021-20563) |
2021-11-12 12:43:10 |
IBM Sterling File Gateway信息泄露漏洞 |
详情 |
| 41c47f01a4c65dcb6efc9ebf483fe762 |
CNVD-2021-87010 (CVE-2021-38887) |
2021-11-12 12:43:08 |
IBM InfoSphere Information Server信息泄露漏洞 |
详情 |
| f51d33e7a09fd61ca90ede453515a830 |
CNVD-2021-87016 (CVE-2021-29764) |
2021-11-12 12:43:07 |
IBM Sterling B2B Integrator跨站脚本漏洞 |
详情 |
| 33615a5f78df822e82e6d3436045c48c |
CNVD-2021-87026 (CVE-2021-38877) |
2021-11-12 12:43:06 |
IBM Jazz for Service Management跨站脚本漏洞 |
详情 |
| 8e729177bcb4105dd831fb1e123ed1bb |
CNVD-2021-87014 (CVE-2021-29679) |
2021-11-12 12:43:04 |
IBM Cognos Analytics远程代码执行漏洞 |
详情 |
| 1a3b856f78e9fbdca12aeddc7d665aca |
CNVD-2021-87029 (CVE-2021-29752) |
2021-11-12 12:43:03 |
IBM Db2信息泄露漏洞 |
详情 |
| 6f1aa3a0cb819d97519baa47fd0232d5 |
CNVD-2021-87015 (CVE-2021-29745) |
2021-11-12 12:43:02 |
IBM Cognos Analytics权限提升漏洞 |
详情 |
| cbcb12f5f51d6e7d6d8a9fa581aa863a |
CNVD-2021-73908 |
2021-11-11 16:42:44 |
泛微e-cology存在SQL注入漏洞 |
详情 |
| ae6fd467da55de31aa7219187cf5c2d4 |
CNVD-2021-86904 (CVE-2021-20351) |
2021-11-11 08:31:46 |
IBM Engineering跨站脚本漏洞 |
详情 |
| 412a15b40959ed9cf9330ee79f99e079 |
CNVD-2021-86903 (CVE-2021-31173) |
2021-11-11 08:31:44 |
Microsoft SharePoint Server信息泄露漏洞 |
详情 |
| 1cbc5d5faac431d3e82c9e5ea9588b5f |
CNVD-2021-86902 (CVE-2021-31172) |
2021-11-11 08:31:43 |
Microsoft SharePoint欺骗漏洞 |
详情 |
| 686c7cfb20933b41c3d679cbba79a2ad |
CNVD-2021-86901 (CVE-2021-31181) |
2021-11-11 08:31:42 |
Microsoft SharePoint远程代码执行漏洞 |
详情 |
| 72fdfb2d44c0d41d638e4632bdfc10b8 |
CNVD-2021-86900 (CVE-2021-3561) |
2021-11-11 08:31:41 |
fig2dev缓冲区溢出漏洞 |
详情 |
| 3ba6f0e9394f9414e2cadb9495e2d5f5 |
CNVD-2021-85884 (CVE-2021-41210) |
2021-11-10 07:24:57 |
Google TensorFlow堆分配数组越界读取漏洞 |
详情 |
| 4d8c4744ea972fb2fcb9673fea1fc7b7 |
CNVD-2021-85883 (CVE-2021-41226) |
2021-11-10 07:24:56 |
Google TensorFlow堆越界访问漏洞 |
详情 |
| 8778f9cd924cae585ca5e2e0b8be3b3f |
CNVD-2021-85882 (CVE-2021-41224) |
2021-11-10 07:24:54 |
Google TensorFlow堆越界访问漏洞 |
详情 |
| e1b2722e6d5c509c680b584416d9cb20 |
CNVD-2021-85881 (CVE-2021-42770) |
2021-11-10 07:24:53 |
OPNsense跨站脚本漏洞 |
详情 |
| ed09c9fa5586e2d4d9b4e95fe3b447a0 |
CNVD-2021-85880 (CVE-2021-28024) |
2021-11-10 07:24:52 |
ServiceTonic访问控制不当漏洞 |
详情 |
| 8a642f0922f7f915e81b2b947276a96c |
CNVD-2021-85879 (CVE-2021-28023) |
2021-11-10 07:24:50 |
ServiceTonic任意文件上传漏洞 |
详情 |
| c00b061c2cfdee4016a869a188135db5 |
CNVD-2021-85878 (CVE-2021-28022) |
2021-11-10 07:24:49 |
ServiceTonic SQL注入漏洞 |
详情 |
| 9c4b20a28ad2bd4ab916448f0e1272bd |
CNVD-2021-85877 (CVE-2021-32483) |
2021-11-10 07:24:48 |
Cloudera Manager不正确访问控制漏洞 |
详情 |
| 4d4423857b7b1f38e49738f00e8949ba |
CNVD-2021-85876 (CVE-2021-32481) |
2021-11-10 07:24:46 |
Cloudera Hue跨站脚本漏洞 |
详情 |
| 6b12b7fc216d603e8e07351603851c86 |
CNVD-2021-85875 (CVE-2021-29994) |
2021-11-10 07:24:45 |
Cloudera Hue跨站脚本漏洞 |
详情 |
| 72894fb3a3538de240d2f6810aae63c9 |
CNVD-2021-85892 (CVE-2021-42701) |
2021-11-10 02:38:27 |
DAQFactory中间人攻击漏洞 |
详情 |
| 94a1f99a64ba24540cc1594d0a0b3152 |
CNVD-2021-85893 (CVE-2021-42699) |
2021-11-10 02:38:26 |
DAQFactory明文传输漏洞 |
详情 |
| 5d9bac33be8f2f88391f6de02fb89c73 |
CNVD-2021-85894 (CVE-2021-42698) |
2021-11-10 02:38:24 |
DAQFactory反序列化漏洞 |
详情 |
| 国家信息安全漏洞库(CNNVD) [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| b5815af17792cf5abac5732bae3094e9 |
CNNVD-202308-131 (CVE-2023-20215) |
2023-08-03 12:41:47 |
Cisco Secure Web Appliance 安全漏洞 |
详情 |
| 8d98bb094a70919c9e881cc7da5898d4 |
CNNVD-202308-132 (CVE-2023-20204) |
2023-08-03 12:40:44 |
Cisco BroadWorks CommPilot 安全漏洞 |
详情 |
| c65e18d821cb73d6036dc2df6a726951 |
CNNVD-202308-123 (CVE-2023-29409) |
2023-08-02 12:45:03 |
Google Golang 资源管理错误漏洞 |
详情 |
