CVE-2026-45498 · 2026-09-02 · pending_review
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
按严重度 / 渠道 / 厂商 / 时间筛选公开漏洞条目。
CVE-2026-45498 · 2026-09-02 · pending_review
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CVE-2026-32202 · 2026-09-02 · pending_review
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20805 · 2026-09-02 · pending_review
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
CVE-2025-49706 · 2026-09-02 · pending_review
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive informatio…
CVE-2023-20269 · 2026-09-02 · pending_review
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify v…
CVE-2022-2586 · 2026-09-02 · pending_review
Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.
CVE-2022-24682 · 2026-09-04 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.
CVE-2021-41379 · 2026-09-04 · pending_review
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-34448 · 2026-09-04 · pending_review
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
CVE-2021-20023 · 2026-09-04 · pending_review
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain …
CVE-2020-3153 · 2026-09-03 · pending_review
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system…
CVE-2019-6693 · 2026-09-02 · pending_review
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
CVE-2019-5591 · 2026-09-04 · pending_review
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol …
CVE-2018-6882 · 2026-09-03 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.
CVE-2018-19953 · 2026-09-03 · pending_review
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-13374 · 2026-09-03 · pending_review
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request…
CVE-2016-3351 · 2026-09-03 · pending_review
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's co…
CVE-2013-0431 · 2026-09-03 · pending_review
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
CVE-2010-0738 · 2026-09-03 · pending_review
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's …
CVE-2009-3960 · 2026-09-04 · pending_review
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
CVE-2008-4128 · 2026-09-02 · draft
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "al…
CVE-2015-3246 · 2026-09-02 · auto
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) b…
CVE-2026-66384 · 2026-09-02 · pending_review
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CVE-2025-68686 · 2026-09-02 · pending_review
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions…
CVE-2026-48710 · 2026-09-02 · pending_review
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw …