vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Microsoft Windows Information Disclosure Vulnerability
中危 5.5 KEV

CVE-2026-20805 · 2026-09-02 · pending_review

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.

Linux Kernel Use-After-Free Vulnerability
中危 5.3 KEV

CVE-2022-2586 · 2026-09-02 · pending_review

Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.

SonicWall Email Security Path Traversal Vulnerability
中危 4.9 KEV

CVE-2021-20023 · 2026-09-04 · pending_review

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain …

Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
中危 6.5 KEV

CVE-2019-6693 · 2026-09-02 · pending_review

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

Fortinet FortiOS Default Configuration Vulnerability
中危 6.5 KEV

CVE-2019-5591 · 2026-09-04 · pending_review

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol …

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
中危 4.3 KEV

CVE-2018-13374 · 2026-09-03 · pending_review

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request…

Oracle JRE Sandbox Bypass Vulnerability
中危 5.3 KEV

CVE-2013-0431 · 2026-09-03 · pending_review

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

Cisco IOS Cross-Site Request Forgery Vulnerability
中危 4.3 KEV

CVE-2008-4128 · 2026-09-02 · draft

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "al…

下一页 →