📊 2026-07-06 漏洞情报日报 · 200 条 · 高危 119
每日漏洞情报汇总 · 2026-07-06
📊 2026-07-06 漏洞情报日报
📋 共 200 条
🔥 高危/严重 119 条
🛡️ NVD-Latest 119 条 🔥119
⚔️ Sploitus 81 条
🤖 今日安全态势分析
🎯 今日重点关注
- CVE-2026-13768 (CVSS 10.0) - Gardyn 智能花园设备:暴露了高权限的 IoTHub 所有者密钥,攻击者利用该密钥可调用 IoTHub 注册表管理功能,获取所有 Gardyn Home Kit 及 Studio 设备的连接信息,进而实施远程代码执行与内网横向移动。PoC 已公开,利用条件极低。
- CVE-2026-27419 (CVSS 9.9) - Zegen 系统文件上传漏洞:影响 Zegen 1.1.9 及更早版本。普通订阅者用户可上传任意文件,结合服务器解析策略可能导致远程代码执行。需要低权限用户账户即可利用。
- CVE-2026-4321 (CVSS 9.8) - Raera Destekz 系统 SQL 注入:土耳其安卡拉 Web 设计公司 Raera 旗下的“Destekz”产品存在 SQL 注入漏洞。攻击者无需身份验证即可通过特殊构造的输入修改后台数据库,可能导致用户数据泄露及管理员权限接管。
- CVE-2026-14544 (CVSS 9.8) - HPLIP 打印软件权限提升:针对 CVE-2026-8631 的修复不完整,允许远程攻击者利用此漏洞在受影响的 HP Linux 打印系统上提升权限或执行任意代码。影响所有使用 HPLIP 的 Linux 发行版。
📈 威胁趋势
- 远程代码执行(RCE)与权限提升:共 4 个高危漏洞与此有关。包括 CVE-2026-13768(IoT 设备 RCE)、CVE-2026-27419(文件上传RCE)、CVE-2026-14544(HPLIP 提权至任意代码执行)、CVE-2026-27436(编辑器代码执行)。攻击路径趋近于从边缘设备或低权限入口渗透至核心系统。
- 信息泄露(凭证/数据库):CVE-2026-13768 暴露可枚举全量设备的高级凭证;CVE-2026-4321 (SQL 注入) 可导致数据库敏感信息泄露。凭证泄露是当前最严重的持续性威胁。
- 文件操作漏洞:CVE-2026-27419(任意文件上传)和 CVE-2026-9725(任意文件删除)表明,不充分的路径与类型校验仍是 Web 应用与 WordPress 插件的共性问题,影响面广。
🛡️ 缓解建议
- 立即隔离并修补高风险 IoT 设备:针对 CVE-2026-13768,在厂商补丁发布前,应立即断开 Gardyn 设备与公网的直接连接,或限制其 IoTHub 通信端点仅允许受信任内部 IP 访问。
- 更新与访问控制:对于 Zegen (≤1.1.9) 及 Raera Destekz 用户,立即联系厂商获取修复版本;暂时无法更新的,对公共上传目录执行严格的文件类型白名单检查,并对 Web 应用启用 WAF 规则以拦截 SQL 注入。
- 升级 HPLIP 及检查系统补丁:所有 Linux 系统管理员应立即升级 HPLIP 至最新版本,并确认 CVE-2026-8631 的补丁已完整安装。临时措施可限制不必要的用户对 CUPS 打印服务的网络访问。
🛡️ NVD-Latest(119 条)
Critical (6 条)
- CVE-2026-13768 Gardyn devices expose a privileged iothubowner key. Access to this key will allo
CVE-2026-13768Critical 10.0
CVE-2026-13768 CVSS:10.0 Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry…
+PoC-in-GitHu - CVE-2026-27419 Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
CVE-2026-27419Critical 9.9
CVE-2026-27419 CVSS:9.9 Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. 产品: - CVE-2026-4321 Improper neutralization of special elements used in an SQL command ('SQL injecti
CVE-2026-4321Critical 9.8
CVE-2026-4321 CVSS:9.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and… - CVE-2026-14544 A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnera
CVE-2026-14544Critical 9.8
CVE-2026-14544 CVSS:9.8 A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow… - CVE-2026-9725 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress
CVE-2026-9725Critical 9.1
CVE-2026-9725 CVSS:9.1 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up… - CVE-2026-27436 Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.