| 452c53b54ef3a658eaf6bd8e7d93fe05 |
CNNVD-202308-124 (CVE-2023-4070) |
2023-08-02 12:44:01 |
Google Chrome 安全漏洞 |
详情 |
| ac7b17414d163c2f26008516638e3a99 |
CNNVD-202308-125 (CVE-2023-39113) |
2023-08-02 12:42:59 |
ngiflib 安全漏洞 |
详情 |
| 224fd467b813dbee234efe1e61e2ec66 |
CNNVD-202308-126 (CVE-2023-39114) |
2023-08-02 12:42:57 |
ngiflib 安全漏洞 |
详情 |
| 72d862f454eb3d0e4dd221413d85f6b2 |
CNNVD-202308-127 (CVE-2023-1437) |
2023-08-02 12:42:55 |
Advantech WebAccess/SCADA 安全漏洞 |
详情 |
| a3b636c53a2116b7ab85ea0c29470e76 |
CNNVD-202308-128 (CVE-2023-3329) |
2023-08-02 12:42:53 |
SpiderControl SCADA Webserver 路径遍历漏洞 |
详情 |
| 0e8e3c3600e145e70920c2026bde8feb |
CNNVD-202308-129 (CVE-2023-4069) |
2023-08-02 12:42:51 |
Google Chrome 安全漏洞 |
详情 |
| 619ce483843859fb783525b2b8d00f59 |
CNNVD-202308-130 (CVE-2023-4068) |
2023-08-02 12:41:48 |
Google Chrome 安全漏洞 |
详情 |
| 6a73381eaa628503bd8c242cd313f005 |
CNNVD-202308-057 (CVE-2023-36121) |
2023-08-01 12:48:12 |
e107 跨站脚本漏洞 |
详情 |
| 086c171bc44677f87e0ad45c8ab5dab6 |
CNNVD-202308-058 (CVE-2023-2164) |
2023-08-01 12:47:10 |
GitLab 跨站脚本漏洞 |
详情 |
| bc6915cfb72ce7e27f2aa64ff3a35ee2 |
CNNVD-202308-059 (CVE-2023-31432) |
2023-08-01 12:47:08 |
Brocade Fabric OS 安全漏洞 |
详情 |
| 915090fa2939ee9d9978125be4eeff27 |
CNNVD-202308-060 (CVE-2023-3739) |
2023-08-01 12:46:07 |
Google Chrome 安全漏洞 |
详情 |
| b790441bc923d37c914ea50edcdfaa16 |
CNNVD-202308-061 (CVE-2023-3385) |
2023-08-01 12:46:05 |
GitLab 路径遍历漏洞 |
详情 |
| a6be4479387eddda68e1c7808965c1bc |
CNNVD-202308-062 (CVE-2022-40609) |
2023-08-01 12:46:03 |
IBM SDK, Java Technology Edition 安全漏洞 |
详情 |
| 55409ee74ffe87168f7d61814b568334 |
CNNVD-202308-063 (CVE-2023-31431) |
2023-08-01 12:46:02 |
Brocade Fabric OS 安全漏洞 |
详情 |
| a4340da9d26800c671fa800a080c3d01 |
CNNVD-202308-064 (CVE-2023-36210) |
2023-08-01 12:45:00 |
MotoCMS 安全漏洞 |
详情 |
| d70ae2187ae1aa50a2af6befce15bfbd |
CNNVD-202308-065 (CVE-2023-31428) |
2023-08-01 12:43:58 |
Brocade Fabric OS 代码问题漏洞 |
详情 |
| 8b0e98f117732e813318bdec77d0fb4b |
CNNVD-202308-066 (CVE-2023-31928) |
2023-08-01 12:42:57 |
Brocade Fabric OS 跨站脚本漏洞 |
详情 |
| 73ffd9540daad0a04d3d54041ba9df14 |
CNNVD-202307-2321 (CVE-2023-37772) |
2023-07-31 12:44:10 |
Online Shopping Portal 安全漏洞 |
详情 |
| 10f462bbd81ee431ab32c6a160fc068d |
CNNVD-202307-2322 (CVE-2023-3983) |
2023-07-31 12:44:08 |
Advantech iView 安全漏洞 |
详情 |
| 91dcd4420b85064dbae045bceabb71b9 |
CNNVD-202307-2323 (CVE-2023-37496) |
2023-07-31 12:44:07 |
HCL Technologies HCL Verse 安全漏洞 |
详情 |
| c81e50233ec479272b638b8dbddedeea |
CNNVD-202307-2324 (CVE-2023-38989) |
2023-07-31 12:44:05 |
jeesite 安全漏洞 |
详情 |
| 775849c6f8c5fe41588806137e12cfa8 |
CNNVD-202307-2326 (CVE-2023-3462) |
2023-07-31 12:44:03 |
HashiCorp Vault 安全漏洞 |
详情 |
| f995ebc4f6961ed50c6d18ec0f7efcf4 |
CNNVD-202307-2327 (CVE-2022-42183) |
2023-07-31 12:44:01 |
Precisely Spectrum Spatial Analyst 安全漏洞 |
详情 |
| 67539644d8b06577c03aeab1ac018450 |
CNNVD-202307-2328 (CVE-2022-42182) |
2023-07-31 12:43:59 |
Precisely Spectrum Spatial Analyst 安全漏洞 |
详情 |
| b61f0e730dfb90bb1c6f8f6e83508ae7 |
CNNVD-202307-2329 (CVE-2023-39122) |
2023-07-31 12:43:56 |
BMC Control-M 安全漏洞 |
详情 |
| a09d1da1d10d2b5f823d7b8b41490660 |
CNNVD-202307-2330 (CVE-2023-3825) |
2023-07-31 12:42:54 |
PTC Kepware KEPServerEX 资源管理错误漏洞 |
详情 |
| 05caf2e95b7a0f72e0c071c443e1d82b |
CNNVD-202307-2331 (CVE-2023-4033) |
2023-07-31 12:42:52 |
Mlflow 操作系统命令注入漏洞 |
详情 |
| 奇安信 [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| 45ab4afdafe578698bcfccccd65d833e |
|
yt |
QiAnXinTI-SV-2020-0009 Microsoft Windows Type 1字体处理远程代码执行漏洞(ADV200006)通告 |
详情 |
| 74691465618764c64d52a2ff58013ac4 |
|
yt |
QiAnXinTI-SV-2019-0013 Firefox远程代码执行漏洞(CVE-2019-11707)预警通告 |
