全部/科技/实时热榜

NVD · 实时热榜

HISTORY2026年8月26日205 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS205 个热搜
  1. 01
    CVE-2026-16639 · UNKNOWN

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

    最高第 2007:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  2. 02
    CVE-2026-16640 · UNKNOWN

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.

    最高第 1907:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  3. 03
    CVE-2026-16641 · UNKNOWN

    Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

    最高第 1807:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  4. 04
    CVE-2026-16642 · UNKNOWN

    Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

    最高第 1707:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  5. 05
    CVE-2026-16643 · UNKNOWN

    Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

    最高第 1607:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  6. 06
    CVE-2026-16644 · UNKNOWN

    Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

    最高第 1507:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  7. 07
    CVE-2026-16645 · UNKNOWN

    Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.

    最高第 1407:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  8. 08
    CVE-2026-16646 · UNKNOWN

    Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

    最高第 1307:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  9. 09
    CVE-2026-18259 · UNKNOWN

    Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

    最高第 1207:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  10. 10
    CVE-2026-18260 · UNKNOWN

    Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.

    最高第 1107:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  11. 11
    CVE-2026-18261 · UNKNOWN

    Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

    最高第 1007:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  12. 12
    CVE-2026-18985 · UNKNOWN

    Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

    最高第 907:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  13. 13
    CVE-2026-41707 · HIGH 7.4

    Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11

    最高第 807:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  14. 14
    CVE-2026-44476 · MEDIUM 6.3

    Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its client_secret. This occurs because the Dynamic Client Registration feature creates applications with confidential: false hard-coded, even though the registration response returns a client_secret and advertises support for the client_secret_basic and client_secret_post authentication methods; since Doorkeeper treats a blank or missing secret as valid for non-confidential (public) clients, the secret is never verified. Only projects that have explicitly enabled Dynamic Client Registration, which is disabled by default, are affected. This issue is fixed in version 1.10.0.

    最高第 707:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  15. 15
    CVE-2026-54757 · HIGH 7.8

    Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclude and MDSectionInclude Jinja2 tags re-parse untrusted Markdown content as template source code using a non-sandboxed jinja2.Environment. An attacker who controls content that Trestle renders, such as a crafted workspace Markdown file, a third-party SSP document, or a YAML lookup-table value, can inject a Jinja2 expression that traverses Python object internals to execute arbitrary operating system commands in the context of the Trestle process. This issue is fixed in versions 3.12.4 and 4.1.0.

    最高第 607:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  16. 16
    CVE-2026-55805 · UNKNOWN

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

    最高第 507:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  17. 17
    CVE-2026-70665 · MEDIUM 4.2

    Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.

    最高第 407:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  18. 18
    CVE-2026-79911 · CRITICAL 9.3

    A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    最高第 307:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  19. 19
    CVE-2026-79912 · MEDIUM 5.5

    A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

    最高第 207:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  20. 20
    CVE-2026-80138 · CRITICAL 9.2

    ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.

    最高第 107:31 达到07:31 首次观测上榜23:52 观测离榜累计约16小时22分
  21. 21
    CVE-2026-76195 · CRITICAL 10

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    最高第 502:27 达到02:27 首次观测上榜04:19 观测离榜累计约1小时52分
  22. 22
    CVE-2026-76197 · CRITICAL 10

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    最高第 402:27 达到02:27 首次观测上榜04:19 观测离榜累计约1小时52分
  23. 23
    CVE-2026-76198 · MEDIUM 5.5

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    最高第 302:27 达到02:27 首次观测上榜04:19 观测离榜累计约1小时52分
  24. 24
    CVE-2026-79786 · HIGH 7

    Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions.

    最高第 503:31 达到03:31 首次观测上榜05:23 观测离榜累计约1小时52分
  25. 25
    CVE-2026-79787 · CRITICAL 9.3

    Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

    最高第 403:31 达到03:31 首次观测上榜05:23 观测离榜累计约1小时52分
  26. 26
    CVE-2026-79788 · HIGH 7.1

    In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an arbitrary HTTP/HTTPS address (including internal/link-local hosts such as http://169.254.169.254) and reassign the built-in Roslin agent to use it. When an AI interaction is triggered, the server issues a request to the attacker-supplied URL (server-side request forgery). For non-2xx responses, the target's response body is reflected verbatim to the attacker's browser via ActionCable/Turbo Stream error messages, making the SSRF readable.

