
NVD · 实时热榜
- 01CVE-2026-77645 · CRITICAL 9.2
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
最高第 2 名06:18 达到06:18 首次观测上榜12:26 观测离榜累计约6小时8分 - 02CVE-2026-77646 · HIGH 7.7
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
最高第 1 名06:18 达到06:18 首次观测上榜12:26 观测离榜累计约6小时8分 - 03CVE-2026-20679 · UNKNOWN
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
最高第 5 名09:30 达到09:30 首次观测上榜15:22 观测离榜累计约5小时52分 - 04CVE-2026-43679 · UNKNOWN
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
最高第 4 名09:30 达到09:30 首次观测上榜15:22 观测离榜累计约5小时52分 - 05CVE-2026-77649 · CRITICAL 9.8
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
最高第 3 名09:30 达到09:30 首次观测上榜15:22 观测离榜累计约5小时52分 - 06CVE-2026-77650 · CRITICAL 9.8
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
最高第 2 名09:30 达到09:30 首次观测上榜15:22 观测离榜累计约5小时52分 - 07CVE-2026-77651 · CRITICAL 9.8
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
最高第 1 名09:30 达到09:30 首次观测上榜15:22 观测离榜累计约5小时52分 - 08CVE-2026-72860 · MEDIUM 6.3
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.\d+\.\d+)$, but the WHATWG URL parser canonicalizes such literals to hextets before the guard runs, so new URL("http://[::ffff:127.0.0.1]/").hostname yields [::ffff:7f00:1] and the pattern is tested against a string it is never handed. Every IPv4-mapped address therefore passes, and http://[::ffff:7f00:1] and http://[::ffff:a9fe:a9fe] reach loopback and link-local metadata addresses; a hostname whose A record points at an internal address passes as well because no resolution occurs. In the custom-embedding branch the upstream response body is truncated to 200 bytes and returned to the caller whenever the upstream status is neither 2xx nor 401 nor 403, which discloses the beginning of internal responses, and the other validation types remain usable for blind internal port scanning through status and timing differences. The caller-supplied apiKey is forwarded to the internal destination as an Authorization Bearer header. A dashboard session is required by default, and none is required when requireLogin is disabled.
最高第 6 名06:18 达到06:18 首次观测上榜11:22 观测离榜累计约5小时4分 - 09CVE-2026-77642 · HIGH 7.5
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
最高第 5 名06:18 达到06:18 首次观测上榜11:22 观测离榜累计约5小时4分 - 10CVE-2026-77643 · MEDIUM 4.4
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
最高第 4 名06:18 达到06:18 首次观测上榜11:22 观测离榜累计约5小时4分 - 11CVE-2026-77644 · CRITICAL 9.3
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.
最高第 3 名06:18 达到06:18 首次观测上榜11:22 观测离榜累计约5小时4分 - 12CVE-2026-45202 · UNKNOWN
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.
最高第 3 名12:26 达到12:26 首次观测上榜17:30 观测离榜累计约5小时4分 - 13CVE-2026-65644 · UNKNOWN
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the Omnichannel Queue side panel (InquireSidePanelItem.tsx), injecting a real, clickable HTML link - pointing to any attacker-controlled domain, with arbitrary social-engineering text - into the DOM of any agent viewing the queue.
最高第 2 名12:26 达到12:26 首次观测上榜17:30 观测离榜累计约5小时4分 - 14CVE-2026-65645 · UNKNOWN
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id or message-id. The authorization check resolves to a room the attacker already has access to, while the downstream data query fans out across all rooms - disclosing private thread parents and their full reply content to any low-privilege authenticated user. The REST route chat.getThreadsList was patched in v5.0 (HackerOne report #1446767) by adding rid: {type:'string'} AJV validation. The equivalent DDP method was never given the same fix and remains exploitable
最高第 1 名12:26 达到12:26 首次观测上榜17:30 观测离榜累计约5小时4分 - 15CVE-2026-77113 · MEDIUM 6.7
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
最高第 3 名07:22 达到07:22 首次观测上榜12:26 观测离榜累计约5小时4分 - 16CVE-2026-77647 · CRITICAL 9.8
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
最高第 2 名07:22 达到07:22 首次观测上榜12:26 观测离榜累计约5小时4分 - 17CVE-2026-77648 · LOW 2.2
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
最高第 1 名07:22 达到07:22 首次观测上榜12:26 观测离榜累计约5小时4分 - 18CVE-2026-76155 · CRITICAL 9.3
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
最高第 5 名10:18 达到10:18 首次观测上榜15:22 观测离榜累计约5小时4分 - 19CVE-2026-76156 · CRITICAL 9.4
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
最高第 4 名10:18 达到10:18 首次观测上榜15:22 观测离榜累计约5小时4分 - 20CVE-2026-76157 · HIGH 8.8
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.