详情 |
| 6bd01daffa85191c80698354fc8e252f |
|
wt |
QianxinTI-SV-2019-0015 Microsoft Windows RDP远程桌面服务多个远程代码执行漏洞通告 |
详情 |
| 59085bf4ae9a7a3802468d9764c94968 |
|
wt |
QiAnXinTI-SV-2019-0022 微软IE浏览器JScript脚本引擎远程代码执行漏洞通告 |
详情 |
| 7010355bb6ffff38cb1a885acf784ca7 |
|
ft |
QiAnXinTI-SV-2020-0008 Microsoft Windows SMBv3.0服务远程代码执行漏洞(CVE-2020-0796)通告 |
详情 |
| 5edb21a58a7e21692bd0ddd622d39279 |
|
St |
QiAnXinTI-SV-2020-0013 Microsoft DNS Server远程代码执行漏洞(CVE-2020-1350)通告 |
详情 |
| 3e8973410ef7c04408d63fa10c230487 |
|
St |
QiAnXinTI-SV-2020-0002 Microsoft IE jscript远程命令执行0day漏洞(CVE-2020-0674)通告 |
详情 |
| e8bc02a0c3bfbafd4c84d9ec26e9bede |
|
St |
QianxinTI-SV-2020-0001 微软核心加密库漏洞(CVE-2020-0601)通告 |
详情 |
| f749eac58b87d0954f0e4a84b5d67057 |
CVE-2020-1350 |
2020-07-15 15:57:00 |
QiAnXinTI-SV-2020-0013 Microsoft DNS Server远程代码执行漏洞(CVE-2020-1350)通告 |
详情 |
| 90b93cb7073fe73b17746ac166a09637 |
CVE-2020-6819, CVE-2020-6820 |
2020-04-08 10:34:35 |
QianxinTI-SV-2020-0012 Firefox在野远程代码执行漏洞(CVE-2020-6819、CVE-2020-6820)通告 |
详情 |
| e318a5efa4803b50cdef480b90b1784d |
|
2020-03-25 13:58:51 |
QiAnXinTI-SV-2020-0009 Microsoft Windows Type 1字体处理远程代码执行漏洞(ADV200006)通告 |
详情 |
| cffc3035f7899495cfeae521451f91b2 |
CVE-2020-0796 |
2020-03-12 10:32:09 |
QiAnXinTI-SV-2020-0008 Microsoft Windows SMBv3.0服务远程代码执行漏洞(CVE-2020-0796)通告 |
详情 |
| 3e6175d47d17c6f94bd9ba10d81c3717 |
CVE-2020-0674 |
2020-03-02 14:52:46 |
QiAnXinTI-SV-2020-0002 Microsoft IE jscript远程命令执行0day漏洞(CVE-2020-0674)通告 |
详情 |
| d99d073afb7d248a8a62fb068921997f |
CVE-2020-0601 |
2020-01-15 14:11:41 |
QianxinTI-SV-2020-0001 微软核心加密库漏洞(CVE-2020-0601)通告 |
详情 |
| b7b45b14a3af1225ef6eec72d74964df |
CVE-2019-1367 |
2019-09-25 17:23:00 |
QiAnXinTI-SV-2019-0022 微软IE浏览器JScript脚本引擎远程代码执行漏洞通告 |
详情 |
| 504fc79f0123db109a11b149c334b75c |
CVE-2019-0708 |
2019-09-09 10:20:47 |
QiAnXinTI-SV-2019-0006 微软远程桌面服务远程代码执行漏洞(CVE-2019-0708)预警通告 |
详情 |
| 5b727692d583d4a6e7cdb0f670eac12a |
CVE-2019-1181, CVE-2019-1182, CVE-2019-1222, CVE-2019-1226 |
2019-08-14 11:09:05 |
QianxinTI-SV-2019-0015 Microsoft Windows RDP远程桌面服务多个远程代码执行漏洞通告 |
详情 |
| 54b48d765fccbc8dcfa3de0920459f8d |
CVE-2019-11707 |
2019-06-19 16:53:47 |
QiAnXinTI-SV-2019-0013 Firefox远程代码执行漏洞(CVE-2019-11707)预警通告 |
详情 |
| 5b4d5fea09fbc2dca45be53f162d39de |
CVE-2019-0708 |
2019-05-31 17:03:19 |
QiAnXinTI-SV-2019-0006 微软远程桌面服务远程代码执行漏洞(CVE-2019-0708)预警通告 |
详情 |
| 安全客 [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| 03afa8b4eaf4a0160784152fca5465b2 |
CVE-2021-27308 |
2021-07-11 14:22:05 |
4images 跨站脚本漏洞 |
详情 |
| 8b0ace4c54a7fc20a99d21e294152a99 |
CVE-2020-15261 |
2021-07-11 14:22:05 |
Veyon Service 安全漏洞 |
详情 |
| d4f12de949590ab346b61986a29d8b4d |
CVE-2021-35039 |
2021-07-09 17:30:13 |
Linux kernel 安全漏洞 |
详情 |
| f790e7ef3b5de3774d42ee32b9b10c01 |
CVE-2021-34626 |
2021-07-09 17:30:13 |
WordPress 访问控制错误漏洞 |
详情 |
| 71bf261eb2113d5ff870ab9bafd29f55 |
CVE-2021-25952 |
2021-07-09 17:30:13 |
just-safe-set 安全漏洞 |
详情 |
| 152793cbc104933584f5f227606f433d |
CVE-2021-0597 |
2021-07-09 17:30:13 |
Google Android 信息泄露漏洞 |
详情 |
| 75f153c327984fdfdd2d9c463a91371d |
CVE-2021-34430 |
2021-07-09 17:30:13 |
Eclipse TinyDTLS 安全特征问题漏洞 |
详情 |
| 9610336f1a41241cc8edea22a2780ec5 |
CVE-2021-3638 |
2021-07-09 17:30:13 |
QEMU 安全漏洞 |
详情 |
| 92fe450ae5c5dfa48072aca79d64ba63 |
CVE-2021-34614 |
2021-07-09 14:24:32 |
Aruba ClearPass Policy Manager 安全漏洞 |
详情 |
| 680a4218fc32922746717210664a3d62 |
CVE-2021-22144 |
2021-07-09 13:28:16 |
Elasticsearch 安全漏洞 |
详情 |
| 373930f669f2c1f7b61101a925304779 |
CVE-2021-24022 |
2021-07-09 13:28:16 |
Fortinet FortiManager 安全漏洞 |
详情 |
| 8556f9cd0699f88c1f6cca9a43463bdd |
CVE-2021-33012 |
2021-07-09 13:28:16 |