CVE-2026-27436Critical 9.1
CVE-2026-27436 CVSS:9.1 Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. 产品:
High (113 条)
- CVE-2026-14721 A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Th
CVE-2026-14721High 8.8
CVE-2026-14721 CVSS:8.8 A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file… - CVE-2026-14535 In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImports
CVE-2026-14535High 8.8
CVE-2026-14535 CVSS:8.8 In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls… - CVE-2026-14534 Trail of Bits fickling versions up to and including 0.1.10 do not include the Py
CVE-2026-14534High 8.8
CVE-2026-14534 CVSS:8.8 Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site,… - CVE-2025-71380 The Execute Command node in n8n allows authenticated users to execute arbitrary
CVE-2025-71380High 8.8
CVE-2025-71380 CVSS:8.8 The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers… - CVE-2026-14460 Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Rese
CVE-2026-14460High 8.8
CVE-2026-14460 CVSS:8.8 Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument… - CVE-2026-14459 Improper neutralization of argument delimiters in a command ('argument injection
CVE-2026-14459High 8.8
CVE-2026-14459 CVSS:8.8 Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software…
+PoC-in-GitHu - CVE-2026-10054 In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exp
CVE-2026-10054High 8.8
CVE-2026-10054 CVSS:8.8 In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket… - CVE-2026-56037 Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows
CVE-2026-56037High 8.8
CVE-2026-56037 CVSS:8.8 Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup:… - CVE-2026-27414 Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
CVE-2026-27414High 8.8
CVE-2026-27414 CVSS:8.8 Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. 产品: - CVE-2026-27060 Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
CVE-2026-27060High 8.8
CVE-2026-27060 CVSS:8.8 Contributor PHP Object Injection in ARMember Premium <= 7.0 versions. 产品: - CVE-2026-13125 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-13125High 8.8
CVE-2026-13125 CVSS:8.8 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-10055 In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC
CVE-2026-10055High 8.5
CVE-2026-10055 CVSS:8.5 In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client… - CVE-2025-69094 Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-69094High 8.5
CVE-2025-69094 CVSS:8.5 Subscriber SQL Injection in Unicamp <= 2.2.2 versions. 产品: - CVE-2026-54424 An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hos
CVE-2026-54424High 8.4
CVE-2026-54424 CVSS:8.4 An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This…
+PoC-in-GitHu - CVE-2026-57278 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57278High 8.3
CVE-2026-57278 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57277 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57277High 8.3
CVE-2026-57277 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57276 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57276High 8.3
CVE-2026-57276 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57275 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57275High 8.3
CVE-2026-57275 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57274 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57274High 8.3
CVE-2026-57274 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57273 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57273High 8.3
CVE-2026-57273 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57272 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57272High 8.3
CVE-2026-57272 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57271 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57271High 8.3
CVE-2026-57271 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57270 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57270High 8.3
CVE-2026-57270 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57269 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57269High 8.3
CVE-2026-57269 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57268 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57268High 8.3
CVE-2026-57268 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57267 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57267High 8.3
CVE-2026-57267 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57266 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57266High 8.3
CVE-2026-57266 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57265 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57265High 8.3
CVE-2026-57265 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-57264 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-57264High 8.3
CVE-2026-57264 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-13132 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-13132High 8.3
CVE-2026-13132 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-13131 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Playe
CVE-2026-13131High 8.3
CVE-2026-13131 CVSS:8.3 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed… - CVE-2026-14637 A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter
CVE-2026-14637High 8.2
CVE-2026-14637 CVSS:8.2 A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to… - CVE-2026-14336 PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (
CVE-2026-14336High 8.2
CVE-2026-14336 CVSS:8.2 PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in… - CVE-2025-71375 picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in fun
CVE-2025-71375High 8.1
CVE-2025-71375 CVSS:8.1 picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code.… - CVE-2025-71373 picklescan before 0.0.33 fails to detect operator.methodcaller function calls in
CVE-2025-71373High 8.1
CVE-2025-71373 CVSS:8.1 picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security… - CVE-2025-71372 Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef
CVE-2025-71372High 8.1
CVE-2025-71372 CVSS:8.1 Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary… - CVE-2025-71369 picklescan before 0.0.28 fails to detect malicious pickle files that use torch.u
CVE-2025-71369High 8.1
CVE-2025-71369 CVSS:8.1 picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in… - CVE-2025-71367 picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in
CVE-2025-71367High 8.1
CVE-2025-71367 CVSS:8.1 picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security… - CVE-2025-71366 picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main
CVE-2025-71366High 8.1
CVE-2025-71366 CVSS:8.1 picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files,… - CVE-2025-71364 picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocess
CVE-2025-71364High 8.1
CVE-2025-71364 CVSS:8.1 picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods,… - CVE-2025-71362 picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.
