
NVD · 实时热榜
- 01CVE-2026-19955 · LOW 2
A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
最高第 1 名04:30 达到04:30 首次观测上榜11:26 观测离榜累计约6小时56分 - 02CVE-2026-19956 · MEDIUM 5.3
A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659. Applying a patch is advised to resolve this issue.
最高第 1 名05:18 达到05:18 首次观测上榜11:26 观测离榜累计约6小时8分 - 03CVE-2026-19957 · LOW 2.1
A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
最高第 1 名06:22 达到06:22 首次观测上榜11:26 观测离榜累计约5小时4分 - 04CVE-2026-19961 · HIGH 8.6
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 1 名07:26 达到07:26 首次观测上榜12:36 观测离榜累计约5小时10分 - 05CVE-2026-19965 · LOW 2.9
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.
最高第 1 名08:30 达到08:30 首次观测上榜13:24 观测离榜累计约4小时54分 - 06CVE-2026-19969 · LOW 2.1
A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Model Output Mesh Generator. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
最高第 1 名09:18 达到09:18 首次观测上榜14:28 观测离榜累计约5小时10分 - 07CVE-2026-19972 · LOW 2.1
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewpatient.php. Such manipulation of the argument delid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
最高第 1 名10:22 达到10:22 首次观测上榜14:28 观测离榜累计约4小时6分 - 08CVE-2026-19981 · MEDIUM 5.3
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument switch_power/restore_power can lead to os command injection. The attack can be launched remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
最高第 1 名12:36 达到12:36 首次观测上榜16:20 观测离榜累计约3小时44分 - 09CVE-2026-19986 · LOW 2.1
A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 1 名13:24 达到13:24 首次观测上榜17:24 观测离榜累计约4小时 - 10CVE-2026-20000 · LOW 2.1
A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the argument delid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
最高第 1 名16:20 达到16:20 首次观测上榜19:32 观测离榜累计约3小时12分 - 11CVE-2026-22072 · HIGH 8.3
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
最高第 1 名15:32 达到15:32 首次观测上榜19:32 观测离榜累计约4小时 - 12CVE-2026-50602 · HIGH 8.5
A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an authenticated local user could potentially modify or replace the executable and execute arbitrary code with SYSTEM privileges when the service starts or the system is restarted.
最高第 1 名11:26 达到11:26 首次观测上榜15:32 观测离榜累计约4小时6分 - 13CVE-2026-58561 · MEDIUM 4
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.
最高第 1 名17:24 达到17:24 首次观测上榜19:32 观测离榜累计约2小时8分 - 14CVE-2026-59911 · MEDIUM 5.5
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
最高第 1 名22:28 达到22:28 首次观测上榜当日结束时仍在榜累计约1小时20分 - 15CVE-2026-73851 · MEDIUM 6.1
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.
最高第 1 名23:32 达到23:32 首次观测上榜当日结束时仍在榜累计约16分钟 - 16CVE-2026-74579 · UNKNOWN
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field offload nft_payload_offload_mask() builds the offload match mask for a payload expression that covers only part of a header field. For a partial IPv6 address match (field_len = 16, priv_len = 1) that shift is 1 << 120, which is undefined on the 32-bit int operand. It also trims only one word, so the remaining words stay 0xffffffff (and when priv_len is a multiple of 4 the trim is skipped entirely), leaving the mask covering more bytes than the rule matches. UBSAN: shift-out-of-bounds in net/netfilter/nft_payload.c:278:20 shift exponent 120 is too large for 32-bit type 'int' ... The match is byte-granular and struct nft_data is zero-initialised, so the correct mask is simply the first priv_len bytes set to 0xff. Set those bytes directly and drop the word/shift trimming; this removes the undefined shift and no longer over-masks the trailing bytes.
最高第 1 名14:28 达到14:28 首次观测上榜18:28 观测离榜累计约4小时 - 17CVE-2026-74797 · LOW 2.3
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
最高第 1 名00:00 达到当日首次采集时已在榜11:26 观测离榜累计约11小时26分 - 18CVE-2026-74843 · CRITICAL 9.3
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
最高第 1 名20:20 达到20:20 首次观测上榜22:28 观测离榜累计约2小时8分 - 19CVE-2026-74845 · HIGH 8.7
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
最高第 1 名18:28 达到18:28 首次观测上榜19:32 观测离榜累计约1小时4分 - 20CVE-2026-74901 · CRITICAL 9.3
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
最高第 1 名19:32 达到19:32 首次观测上榜22:28 观测离榜累计约2小时56分 - 21CVE-2026-75010 · MEDIUM 6.4
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
最高第 1 名21:24 达到21:24 首次观测上榜23:32 观测离榜累计约2小时8分 - 22CVE-2026-19960 · LOW 2.1
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 2 名07:26 达到07:26 首次观测上榜12:36 观测离榜累计约5小时10分 - 23CVE-2026-19964 · LOW 2
A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
最高第 2 名08:30 达到08:30 首次观测上榜13:24 观测离榜累计约4小时54分 - 24CVE-2026-19968 · LOW 2.1
A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.