Allen Bradley Micrologix 1100输入验证错误漏洞 |
详情 |
| 480ae713cc88cc0985e1ebc079974d83 |
CVE-2021-0592 |
2021-07-09 13:28:16 |
Google Android 安全漏洞 |
详情 |
| 8ef4dbefa6604ea2312621401c3ec0b9 |
CVE-2021-1598 |
2021-07-09 13:28:16 |
Cisco Video Surveillance 7000 Series IP Cameras 安全漏洞 |
详情 |
| d6e8714c32df7a0dcc2f3910ec68b42d |
CVE-2021-20782 |
2021-07-09 13:28:16 |
Software License Manager 跨站请求伪造漏洞 |
详情 |
| 4e60b22611b8bb0fd7e532896498af29 |
CVE-2021-20781 |
2021-07-09 13:28:16 |
WordPress 跨站请求伪造漏洞 |
详情 |
| 5ca48ad58fb499c069ae0800c3b39875 |
CVE-2021-32961 |
2021-07-09 13:28:16 |
MDT AutoSave代码问题漏洞 |
详情 |
| 2ed854890b43f08e52340a1e8fe6d39f |
CVE-2021-0577 |
2021-07-09 13:28:16 |
Google Android 安全漏洞 |
详情 |
| 8d63110e1475bbd245715b2ee1824d13 |
CVE-2021-31816 |
2021-07-09 13:28:16 |
Octopus Server 安全漏洞 |
详情 |
| 72bef2ae2f5db7dd066e1cdefa618dc5 |
CVE-2021-31817 |
2021-07-09 13:28:16 |
Octopus Server 安全漏洞 |
详情 |
| 1f7369b2609dbd2cd40d091f7de540cd |
CVE-2020-20217 |
2021-07-09 13:28:16 |
Mikrotik RouterOs 安全漏洞 |
详情 |
| 1793176eecc5813c3348f026dc9909c9 |
CVE-2020-28598 |
2021-07-09 13:28:16 |
PrusaSlicer 安全漏洞 |
详情 |
| 7f4cf34ceb545548dcfcc3c0e7120268 |
CVE-2021-32945 |
2021-07-09 13:28:16 |
MDT AutoSave加密问题漏洞 |
详情 |
| 58553eb00d6e3e83b633f09464c4e98a |
CVE-2021-29712 |
2021-07-09 13:28:16 |
IBM InfoSphere Information Server 跨站脚本漏洞 |
详情 |
| d8e27ec42fb0b89998fcc006f49b249b |
CVE-2021-25432 |
2021-07-09 13:28:16 |
Samsung Members 信息泄露漏洞 |
详情 |
| 8f2adc6c247725bf2eb7f53256c93ea7 |
CVE-2021-25433 |
2021-07-09 13:28:16 |
Samsung Tizen安全漏洞 |
详情 |
| 8f949676124339eb6f64f9c607af5470 |
CVE-2021-25431 |
2021-07-09 13:28:16 |
Samsung Mobile Device Cameralyzer 访问控制错误漏洞 |
详情 |
| 069818a8958f9c158fcb0956ee32fc03 |
CVE-2021-25434 |
2021-07-09 13:28:16 |
Samsung Tizen 代码注入漏洞 |
详情 |
| 55b9126220b9722ff5d730d3996877e9 |
CVE-2021-32949 |
2021-07-09 13:28:16 |
MDT AutoSave 路径遍历漏洞 |
详情 |
| ebab009fffdee3d360dcdff74b0ed061 |
CVE-2021-25435 |
2021-07-09 13:28:16 |
Samsung Tizen代码注入漏洞 |
详情 |
| 斗象 [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| 096b6298d82574500dc1a14c9dba4065 |
CVE-2022-22038, CVE-2022-22047, CVE-2022-30216, CVE-2022-22029 |
2022-07-15 00:38:28 |
微软2022年7月补丁日漏洞通告 |
详情 |
| 6018f718b2d751478bf1ce069ac65f0d |
CVE-2022-2185 |
2022-07-01 09:02:05 |
GitLab 远程代码执行漏洞(CVE-2022-2185) |
详情 |
| 844719cf0bb4843aff73d2f33cc6dd0b |
CVE-2022-30190, CVE-2022-30136 |
2022-06-15 05:48:12 |
微软2022年6月补丁日漏洞通告 |
详情 |
| 8b47000e1abfbacdadb7df6f09152d89 |
CVE-2022-26134 |
2022-06-03 05:48:38 |
Atlassian Confluence 远程代码执行漏洞(CVE-2022-26134) |
详情 |
| eebe93468b36d2ca24cf4b82136a5635 |
CVE-2022-30190 |
2022-05-31 13:57:17 |
Microsoft Windows MSDT 远程代码执行漏洞(CVE-2022-30190) |
详情 |
| 95525e3f5907a776dc7cd4f87f2e2154 |
|
2022-05-23 07:11:04 |
Fastjson 反序列化漏洞 |
详情 |
| 945fd6e612634d9721f861833f1ecb75 |
CVE-2022-26925, CVE-2022-26937, CVE-2022-22017, CVE-2022-26923 |
2022-05-11 03:45:48 |
微软2022年5月补丁日漏洞通告 |
详情 |
| e2938ff82d0cc152508e0240697def4c |
CVE-2022-1388 |
2022-05-06 05:53:04 |
F5 BIG-IP iControl REST 身份验证绕过漏洞(CVE-2022-1388) |
详情 |
| bcf7253d2ee580c618737de137d370c4 |
CVE-2022-29464 |
2022-04-22 02:21:17 |
WSO2 Carbon Server 远程代码执行漏洞(CVE-2022-29464) |
详情 |
| 07c09799b08afb04c63a9de750b70aca |
CVE-2022-26809, CVE-2022-24491, CVE-2022-24497, CVE-2022-26815, CVE-2022-26904 |
2022-04-13 07:51:00 |
微软2022年4月补丁日漏洞通告 |
详情 |
| f5b543501ed5679d423411edac502e24 |
CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, CVE-2022-22958, CVE-2022-22959, CVE-2022-22960, CVE-2022-22961 |
2022-04-08 03:49:31 |
VMware 产品多个高危漏洞通告 |
详情 |
| f421bcdb306e2bc1ffbf58fcb024a0dd |
|
2022-03-29 17:11:30 |
Spring 框架远程代码执行漏洞 |
详情 |
| 0473358d95e58c7c3f2e7db0109f56f4 |
|
