
NVD · 实时热榜
- 01CVE-2026-9693 · LOW 3.5
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
最高第 1 名07:22 达到07:22 首次观测上榜18:24 观测离榜累计约11小时2分 - 02CVE-2026-75079 · MEDIUM 5.5
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
最高第 4 名08:26 达到08:26 首次观测上榜19:28 观测离榜累计约11小时2分 - 03CVE-2026-75080 · MEDIUM 5.5
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
最高第 3 名08:26 达到08:26 首次观测上榜19:28 观测离榜累计约11小时2分 - 04CVE-2026-75081 · LOW 2.1
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
最高第 2 名08:26 达到08:26 首次观测上榜19:28 观测离榜累计约11小时2分 - 05CVE-2026-75082 · LOW 2.1
A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
最高第 1 名08:26 达到08:26 首次观测上榜19:28 观测离榜累计约11小时2分 - 06CVE-2026-75088 · LOW 2.1
A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument delid can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
最高第 2 名09:30 达到09:30 首次观测上榜20:32 观测离榜累计约11小时2分 - 07CVE-2026-75089 · MEDIUM 5.5
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
最高第 1 名09:30 达到09:30 首次观测上榜20:32 观测离榜累计约11小时2分 - 08CVE-2026-75090 · LOW 2.1
A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component GGUF Tokenizer. The manipulation of the argument eos_token_id/bos_token_id/unknown_token_id results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 0.8.23 can resolve this issue. The patch is identified as cd5297e2ea5cb27c790bdcf2f3c2f1064a81d55e. Upgrading the affected component is recommended.
最高第 3 名10:18 达到10:18 首次观测上榜20:32 观测离榜累计约10小时14分 - 09CVE-2026-75093 · LOW 2.1
A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Such manipulation leads to incorrect calculation of buffer size. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 66b10bda8895f4bfaf8c205361f0125cdf51f99b. It is best practice to apply a patch to resolve this issue.
最高第 2 名10:18 达到10:18 首次观测上榜20:32 观测离榜累计约10小时14分 - 10CVE-2026-75094 · HIGH 8.5
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
最高第 1 名10:18 达到10:18 首次观测上榜20:32 观测离榜累计约10小时14分 - 11CVE-2026-75086 · LOW 2.1
A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php. Such manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
最高第 4 名09:30 达到09:30 首次观测上榜19:28 观测离榜累计约9小时58分 - 12CVE-2026-75087 · LOW 2.1
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
最高第 3 名09:30 达到09:30 首次观测上榜19:28 观测离榜累计约9小时58分 - 13CVE-2026-75078 · LOW 2.1
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
最高第 3 名07:22 达到07:22 首次观测上榜17:20 观测离榜累计约9小时58分 - 14CVE-2026-75587 · LOW 3.6
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
最高第 2 名07:22 达到07:22 首次观测上榜17:20 观测离榜累计约9小时58分 - 15CVE-2026-67961 · UNKNOWN
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.
最高第 4 名07:22 达到07:22 首次观测上榜16:32 观测离榜累计约9小时10分 - 16CVE-2026-11801 · HIGH 7.5
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including registered post types, labels, associated taxonomies, form scheme metadata, contact options, and custom field meta keys.
最高第 2 名11:22 达到11:22 首次观测上榜20:32 观测离榜累计约9小时10分 - 17CVE-2026-75151 · MEDIUM 5.3
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.
最高第 1 名11:22 达到11:22 首次观测上榜20:32 观测离榜累计约9小时10分 - 18CVE-2026-67919 · UNKNOWN
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components
最高第 5 名07:22 达到07:22 首次观测上榜15:28 观测离榜累计约8小时6分 - 19CVE-2026-42162 · UNKNOWN
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.
最高第 7 名07:22 达到07:22 首次观测上榜14:24 观测离榜累计约7小时2分 - 20CVE-2026-42164 · UNKNOWN
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
最高第 6 名07:22 达到07:22 首次观测上榜14:24 观测离榜累计约7小时2分 - 21CVE-2026-15748 · CRITICAL 9.8
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
最高第 2 名14:24 达到14:24 首次观测上榜20:32 观测离榜累计约6小时8分 - 22CVE-2026-75091 · HIGH 7.2
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
最高第 1 名14:24 达到14:24 首次观测上榜20:32 观测离榜累计约6小时8分 - 23CVE-2026-9859 · MEDIUM 6.5
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an arbitrary channel via a crafted PATCH request. Mattermost Advisory ID: MMSA-2026-00686
最高第 1 名06:18 达到06:18 首次观测上榜11:22 观测离榜累计约5小时4分 - 24CVE-2026-15371 · HIGH 8.1
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.
最高第 1 名15:28 达到15:28 首次观测上榜20:32 观测离榜累计约5小时4分 - 25CVE-2026-38165 · UNKNOWN
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
最高第 8 名07:22 达到07:22 首次观测上榜11:22 观测离榜累计约4小时 - 26CVE-2026-71424 · CRITICAL 9.6
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server/features/mcp/api.py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_server_to_api_mcp_server returns that row through auth_template.headers to any BASIC_ACCESS user. This issue is fixed in versions 3.1.10, 3.2.14, and 4.0.0.
最高第 4 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 27CVE-2026-75077 · LOW 2.1
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
最高第 3 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 28CVE-2026-9816 · HIGH 8.3
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitrary users via POST /api/v2/boards/{boardID}/members and POST /api/v2/teams/{teamID}/archive/import.. Mattermost Advisory ID: MMSA-2026-00685
最高第 2 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 29CVE-2026-34884 · UNKNOWN
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.