最高第 3 名10:18 达到10:18 首次观测上榜15:22 观测离榜累计约5小时4分 - 21CVE-2026-77391 · LOW 2.1
A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
最高第 2 名10:18 达到10:18 首次观测上榜15:22 观测离榜累计约5小时4分 - 22CVE-2026-77392 · LOW 2.1
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
最高第 1 名10:18 达到10:18 首次观测上榜15:22 观测离榜累计约5小时4分 - 23CVE-2026-76158 · CRITICAL 9.3
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
最高第 1 名11:22 达到11:22 首次观测上榜16:26 观测离榜累计约5小时4分 - 24CVE-2026-16520 · HIGH 8.7
Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass. This issue affects Genian NAC V4.0: from 4.0.0 before 4.0.175(Revision 150340); Genian NAC V5.0: from 5.0.0 before 5.0.65 LTS(Revision 150331), from 5.0.0 before 5.0.75 LTS(Revision 150330), from 5.0.0 before 5.0.87 Release Stable(Revision 150329), and from 5.0.0 before 5.0.88(Revision 150328); Genian ZTNA V6.0: from 6.0.0 before 6.0.26 LTS(Revision 150337), from 6.0.0 before 6.0.35 LTS(Revision 150336), from 6.0.0 before 6.0.47 Release Stable(Revision 150334), and from 6.0.0 before 6.0.48(Revision 150333).
最高第 1 名08:26 达到08:26 首次观测上榜12:26 观测离榜累计约4小时 - 25CVE-2026-70105 · MEDIUM 6.5
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
最高第 11 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 26CVE-2026-72818 · HIGH 8.7
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain that such input never supplies, the engine explores those partitions before failing at each offset. A few kilobytes of input therefore consumes seconds to minutes of single-threaded CPU, and the HANG_RE substitution performed before matching does not collapse the pattern. TweetTokenizer is intended for tokenizing untrusted social-media text, so any service that applies it, or the module-level casual_tokenize, to submitted text can be stalled per request without authentication. Version 3.10.1 bounds the label repetition.
最高第 10 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 27CVE-2026-72843 · CRITICAL 9.3
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the customer by the uuid taken from the URL path and writes the supplied fields back to that record, hashing a password if one is provided, without verifying that the caller owns the record. An unauthenticated request carrying a known customer uuid can therefore overwrite that customer's email address and password and read back the updated record from the 200 response, taking over the account and locking out its owner. Customer uuids are exposed through order confirmation email links and administrative URLs. Version 2.2.1 changes the route to "access": "private".
最高第 9 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 28CVE-2026-72846 · MEDIUM 5.3
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call fetch on the stored URL directly. The validatePublicHttpUrl helper in packages/backend/src/utils/ssrfProtection.ts, used for MCP server URLs, is not applied on either path, and the webhook fields carry no server-side URL constraint. A user able to create or trigger a scheduled delivery can therefore direct the server to issue POST requests to private, loopback and link-local addresses, including cloud metadata endpoints, and can distinguish reachable internal services from unreachable ones through the resulting errors. The upstream response is never returned to the requester; on a failure status its body is written to the server log instead. Version 1.146.4 routes both clients through postSchedulerWebhook from packages/backend/src/utils/schedulerWebhookValidation rather than calling fetch directly.