2022-03-29 17:11:30 |
Spring Framework 远程代码执行漏洞(CVE-2022-22965) |
详情 |
| a888c948ca1172f8a06a3879479f1de4 |
CVE-2022-22965 |
2022-03-29 17:11:30 |
Spring Framework 远程代码执行漏洞(CVE-2022-22965) |
详情 |
| 71ed541bb737196268b75c7ba435e1a9 |
|
2022-03-28 04:57:30 |
Spring Cloud Function SpEL表达式注入漏洞 |
详情 |
| f7a5dcd376be777c6593a29b8ebd411a |
CVE-2022-0778 |
2022-03-18 07:09:22 |
OpenSSL拒绝服务漏洞(CVE-2022-0778) |
详情 |
| 6c4124fed44906a79843cd2dd383c695 |
CVE-2022-0847 |
2022-03-15 03:32:03 |
Linux Kernel本地提权漏洞(CVE-2022-0847) |
详情 |
| a2795e4829bff16f108cf191eba663c3 |
CVE-2022-21990, CVE-2022-24508, CVE-2022-23277 |
2022-03-11 02:14:56 |
微软2022年3月补丁日漏洞通告 |
详情 |
| d09f0641bf65c64a16d802cd78e14097 |
CVE-2022-0847 |
2022-03-08 08:23:08 |
Linux 内核本地提权漏洞(CVE-2022-0847) |
详情 |
| 69052e2a8c09416f5df674f92cba25a6 |
CVE-2022-22947 |
2022-03-02 11:42:55 |
Spring Cloud Gateway 远程代码执行漏洞(CVE-2022-22947) |
详情 |
| 5f42b6f584a9ace426787dc8dfd6e6e5 |
|
2022-02-16 10:44:18 |
向日葵远程命令执行漏洞(CNVD-2022-10270) |
详情 |
| 79556071f6236ab4674f75b3beee4d79 |
CVE-2022-24112 |
2022-02-11 06:13:35 |
Apache APISIX 远程代码执行漏洞 (CVE-2022-24112) |
详情 |
| 485f2c57713f4a39830e8c2d01e43cfe |
CVE-2021-4034 |
2022-01-26 06:19:16 |
Linux Polkit 权限提升漏洞(CVE-2021-4034) |
详情 |
| 0aa6eab412c0318b74c6a470ee774df1 |
CVE-2022-21907, CVE-2022-21969, CVE-2022-21846, CVE-2022-21855, CVE-2022-21874, CVE-2022-21893, CVE-2022-21850, CVE-2022-21851, CVE-2022-21836, CVE-2022-21919 |
2022-01-12 03:44:50 |
微软2022年1月补丁日漏洞通告 |
详情 |
| 88a8c676b52a739c0335d7c21ca810a9 |
|
2022-01-06 08:19:17 |
MeterSphere 远程代码执行漏洞 |
详情 |
| 76cad61d2d5a8750a6a714ab2c6dbc97 |
CVE-2021-45232 |
2021-12-28 10:31:16 |
Apache APISIX Dashboard 接口未授权访问漏洞(CVE-2021-45232) |
详情 |
| af4f5f63390eb00de8705b5029d8c376 |
CVE-2021-44228, CVE-2021-45046 |
2021-12-14 01:56:52 |
Apache Log4j 远程代码执行漏洞 |
详情 |
| 43456ae172e45c12087c40c03d925e0e |
CVE-2021-44228 |
2021-12-11 03:21:34 |
Apache Log4j 远程代码执行漏洞 |
详情 |
| 392b133d98d6f61aee36ce6c8784f4df |
|
2021-12-09 15:20:54 |
Apache Log4j 远程代码执行漏洞 |
详情 |
| 1e193280a8f45427c06cb4945be4f126 |
|
2021-12-07 06:48:55 |
Grafana 任意文件读取漏洞 |
详情 |
| 红后 [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| 6fa0a347889bf0da0cae47ef068a6a99 |
CVE-2023-32836 |
2023-11-16 21:05:37 |
GOOGLE ANDROID Vulnerability |
详情 |
| 49751f9f84ed69956c96cc87959ec666 |
CVE-2021-22499 |
2023-11-16 21:05:34 |
Micro Focus Application Performance Management 跨站脚本漏洞 |
详情 |
| eaa040f80d817832a627456843d3e24c |
CVE-2021-23883 |
2023-11-16 21:05:33 |
迈克菲 McAfee Endpoint Security 代码问题漏洞 |
详情 |
| d52ddce51389f668d6fad6e7044bd974 |
CVE-2021-23878 |
2023-11-16 21:05:33 |
迈克菲 McAfee Endpoint Security 加密问题漏洞 |
详情 |
| b62432054e9970a34c4d9e4d9efd1075 |
CVE-2023-32838 |
2023-11-16 21:05:33 |
GOOGLE ANDROID Vulnerability |
详情 |
| 162855c32b8e1a1dafd6ef3e7a3b3da8 |
CVE-2022-43554 |
2023-11-16 21:05:33 |
IVANTI AVALANCHE Vulnerability |
详情 |
| dff8e982c8571446fc1d46fdb5263781 |
CVE-2021-21019 |
2023-11-16 21:05:33 |
Adobe Magento 注入漏洞 |
详情 |
| 5c28bf13629d4240819bb4f492d588a9 |
CVE-2022-34396 |
2023-11-15 21:56:12 |
DELL OPENMANAGE_SERVER_ADMINISTRATOR Vulnerability |
详情 |
| 8876fd1be50182e42f17aaf033bfaf25 |
CVE-2022-45098 |
2023-11-15 21:56:10 |
DELL EMC_POWERSCALE_ONEFS Vulnerability |
详情 |
| d8a4cb7ca4e0f29533302f9f97f22a55 |
CVE-2022-45102 |
2023-11-15 21:55:56 |
DELL Multiple product Vulnerability |
详情 |
| 72e081fb5149198ecc92f3f06383f0d5 |
CVE-2023-0512 |
2023-11-15 21:55:53 |
VIM VIM Vulnerability |
详情 |
| 741e4f08caf4baef7072136884f07ae6 |
CVE-2023-24829 |
2023-11-15 21:55:48 |
APACHE IOTDB Vulnerability |
详情 |
| 06eca26d44409544e5ec96702bf85ce0 |
CVE-2023-23628 |
2023-11-15 21:54:44 |
METABASE METABASE Vulnerability |
详情 |
| 830da4b9e4f027d37c9e39125a30cc18 |
CVE-2022-3488 |
2023-11-15 21:54:27 |
ISC BIND Vulnerability |
详情 |
| 93ceb6d645101eee2b05535717260299 |
CVE-2022-45808 |
2023-11-15 21:54:21 |
THIMPRESS LEARNPRESS Vulnerability |
详情 |
| d79756a4e0c6522a5ba958c82d0b4c88 |
CVE-2023-22482 |
2023-11-15 21:54:17 |
LINUXFOUNDATION ARGO-CD Vulnerability |
详情 |
| 1c317622086c85695ff9266e3c5cf66f |
CVE-2022-4323 |
2023-11-15 21:54:16 |
SUMO GOOGLE_ANALYTICATOR Vulnerability |
详情 |
| 6e8e12e7cd90fd6550e5cef8c12a4a50 |
CVE-2023-24069 |
2023-11-15 21:54:13 |
SIGNAL SIGNAL-DESKTOP Vulnerability |
详情 |
| de78bbaf8c5f6d744b657b8b7733d20e |
CVE-2023-24044 |
2023-11-15 21:54:12 |
PLESK OBSIDIAN Vulnerability |
详情 |
| 44e1e95916d186bbbc5cabca01532712 |
CVE-2022-41733 |
2023-11-15 21:54:05 |
IBM INFOSPHERE_INFORMATION_SERVER Vulnerability |
详情 |
| 136d79ca309f157fcf93764b6993609c |
CVE-2022-20752 |
2023-11-15 20:59:35 |
Cisco Unified Communications Manager 和 Cisco Unity Connection安全漏洞 |
详情 |
| cfa598cc25996bf7c25d8622f86868f3 |
CVE-2022-32208 |
2023-11-15 20:59:35 |
curl 缓冲区错误漏洞 |
详情 |
| 5dc2248c28a031fb6cb3e94f714da748 |
CVE-2021-31677 |
2023-11-15 20:59:35 |
PESCMS 跨站请求伪造漏洞 |
详情 |
| 2df25199d06527c66c1929ede927aa18 |
CVE-2022-20800 |
2023-11-15 20:59:35 |
Cisco Unified Communications Manager 跨站脚本漏洞 |
详情 |
| 537152d5106a70b12b4e0204db3ba5b3 |
CVE-2022-2304 |
2023-11-15 20:59:34 |
Vim 安全漏洞 |
详情 |
| dee30b1a759cdba8cda08222c3b6cf63 |
CVE-2022-2309 |
2023-11-15 20:59:34 |
lxml 和 libxml2 代码问题漏洞 |
详情 |
| edc189cc3f6caea2e67f158e0f93dd19 |
CVE-2022-31116 |
2023-11-15 20:59:34 |
UltraJSON 其他漏洞 |
详情 |
| 3e53baf169ff30745b9dfa6f9505233b |
CVE-2022-20791 |
2023-11-15 20:59:26 |
Cisco Unified Communications Manager 路径遍历漏洞 |
详情 |
| 6ae237378a32e08e6f0495fa3dbce32b |
CVE-2022-20812 |
2023-11-15 20:59:26 |
Cisco Expressway Series 和 Cisco TelePresence Video Communication Server 路径遍历漏洞 |
详情 |
| a2523ef82d3016d54faf64dd9af12f3f |
CVE-2022-31129 |
2023-11-15 20:59:26 |
Moment.js 资源管理错误漏洞 |
详情 |
| 绿盟 [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| 07ff13766e6eda544e413ceb300607e9 |
CVE-2024-12312 |
2025-02-28 13:27:57 |
WordPress Print Science Designer plugin不受信任数据反序列化漏洞 |
详情 |
| 96e0b0c91b06d953b4a5ecfec71bc612 |
CVE-2024-12329 |
2025-02-28 13:27:57 |
WordPress Essential Real Estate plugin敏感信息泄露漏洞 |
详情 |
| 205143180fd646aa434da08572dc37a5 |
CVE-2024-12564 |
2025-02-28 13:27:57 |
Open Design Alliance CDE inWEB SDK敏感信息泄露漏洞 |
详情 |
| 78c4aba7419004dcc8345585d527ae37 |
CVE-2024-12333 |
2025-02-28 13:27:57 |
WordPress Woodmart theme代码注入漏洞 |
详情 |
| 2d3fe5437226d262f5c3df68dba66d7c |
CVE-2024-11760 |
2025-02-28 13:27:57 |
WordPress Currency Converter Widget PRO plugin跨站脚本漏洞 |
详情 |
| 319c981098d0f2d7bc91e06390e4800c |
CVE-2024-12160 |
2025-02-28 13:27:57 |
WordPress Seraphinite Bulk Discounts for WooCommerce跨站脚本漏洞 |
详情 |
| 9c491939e6e0bd7c2901366e18b6d07c |
CVE-2024-10043 |
2025-02-28 13:27:57 |
GitLab EE授权错误漏洞 |
详情 |
| b01d6119078e51c36fd74abe01052e61 |
CVE-2024-12201 |
2025-02-28 13:27:57 |
WordPress Hash Form plugin授权缺失漏洞 |
详情 |
| 1589394801933a9f20626d1ddb8fceee |
CVE-2024-12397 |
2025-02-28 13:27:57 |
Quarkus HTTP请求夹带漏洞 |
详情 |
| d03ae50732ec3864b9ee63b6ca0d6819 |
CVE-2024-11727 |
2025-02-28 13:27:57 |
WordPress NotificationX plugin跨站脚本漏洞 |
详情 |
| 2a7dc7fdb9b96a3347032f71650e65e0 |
CVE-2024-12401 |
2025-02-28 13:27:57 |
cert-manager输入验证错误漏洞 |
详情 |
| 96ac6565cb6d60af90a82f5ca6441700 |
CVE-2024-11724 |
2025-02-28 13:27:57 |
WordPress Cookie Consent for WP plugin授权缺失漏洞 |
详情 |
| ef7b44b2166f0d595eba2dc2089677ea |
CVE-2024-21574 |
2025-02-28 13:27:57 |
ComfyUI-Manager代码注入漏洞 |
详情 |
| a3bd04b9029a521aaf5f3ffe4484cd2d |