最高第 1 名16:32 达到16:32 首次观测上榜20:32 观测离榜累计约4小时 - 30CVE-2024-14045 · LOW 2.1
A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.
最高第 2 名17:20 达到17:20 首次观测上榜20:32 观测离榜累计约3小时12分 - 31CVE-2026-43971 · MEDIUM 6.3
Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping or token-grammar validation. A > byte in target prematurely closes the URI slot, allowing an attacker to append additional link entries with attacker-chosen rel directives. A " or \ in rel escapes the quoted string and opens new parameters. Any byte — including whitespace, =, and " — in an attribute key is emitted verbatim. Because browsers act on Link: directives such as rel="preconnect", rel="preload", and rel="prerender", an attacker who can influence these fields in an application that round-trips parsed Link headers through cow_link:link/1 can force victim browsers to make out-of-band connections to attacker-controlled origins. This issue affects cowlib: from 2.9.0 onward.
最高第 1 名17:20 达到17:20 首次观测上榜20:32 观测离榜累计约3小时12分 - 32CVE-2026-67918 · UNKNOWN
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint
最高第 8 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 33CVE-2026-67960 · UNKNOWN
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
最高第 7 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 34CVE-2026-69146 · MEDIUM 6.5
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the dataset_inputs lineage metadata without UPDATE permission. This issue is fixed in version 3.15.0.
最高第 6 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 35CVE-2026-69148 · HIGH 7.1
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.
最高第 5 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 36CVE-2026-68519 · HIGH 7.1
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enabled, allowing configured redirection, command chaining, or pipes to execute when an alert triggers. This issue is fixed in 4.5.6.
最高第 5 名02:18 达到02:18 首次观测上榜04:26 观测离榜累计约2小时8分 - 37CVE-2026-68520 · MEDIUM 5.3
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthenticated GET /api/4/config and GET /api/4/config/ip requests. This issue is fixed in 4.5.6.
最高第 4 名02:18 达到02:18 首次观测上榜04:26 观测离榜累计约2小时8分 - 38CVE-2026-71491 · HIGH 8.7
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format(sql, strip_comments=True). This issue is fixed in version 0.6.0.
最高第 3 名02:18 达到02:18 首次观测上榜04:26 观测离榜累计约2小时8分 - 39CVE-2026-71979 · HIGH 8.7
INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash the daemon by sending malformed XML with mismatched tags whose names exceed 1024 bytes. Attackers can send a single TCP packet on port 7624 with mismatched XML tags to trigger an unbounded sprintf() write into a fixed 1024-byte stack buffer in MsgQueue.cpp, terminating the daemon and disrupting all active client and driver sessions.
最高第 2 名02:18 达到02:18 首次观测上榜04:26 观测离榜累计约2小时8分 - 40CVE-2026-71980 · HIGH 8.7
Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundaries by sending a zero-length comfort-noise RTP payload. A zero-length payload causes an integer underflow in the uint8_t filter order calculation, which wraps to 255 and is clamped to 10, causing the function to unconditionally read 11 bytes from a zero-byte buffer, resulting in media process termination or silent consumption of adjacent heap memory as reflection coefficients.
最高第 1 名02:18 达到02:18 首次观测上榜04:26 观测离榜累计约2小时8分 - 41CVE-2026-65349 · UNKNOWN
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to cause unexpected system termination or read kernel memory.
最高第 12 名06:18 达到06:18 首次观测上榜08:26 观测离榜累计约2小时8分 - 42CVE-2026-65351 · UNKNOWN
This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
最高第 11 名06:18 达到06:18 首次观测上榜08:26 观测离榜累计约2小时8分 - 43CVE-2026-67854 · UNKNOWN
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
最高第 10 名06:18 达到06:18 首次观测上榜08:26 观测离榜累计约2小时8分 - 44CVE-2026-67868 · UNKNOWN
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
最高第 9 名06:18 达到06:18 首次观测上榜08:26 观测离榜累计约2小时8分 - 45CVE-2026-18929 · MEDIUM 6.9
Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowing an attacker to supply a malicious .docx file containing a zip bomb that decompresses to a significantly larger size, causing excessive memory consumption and crashing the application server. The issue was fixed in versions: 3.8.2, 4.26.3 and 5.4.4. The fix is available across all distribution types.
最高第 1 名18:24 达到18:24 首次观测上榜20:32 观测离榜累计约2小时8分 - 46CVE-2026-75874 · UNKNOWN
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154.
最高第 1 名21:20 达到21:20 首次观测上榜23:28 观测离榜累计约2小时8分 - 47CVE-2026-75049 · MEDIUM 6.5
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
最高第 12 名00:26 达到00:26 首次观测上榜02:18 观测离榜累计约1小时52分 - 48CVE-2026-75050 · HIGH 7.1
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
最高第 11 名00:26 达到00:26 首次观测上榜02:18 观测离榜累计约1小时52分 - 49CVE-2026-75051 · HIGH 8.1
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
最高第 10 名00:26 达到00:26 首次观测上榜02:18 观测离榜累计约1小时52分 - 50CVE-2026-75052 · LOW 3.6
In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects
最高第 9 名00:26 达到00:26 首次观测上榜02:18 观测离榜累计约1小时52分


































































































