vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Microsoft Exchange Server Cross-Site Scripting Vulnerability
高危 KEV

CVE-2026-42897 · 2026-07-14 · pending_review

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browse…

Citrix NetScaler Out-of-Bounds Read Vulnerability
高危 KEV

CVE-2026-3055 · 2026-07-14 · pending_review

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overre…

Broadcom VMware Aria Operations Command Injection Vulnerability
严重 KEV

CVE-2026-22719 · 2026-07-14 · pending_review

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remot…

Fortinet FortiClient EMS SQL Injection Vulnerability
高危 KEV

CVE-2026-21643 · 2026-07-14 · pending_review

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Microsoft Windows Type Confusion Vulnerability
高危 KEV

CVE-2026-21519 · 2026-07-14 · pending_review

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.

Microsoft Windows Information Disclosure Vulnerability
高危 KEV

CVE-2026-20805 · 2026-07-14 · pending_review

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
严重 KEV

CVE-2026-20182 · 2026-07-14 · pending_review

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected syste…

Cisco Unified Communications Products Code Injection Vulnerability
严重 KEV

CVE-2026-20045 · 2026-07-14 · pending_review

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Uni…

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
高危 KEV

CVE-2026-1603 · 2026-07-14 · pending_review

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

Ivanti Sentry OS Command Injection Vulnerability
严重 KEV

CVE-2026-10520 · 2026-07-14 · pending_review

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be su…

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
高危 KEV

CVE-2026-0300 · 2026-07-14 · pending_review

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root pri…

Citrix NetScaler Memory Overflow Vulnerability
严重 KEV

CVE-2025-7775 · 2026-07-15 · pending_review

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
高危 KEV

CVE-2025-6543 · 2026-07-15 · pending_review

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) …

Fortinet FortiWeb Path Traversal Vulnerability
高危 KEV

CVE-2025-64446 · 2026-07-14 · pending_review

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Microsoft Windows Use After Free Vulnerability
高危 KEV

CVE-2025-62221 · 2026-07-14 · pending_review

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.

Microsoft Windows Race Condition Vulnerability
高危 KEV

CVE-2025-62215 · 2026-07-14 · pending_review

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to g…

Oracle E-Business Suite Unspecified Vulnerability
高危 KEV

CVE-2025-61882 · 2026-07-15 · pending_review

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Proc…

Microsoft Windows Improper Access Control Vulnerability
高危 KEV

CVE-2025-59230 · 2026-07-15 · pending_review

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

Fortinet FortiWeb OS Command Injection Vulnerability
高危 KEV

CVE-2025-58034 · 2026-07-14 · pending_review

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
高危 KEV

CVE-2025-5777 · 2026-07-15 · pending_review

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual…

Android Framework Integer Overflow Vulnerability
高危 KEV

CVE-2025-48595 · 2026-07-14 · pending_review

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

Android Runtime Use-After-Free Vulnerability
高危 KEV

CVE-2025-48543 · 2026-07-15 · pending_review

Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.

下一页 →