vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Drupal Core SQL Injection Vulnerability
严重 KEV

CVE-2026-9082 · 2026-07-14 · pending_review

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Laravel Livewire Code Injection Vulnerability
严重 KEV

CVE-2025-54068 · 2026-07-14 · pending_review

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
高危 KEV

CVE-2025-53770 · 2026-07-15 · pending_review

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-20…

Microsoft SharePoint Improper Authentication Vulnerability
高危 KEV

CVE-2025-49706 · 2026-07-15 · pending_review

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive informatio…

Microsoft SharePoint Code Injection Vulnerability
严重 KEV

CVE-2025-49704 · 2026-07-15 · pending_review

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypa…

Apache Tomcat Path Equivalence Vulnerability
高危 KEV

CVE-2025-24813 · 2026-07-15 · pending_review

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

PHP-CGI OS Command Injection Vulnerability
高危 KEV

CVE-2024-4577 · 2026-07-15 · pending_review

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

Apache OFBiz Forced Browsing Vulnerability
高危 KEV

CVE-2024-45195 · 2026-07-15 · pending_review

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Apache OFBiz Incorrect Authorization Vulnerability
严重 KEV

CVE-2024-38856 · 2026-07-15 · pending_review

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

Apache HTTP Server Improper Escaping of Output Vulnerability
高危 KEV

CVE-2024-38475 · 2026-07-15 · pending_review

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/…

Oracle WebLogic Server Unspecified Vulnerability
高危 KEV

CVE-2024-21182 · 2026-07-14 · pending_review

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resul…

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
高危 KEV

CVE-2023-46604 · 2026-07-15 · pending_review

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire pro…

Apache RocketMQ Command Execution Vulnerability
高危 KEV

CVE-2023-33246 · 2026-07-15 · pending_review

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configurat…

Microsoft SharePoint Server Privilege Escalation Vulnerability
高危 KEV

CVE-2023-29357 · 2026-07-15 · pending_review

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This atta…

Oracle WebLogic Server Unspecified Vulnerability
高危 KEV

CVE-2023-21839 · 2026-07-15 · pending_review

Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.

Apache Spark Command Injection Vulnerability
高危 KEV

CVE-2022-33891 · 2026-07-15 · pending_review

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
严重 KEV

CVE-2022-22963 · 2026-07-15 · pending_review

When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local…

Apache Log4j2 Deserialization of Untrusted Data Vulnerability
严重 KEV

CVE-2021-45046 · 2026-07-15 · pending_review

Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default …

Apache Log4j2 Remote Code Execution Vulnerability
严重 KEV

CVE-2021-44228 · 2026-07-18 · pending_review

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

Grafana Path Traversal Vulnerability
高危 KEV

CVE-2021-43798 · 2026-07-15 · pending_review

Grafana contains a path traversal vulnerability that could allow access to local files.

下一页 →