最高第 2 名09:18 达到09:18 首次观测上榜14:28 观测离榜累计约5小时10分 - 25CVE-2026-19971 · MEDIUM 5.3
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of the component Backup Endpoint. This manipulation causes missing authentication. The attack is only possible within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 2 名10:22 达到10:22 首次观测上榜14:28 观测离榜累计约4小时6分 - 26CVE-2026-19980 · MEDIUM 5.3
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
最高第 2 名12:36 达到12:36 首次观测上榜16:20 观测离榜累计约3小时44分 - 27CVE-2026-19984 · LOW 2.1
A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init__.py. This manipulation of the argument src causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. It is recommended to change the configuration settings. The vendor explains: "For deployments where SSRF protection is required, I recommend routing all HTTP(S) requests through an SSRF-safe proxy server. This approach mitigates the vulnerability without requiring changes to the mcp-florence2 source code."
最高第 2 名13:24 达到13:24 首次观测上榜17:24 观测离榜累计约4小时 - 28CVE-2026-19993 · LOW 2.1
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
最高第 2 名14:28 达到14:28 首次观测上榜17:24 观测离榜累计约2小时56分 - 29CVE-2026-19997 · LOW 2
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
最高第 2 名15:32 达到15:32 首次观测上榜19:32 观测离榜累计约4小时 - 30CVE-2026-19999 · LOW 2.1
A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone Transformation Key Parser. The manipulation of the argument transmatrix_count/pcBoneTransforms leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is 50d767984e78d51b53e2020fdf0967fd624bc377. It is recommended to apply a patch to fix this issue.
最高第 2 名16:20 达到16:20 首次观测上榜19:32 观测离榜累计约3小时12分 - 31CVE-2026-40126 · MEDIUM 4.8
OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2
最高第 2 名20:20 达到20:20 首次观测上榜22:28 观测离榜累计约2小时8分 - 32CVE-2026-50601 · MEDIUM 6.6
A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. To mitigate this security risk, Acer has released an update to resolve the issue.
最高第 2 名11:26 达到11:26 首次观测上榜15:32 观测离榜累计约4小时6分 - 33CVE-2026-58560 · MEDIUM 4
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability.
最高第 2 名17:24 达到17:24 首次观测上榜19:32 观测离榜累计约2小时8分 - 34CVE-2026-59910 · HIGH 7.8
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
最高第 2 名22:28 达到22:28 首次观测上榜当日结束时仍在榜累计约1小时20分 - 35CVE-2026-71567 · HIGH 7.7
In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or into manifests. This mostly applies to the Image URL and BMC credentials (which are not verified by FakeFish).
最高第 2 名23:32 达到23:32 首次观测上榜当日结束时仍在榜累计约16分钟 - 36CVE-2026-74796 · HIGH 7
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
最高第 2 名00:00 达到当日首次采集时已在榜11:26 观测离榜累计约11小时26分 - 37CVE-2026-74900 · CRITICAL 9.3
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.
最高第 2 名19:32 达到19:32 首次观测上榜22:28 观测离榜累计约2小时56分 - 38CVE-2026-75007 · MEDIUM 5.4
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
最高第 2 名21:24 达到21:24 首次观测上榜23:32 观测离榜累计约2小时8分 - 39CVE-2026-19959 · HIGH 8.6
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 3 名07:26 达到07:26 首次观测上榜11:26 观测离榜累计约4小时 - 40CVE-2026-19963 · LOW 2.1
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /goform/stainfo. The manipulation of the argument interface leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 3 名08:30 达到08:30 首次观测上榜12:36 观测离榜累计约4小时6分 - 41CVE-2026-19967 · LOW 2.1
A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the function Assimp::Compression::decompressBlock of the file code/Common/Compression.cpp of the component File Parser. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
最高第 3 名09:18 达到09:18 首次观测上榜13:24 观测离榜累计约4小时6分 - 42CVE-2026-19970 · LOW 2.1
A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The manipulation of the argument bones_num results in heap-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
最高第 3 名10:22 达到10:22 首次观测上榜14:28 观测离榜累计约4小时6分 - 43CVE-2026-19977 · CRITICAL 9.3
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
最高第 3 名11:26 达到11:26 首次观测上榜15:32 观测离榜累计约4小时6分 - 44CVE-2026-19979 · MEDIUM 6.9
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
最高第 3 名12:36 达到12:36 首次观测上榜16:20 观测离榜累计约3小时44分 - 45CVE-2026-19983 · MEDIUM 6.9
A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely. Upgrading to version 4.9.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
最高第 3 名13:24 达到13:24 首次观测上榜17:24 观测离榜累计约4小时 - 46CVE-2026-19992 · LOW 1.3
A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
最高第 3 名14:28 达到14:28 首次观测上榜17:24 观测离榜累计约2小时56分 - 47CVE-2026-19996 · LOW 2.1
A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
最高第 3 名15:32 达到15:32 首次观测上榜19:32 观测离榜累计约4小时 - 48CVE-2026-19998 · LOW 2.1
A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
最高第 3 名16:20 达到16:20 首次观测上榜19:32 观测离榜累计约3小时12分 - 49CVE-2026-49308 · MEDIUM 5.5
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
最高第 3 名17:24 达到17:24 首次观测上榜19:32 观测离榜累计约2小时8分 - 50CVE-2026-59909 · HIGH 7.1
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
最高第 3 名22:28 达到22:28 首次观测上榜当日结束时仍在榜累计约1小时20分


































































