    最高第 303:31 达到03:31 首次观测上榜05:23 观测离榜累计约1小时52分
  27. 27
    CVE-2026-79992 · HIGH 7.8

    A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

    最高第 202:27 达到02:27 首次观测上榜04:19 观测离榜累计约1小时52分
  28. 28
    CVE-2026-80049 · HIGH 8.7

    Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace consults X-Airbyte-Workspace-Id ahead of every resource-derived header, including those for connection, source and destination identifiers. Endpoints whose declared request bodies carry only a resource identifier are nonetheless reached with an added workspaceId field, because the extractor reads the body rather than the endpoint's schema, so the permission check is performed against the workspace the caller nominated while the handler acts on the resource identifier the caller supplied. Nothing afterwards compares the resource's owning workspace with the one that was authorized. A member of any workspace can therefore read source and destination configuration, trigger and cancel syncs, and delete connections, sources and destinations that belong to workspaces they have no access to, at whatever privilege level their own workspace membership grants them.

    最高第 203:31 达到03:31 首次观测上榜05:23 观测离榜累计约1小时52分
  29. 29
    CVE-2026-80050 · HIGH 7.1

    ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.

    最高第 103:31 达到03:31 首次观测上榜05:23 观测离榜累计约1小时52分
  30. 30
    CVE-2026-80051 · MEDIUM 5.9

    github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared String, ID, or Boolean scalar instead of raising the request error that the GraphQL specification mandates. In some cases (but not any typical case of JSON sent to a website), a deeply nested value leads to an unrecoverable "fatal error: stack overflow" condition.

    最高第 102:27 达到02:27 首次观测上榜04:19 观测离榜累计约1小时52分
  31. 31
    CVE-2026-24262 · HIGH 8.2

    NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

    最高第 401:17 达到01:17 首次观测上榜02:27 观测离榜累计约1小时10分
  32. 32
    CVE-2026-24263 · HIGH 8.2

    NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

    最高第 301:17 达到01:17 首次观测上榜02:27 观测离榜累计约1小时10分
  33. 33
    CVE-2026-47624 · MEDIUM 6

    NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.

    最高第 201:17 达到01:17 首次观测上榜02:27 观测离榜累计约1小时10分
  34. 34
    CVE-2026-47626 · HIGH 8.2

    NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

    最高第 101:17 达到01:17 首次观测上榜02:27 观测离榜累计约1小时10分
  35. 35
    CVE-2026-79273 · UNKNOWN

    Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    最高第 2005:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  36. 36
    CVE-2026-79274 · UNKNOWN

    Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

    最高第 1905:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  37. 37
    CVE-2026-79275 · UNKNOWN

    Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    最高第 1805:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  38. 38
    CVE-2026-79276 · UNKNOWN

    Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

    最高第 1705:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  39. 39
    CVE-2026-79282 · UNKNOWN

    Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    最高第 1605:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  40. 40
    CVE-2026-79283 · UNKNOWN

    UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

    最高第 1505:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  41. 41
    CVE-2026-79284 · UNKNOWN

    UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    最高第 1405:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  42. 42
    CVE-2026-79285 · UNKNOWN

    Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    最高第 1305:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  43. 43
    CVE-2026-79286 · UNKNOWN

    Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)

    最高第 1205:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  44. 44
    CVE-2026-79287 · UNKNOWN

    Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    最高第 1105:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  45. 45
    CVE-2026-79288 · UNKNOWN

    Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

    最高第 1005:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  46. 46
    CVE-2026-79289 · UNKNOWN

    Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

    最高第 905:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  47. 47
    CVE-2026-79290 · UNKNOWN

    Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

    最高第 805:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  48. 48
    CVE-2026-79291 · UNKNOWN

    Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    最高第 705:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  49. 49
    CVE-2026-79292 · UNKNOWN

    Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    最高第 605:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分
  50. 50
    CVE-2026-79293 · UNKNOWN

    Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

    最高第 505:23 达到05:23 首次观测上榜06:27 观测离榜累计约1小时4分