CVE-2026-9082 · 2026-07-14 · pending_review
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。
CVE-2026-9082 · 2026-07-14 · pending_review
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CVE-2026-56290 · 2026-07-14 · pending_review
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
CVE-2026-48907 · 2026-07-14 · pending_review
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
CVE-2026-45659 · 2026-07-14 · pending_review
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-41940 · 2026-07-14 · pending_review
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control …
CVE-2026-34197 · 2026-07-14 · pending_review
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-32201 · 2026-07-14 · pending_review
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20963 · 2026-07-14 · pending_review
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2025-68645 · 2026-07-14 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allow…
CVE-2025-54236 · 2026-07-14 · pending_review
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-54068 · 2026-07-14 · pending_review
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CVE-2025-53770 · 2026-07-15 · pending_review
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-20…
CVE-2025-49706 · 2026-07-15 · pending_review
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive informatio…
CVE-2025-49704 · 2026-07-15 · pending_review
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypa…
CVE-2025-24813 · 2026-07-15 · pending_review
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2024-4577 · 2026-07-15 · pending_review
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE-2024-45195 · 2026-07-15 · pending_review
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
CVE-2024-38856 · 2026-07-15 · pending_review
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
CVE-2024-38475 · 2026-07-15 · pending_review
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/…
CVE-2024-38094 · 2026-07-15 · pending_review
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
CVE-2024-34102 · 2026-07-15 · pending_review
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
CVE-2024-32113 · 2026-07-15 · pending_review
Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
CVE-2024-27348 · 2026-07-15 · pending_review
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
CVE-2024-23897 · 2026-07-15 · pending_review
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
CVE-2024-21182 · 2026-07-14 · pending_review
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resul…
CVE-2023-7028 · 2026-07-15 · pending_review
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an ac…
CVE-2023-46604 · 2026-07-15 · pending_review
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire pro…
CVE-2023-36845 · 2026-07-15 · pending_review
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafte…
CVE-2023-36844 · 2026-07-15 · pending_review
Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted reques…
CVE-2023-33246 · 2026-07-15 · pending_review
Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configurat…
CVE-2023-29357 · 2026-07-15 · pending_review
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This atta…
CVE-2023-27524 · 2026-07-15 · pending_review
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configu…
CVE-2023-24955 · 2026-07-15 · pending_review
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
CVE-2023-23752 · 2026-07-15 · pending_review
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
CVE-2023-22527 · 2026-07-15 · pending_review
Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
CVE-2023-22518 · 2026-07-15 · pending_review
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality si…
CVE-2023-22515 · 2026-07-15 · pending_review
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
CVE-2023-21839 · 2026-07-15 · pending_review
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
CVE-2022-33891 · 2026-07-15 · pending_review
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CVE-2022-26138 · 2026-07-15 · pending_review
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all conten…
CVE-2022-26134 · 2026-07-15 · pending_review
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
CVE-2022-24706 · 2026-07-15 · pending_review
Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
CVE-2022-24112 · 2026-07-15 · pending_review
Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
CVE-2022-24086 · 2026-07-18 · pending_review
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
CVE-2022-22965 · 2026-07-15 · pending_review
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-22963 · 2026-07-15 · pending_review
When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local…
CVE-2022-22947 · 2026-07-15 · pending_review
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
CVE-2021-45046 · 2026-07-15 · pending_review
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default …
CVE-2021-44228 · 2026-07-18 · pending_review
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE-2021-43798 · 2026-07-15 · pending_review
Grafana contains a path traversal vulnerability that could allow access to local files.