最高第 8 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 29CVE-2026-72848 · HIGH 7.7
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no domain comparison and no check for private, loopback or link-local destinations. An attacker who controls or influences an ingested sitemap can therefore point a nested sitemap entry at an internal address and make the server fetch it even when the deploying application set restrict_to_same_domain to True specifically to confine outbound requests. The fetched content is parsed and surfaces in the returned Documents, so internal responses are disclosed to the caller rather than merely requested.
最高第 7 名06:18 达到06:18 首次观测上榜10:18 观测离榜累计约4小时 - 30CVE-2026-18409 · HIGH 7.2
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit relies on the plugin's own wp_kses_allowed_html filter widening the 'post' allowlist to permit iframe elements with a data-src attribute, which is not on WordPress's URI-attribute sanitization list, allowing a javascript: URI stored in data-src to survive kses processing and subsequently be promoted to a live src attribute by the bundled admin script view-entry.min.js.
最高第 6 名12:26 达到12:26 首次观测上榜16:26 观测离榜累计约4小时 - 31CVE-2026-45199 · UNKNOWN
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
最高第 5 名12:26 达到12:26 首次观测上榜16:26 观测离榜累计约4小时 - 32CVE-2026-45201 · UNKNOWN
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such crafted log2 page size could lead to 4K pages being treated as higher order pages and allowing read and/or write access to the memory beyond 4K threshold.
最高第 4 名12:26 达到12:26 首次观测上榜16:26 观测离榜累计约4小时 - 33CVE-2026-73267 · HIGH 7.7
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's local-cluster or other tenants' clusters, due to a missing ownership check. This vulnerability can lead to a denial of service by enabling unauthorized deletion of ManagedClusters.
最高第 4 名11:22 达到11:22 首次观测上榜15:22 观测离榜累计约4小时 - 34CVE-2026-76131 · MEDIUM 6.9
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.
最高第 3 名11:22 达到11:22 首次观测上榜15:22 观测离榜累计约4小时 - 35CVE-2026-76137 · MEDIUM 4.8
Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may escalate privileges via a local named pipe.
最高第 2 名11:22 达到11:22 首次观测上榜15:22 观测离榜累计约4小时 - 36CVE-2026-69555 · CRITICAL 10
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
最高第 16 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 37CVE-2026-69558 · HIGH 8.6
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
最高第 15 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 38CVE-2026-69836 · CRITICAL 10
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
最高第 14 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 39CVE-2026-69851 · CRITICAL 9.9
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
最高第 13 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 40CVE-2026-69855 · HIGH 7.7
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
最高第 12 名06:18 达到06:18 首次观测上榜09:30 观测离榜累计约3小时12分 - 41CVE-2026-17559 · MEDIUM 5.3
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages.
最高第 10 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 42CVE-2026-18356 · LOW 3.7
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
最高第 9 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 43CVE-2026-19848 · MEDIUM 6.5
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers to store shortcodes that are then executed when the page is viewed, disclosing a chosen user's email address, login and registration date.
最高第 8 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 44CVE-2026-59279 · HIGH 7.5
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0
最高第 7 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 45CVE-2026-59308 · MEDIUM 4.2
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0
最高第 6 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 46CVE-2026-59318 · MEDIUM 6.5
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9
最高第 5 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 47CVE-2026-77029 · MEDIUM 4.6
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
最高第 4 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 48CVE-2026-77759 · HIGH 8.7
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.
最高第 3 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 49CVE-2026-77775 · HIGH 7.7
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the same header for the passthrough routes. No check rejects loopback, link-local, or RFC 1918 destinations, and because the component is a proxy the upstream response is returned to the caller, so the request reaches internal services and cloud metadata addresses and their responses are disclosed. The Authorization header accompanying the request is forwarded unchanged to the caller-designated host. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOM_PROXY_TOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.
最高第 2 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分 - 50CVE-2026-77776 · CRITICAL 9.3
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOM_PROXY_TOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.
最高第 1 名20:26 达到20:26 首次观测上榜23:22 观测离榜累计约2小时56分


































































