CVE-2024-11181 |
2025-02-28 13:27:57 |
WordPress Greenshift plugin信息泄露漏洞 |
详情 |
| 09791539b80d43a3e70c0c615a371846 |
CVE-2024-12265 |
2025-02-28 13:27:57 |
WordPress Web3 Crypto Payments by DePay for WooCommerce授权缺失漏洞 |
详情 |
| f1ebe5e8c4d2b27532decaae22b958c3 |
CVE-2024-46622 |
2025-02-26 09:29:43 |
SecureAge Security Suite权限提升漏洞 |
详情 |
| 11c80e9d55ccd43a588f386f66557910 |
CVE-2025-22395 |
2025-02-26 09:29:43 |
Dell Update Package Framework权限提升漏洞 |
详情 |
| 978a3b64cac54d324490e1d9ccb9d973 |
CVE-2024-48455 |
2025-02-26 09:29:43 |
Netis Systems多款产品信息泄露漏洞 |
详情 |
| 937d32d09ab3d79285bd35cefe2e4fc8 |
CVE-2024-54880 |
2025-02-26 09:29:43 |
SeaCMS访问控制错误漏洞 |
详情 |
| b142cb6a61cb3f3bca079b01c03d1daa |
CVE-2024-56828 |
2025-02-26 09:29:43 |
ChestnutCMS文件上传漏洞 |
详情 |
| 565566dae4c14015c56f1686d51158d9 |
CVE-2024-48457 |
2025-02-26 09:29:43 |
Netis Systems多款产品越界读取漏洞 |
详情 |
| 88439523bbc7fbb5316a3d53d7ef8045 |
CVE-2024-48456 |
2025-02-26 09:29:43 |
Netis Systems多款产品越界读取漏洞 |
详情 |
| 48d06e40461ebe2a07d633bbaac7f98b |
CVE-2024-12402 |
2025-02-26 09:29:43 |
WordPress Themes Coder Plugin权限提升漏洞 |
详情 |
| 091cbc8c2acc33047566c6ba72c0a5f2 |
CVE-2024-11777 |
2025-02-26 09:29:43 |
WordPress Sell Media Plugin跨站脚本漏洞 |
详情 |
| 992986b17991ac85700a5c82085792fe |
CVE-2024-55074 |
2025-02-26 09:29:43 |
Grocy跨站脚本漏洞 |
详情 |
| 6dde449c96bd83c445bd0f39adf55b81 |
CVE-2024-11290 |
2025-02-26 09:29:43 |
WordPress Member Access Plugin信息泄露漏洞 |
详情 |
| b44a11235219206cb5e4232040129753 |
CVE-2024-12098 |
2025-02-26 09:29:43 |
WordPress ARS Affiliate Page Plugin跨站脚本漏洞 |
详情 |
| 6c2b3d895b8b3067dd3c52f6ee79ce05 |
CVE-2024-11337 |
2025-02-26 09:29:43 |
WordPress Horoscope And Tarot Plugin跨站脚本漏洞 |
详情 |
| 3f7a46526136bcfc4aa36cc908a1439c |
CVE-2024-12541 |
2025-02-26 09:29:43 |
WordPress Chative Live chat and Chatbot Plugin跨站请求伪造漏洞 |
详情 |
| 7ba57109b7dd16786a8483309a85c322 |
CVE-2024-11899 |
2025-02-26 09:29:43 |
WordPress Slider Pro Lite Plugin跨站脚本漏洞 |
详情 |
| 美国国家漏洞数据库(NVD) [TOP 30] |
CVES |
TIME |
TITLE |
URL |
| c6b3897e8411249dddc03a2582c3afdc |
CVE-2023-45955 |
2023-10-31 18:15:08 |
An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands. |
详情 |
| 752c86d745d9d6748f49970fc6c72bf7 |
CVE-2022-48189 |
2023-10-30 15:15:39 |
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code. |
详情 |
| 8e0bb5e55759a9b19da4ce8a5bf48799 |
CVE-2022-4573 |
2023-10-30 15:15:39 |
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code. |
详情 |
| 790b026d2f9b8a38a121baf7cc9fbbe2 |
CVE-2023-45797 |
2023-10-30 07:15:12 |
A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code. |
详情 |
| 9fee627171b8e0c7c2f065dae65c293c |
CVE-2023-46468 |
2023-10-28 01:15:51 |
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function. |
详情 |
| 1f2c404d06acfac83f7761c8ab878dee |
CVE-2023-43322 |
2023-10-28 01:15:51 |
ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/. |
详情 |
| eea9f6fc871d45cb3672714124c1d416 |
CVE-2023-46211 |
2023-10-27 21:15:09 |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin <=Â 3.19.14 versions. |
详情 |
| 8496e7ff58df6fda25c681900fb6dfb8 |
CVE-2023-46209 |
2023-10-27 21:15:09 |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in G5Theme Grid Plus – Unlimited grid plugin <= 1.3.2 versions. |
详情 |
| 751468e26927001b02f1b97a3d980488 |
CVE-2023-46208 |
2023-10-27 21:15:09 |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions. |
详情 |
| 26e1875553f4c463d954949d41128765 |
CVE-2023-46200 |
2023-10-27 21:15:09 |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <=Â 1.1.3 versions. |
详情 |
| a86c2cbf359259b1e38cd6e0c560a363 |
CVE-2023-46509 |
2023-10-27 21:15:09 |
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. |
详情 |
