vulnti.work

漏洞列表

按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。

清除筛选
Drupal Core SQL Injection Vulnerability
严重 KEV

CVE-2026-9082 · 2026-07-14 · pending_review

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Check Point Security Gateway Improper Authentication Vulnerability
严重 KEV

CVE-2026-50751 · 2026-07-14 · pending_review

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN con…

Marimo Remote Code Execution Vulnerability
严重 KEV

CVE-2026-39987 · 2026-07-14 · pending_review

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Langflow Code Injection Vulnerability
严重 KEV

CVE-2026-33017 · 2026-07-14 · pending_review

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.

Broadcom VMware Aria Operations Command Injection Vulnerability
严重 KEV

CVE-2026-22719 · 2026-07-14 · pending_review

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remot…

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
严重 KEV

CVE-2026-20182 · 2026-07-14 · pending_review

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected syste…

Cisco Unified Communications Products Code Injection Vulnerability
严重 KEV

CVE-2026-20045 · 2026-07-14 · pending_review

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Uni…

Ivanti Sentry OS Command Injection Vulnerability
严重 KEV

CVE-2026-10520 · 2026-07-14 · pending_review

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be su…

Citrix NetScaler Memory Overflow Vulnerability
严重 KEV

CVE-2025-7775 · 2026-07-15 · pending_review

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

Lantronix EDS5000 Code Injection Vulnerability
严重 KEV

CVE-2025-67038 · 2026-07-14 · pending_review

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Sangoma FreePBX Authentication Bypass Vulnerability
严重 KEV

CVE-2025-57819 · 2026-07-15 · pending_review

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and rem…

Meta React Server Components Remote Code Execution Vulnerability
严重 KEV

CVE-2025-55182 · 2026-07-14 · pending_review

Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoint…

Laravel Livewire Code Injection Vulnerability
严重 KEV

CVE-2025-54068 · 2026-07-14 · pending_review

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.

Microsoft SharePoint Code Injection Vulnerability
严重 KEV

CVE-2025-49704 · 2026-07-15 · pending_review

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypa…

RoundCube Webmail Deserialization of Untrusted Data Vulnerability
严重 KEV

CVE-2025-49113 · 2026-07-14 · pending_review

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/uplo…

CWP Control Web Panel OS Command Injection Vulnerability
严重 KEV

CVE-2025-48703 · 2026-07-14 · pending_review

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager change…

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
严重 KEV

CVE-2025-4428 · 2026-07-15 · pending_review

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability res…

ConnectWise ScreenConnect Improper Authentication Vulnerability
严重 KEV

CVE-2025-3935 · 2026-07-15 · pending_review

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

Langflow Missing Authentication Vulnerability
严重 9.8 KEV

CVE-2025-3248 · 2026-07-15 · pending_review

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Craft CMS Code Injection Vulnerability
严重 KEV

CVE-2025-32432 · 2026-07-14 · pending_review

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

XWiki Platform Eval Injection Vulnerability
严重 KEV

CVE-2025-24893 · 2026-07-14 · pending_review

XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.

Craft CMS Code Injection Vulnerability
严重 KEV

CVE-2025-23209 · 2026-07-15 · pending_review

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

Cisco Identity Services Engine Injection Vulnerability
严重 KEV

CVE-2025-20337 · 2026-07-15 · pending_review

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability…

下一页 →