| c608240b549dc25f03e04b5397e48e1b |
CVE-2023-46199 |
2023-10-27 08:15:31 |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <=Â 4.1.1 versions. |
详情 |
| c4bd3098463c3624a284c838fd6ecb48 |
CVE-2023-46194 |
2023-10-27 08:15:31 |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.5 versions. |
详情 |
| e79edbb292a519fa08055a884d86921e |
CVE-2023-46192 |
2023-10-27 08:15:31 |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <=Â 1.2.3 versions. |
详情 |
| 528422b82114eedfc8a332c895b5d475 |
CVE-2023-46504 |
2023-10-27 04:15:10 |
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a physically proximate attacker to execute arbitrary code via the library name function in the general settings component. |
详情 |
| 4b4a8cd15c35de7b7cb3e0f5110f178b |
CVE-2023-46503 |
2023-10-27 04:15:10 |
Cross Site Scripting (XSS) vulnerability in PwnCYN YXBOOKCMS v.1.0.2 allows a remote attacker to execute arbitrary code via the reader management and book input modules. |
详情 |
| 9637804577e375e89e0c34d1e9dc7daa |
CVE-2023-46505 |
2023-10-27 01:15:32 |
Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 parameter in the demo.php file. |
详情 |
| ccc0d1dc9e1e6371fc7ed4a7e6bc67c9 |
CVE-2023-46491 |
2023-10-27 00:15:09 |
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library. |
详情 |
| 925767e89590e6107a882a20468a3153 |
CVE-2023-42188 |
2023-10-27 00:15:09 |
IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF). |
详情 |
| 8affd999965e83dbd42583837011424c |
CVE-2023-42406 |
2023-10-26 22:15:08 |
SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component. |
详情 |
| 7d0ccfb0da7a7225f1fd25c20c95a57e |
CVE-2023-46435 |
2023-10-26 18:15:08 |
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id. |
详情 |
| 0ab665a469513a0f70af2e1f17519e41 |
CVE-2023-5792 |
2023-10-26 17:15:10 |
A vulnerability has been found in SourceCodester Sticky Notes App 1.0 and classified as critical. This vulnerability affects unknown code of the file endpoint/delete-note.php. The manipulation of the argument note leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-243598 is the identifier assigned to this vulnerability. |
详情 |
| 692b9ba4d9cf7c90b6a3e5b8396a5302 |
CVE-2023-5791 |
2023-10-26 17:15:10 |
A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an unknown part of the file endpoint/add-note.php. The manipulation of the argument noteTitle/noteContent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243597 was assigned to this vulnerability. |
详情 |
| 7e262fff58c0ebc8ddc6cdfb7535d7e2 |
CVE-2023-5790 |
2023-10-26 17:15:10 |
A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.php. The manipulation of the argument uploadedFileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243595. |
详情 |
| c643f1003e7a0ee28d9e54cda26d6b85 |
CVE-2023-43208 |
2023-10-26 17:15:09 |
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679. |
详情 |
| 3d3bc04cd7ec7fdf5aaaa0aa0a140b90 |
CVE-2023-46450 |
2023-10-26 15:15:09 |
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function. |
详情 |
| 844b1b549a5543c879cdc68d7237f444 |
CVE-2023-46449 |
2023-10-26 15:15:09 |
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function. |
详情 |
| f494a8af43bc7ce0e5b6f1d2f18f3740 |
CVE-2023-46081 |
2023-10-26 13:15:09 |
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <=Â 1.1.34 versions. |
详情 |
| 3a451401fdd162ad57ab72c2f5d7b984 |
CVE-2023-46077 |
2023-10-26 13:15:09 |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins The Awesome Feed – Custom Feed plugin <= 2.2.5 versions. |
详情 |
| 428d0a0df20b616e36d68a5b76023a38 |
CVE-2023-46076 |
2023-10-26 13:15:09 |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <=Â 1.2.102 versions. |
详情 |
|