CVE-2025-71362High 8.1
CVE-2025-71362 CVSS:8.1 picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings.… - CVE-2025-71360 picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.ca
CVE-2025-71360High 8.1
CVE-2025-71360 CVSS:8.1 picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce methods. Attackers… - CVE-2025-71359 picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize
CVE-2025-71359High 8.1
CVE-2025-71359 CVSS:8.1 picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce… - CVE-2025-71356 picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symboli
CVE-2025-71356High 8.1
CVE-2025-71356 CVSS:8.1 picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression function… - CVE-2025-71353 picklescan before 0.0.28 fails to detect malicious pickle files that exploit tor
CVE-2025-71353High 8.1
CVE-2025-71353 CVSS:8.1 picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce… - CVE-2025-71347 picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py
CVE-2025-71347High 8.1
CVE-2025-71347 CVSS:8.1 picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods,… - CVE-2025-71345 picklescan before 0.0.30 fails to detect malicious pickle files that invoke torc
CVE-2025-71345High 8.1
CVE-2025-71345 CVSS:8.1 picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function.… - CVE-2025-71343 picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib
CVE-2025-71343High 8.1
CVE-2025-71343 CVSS:8.1 picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in… - CVE-2025-71342 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.ru
CVE-2025-71342High 8.1
CVE-2025-71342 CVSS:8.1 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can… - CVE-2026-42382 Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
CVE-2026-42382High 8.1
CVE-2026-42382 CVSS:8.1 Unauthenticated Local File Inclusion in Audrey <= 1.5 versions. 产品: - CVE-2026-27412 Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 ver
CVE-2026-27412High 8.1
CVE-2026-27412 CVSS:8.1 Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. 产品: - CVE-2025-58902 Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2025-58902High 8.1
CVE-2025-58902 CVSS:8.1 Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. 产品: - CVE-2026-8147 In MLflow versions prior to 3.14.0, when running with authentication enabled, th
CVE-2026-8147High 8.1
CVE-2026-8147 CVSS:8.1 In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization… - CVE-2026-5821 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletio
CVE-2026-5821High 8.1
CVE-2026-5821 CVSS:8.1 The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to… - CVE-2026-12252 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (Stanfo
CVE-2026-12252High 7.8
CVE-2026-12252 CVSS:7.8 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser,… - CVE-2026-4967 In IMS, there is a possible out of bounds read due to a missing bounds check. Th
CVE-2026-4967High 7.5
CVE-2026-4967 CVSS:7.5 In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no… - CVE-2026-14352 The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal
CVE-2026-14352High 7.5
CVE-2026-14352 CVSS:7.5 The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the… - CVE-2026-14327 The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal i
CVE-2026-14327High 7.5
CVE-2026-14327 CVSS:7.5 The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the… - CVE-2026-39448 Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 ve
CVE-2026-39448High 7.5
CVE-2026-39448 CVSS:7.5 Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions. 产品: - CVE-2026-11946 An unauthenticated remote attacker can exhaust server memory via the GetEndpoint
CVE-2026-11946High 7.5
CVE-2026-11946 CVSS:7.5 An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field… - CVE-2025-69134 Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Hel
CVE-2025-69134High 7.5
CVE-2025-69134 CVSS:7.5 Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. 产品: - CVE-2025-69133 Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69133High 7.5
CVE-2025-69133 CVSS:7.5 Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. 产品: - CVE-2026-8441 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-8441High 7.5
CVE-2026-8441 CVSS:7.5 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs… - CVE-2026-13369 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary F
CVE-2026-13369High 7.5
CVE-2026-13369 CVSS:7.5 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up… - CVE-2026-13251 The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all
CVE-2026-13251High 7.5
CVE-2026-13251 CVSS:7.5 The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's'… - CVE-2026-9563 In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the J
CVE-2026-9563High 7.5
CVE-2026-9563 CVSS:7.5 In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the… - CVE-2026-33592 An unauthenticated remote attacker can exhaust server memory via the FindServers
CVE-2026-33592High 7.5
CVE-2026-33592 CVSS:7.5 An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field… - CVE-2026-14249 The Request a Quote plugin for WordPress is vulnerable to Code Injection in vers
CVE-2026-14249High 7.5
CVE-2026-14249 CVSS:7.5 The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the… - CVE-2026-13341 A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server p
CVE-2026-13341High 7.4
CVE-2026-13341 CVSS:7.4 A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote… - CVE-2026-14722 A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impa
CVE-2026-14722High 7.3
CVE-2026-14722 CVSS:7.3 A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file… - CVE-2026-14719 A flaw has been found in SourceCodester Onlne Examination & Learning Management
CVE-2026-14719High 7.3
CVE-2026-14719 CVSS:7.3 A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function… - CVE-2026-14713 A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System
CVE-2026-14713High 7.3
CVE-2026-14713 CVSS:7.3 A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the… - CVE-2026-14705 A vulnerability was determined in code-projects Online Examination 1.0. Affected
CVE-2026-14705High 7.3
CVE-2026-14705 CVSS:7.3 A vulnerability was determined in code-projects Online Examination 1.0. Affected by this issue is some unknown functionality of the… - CVE-2026-14700 A security vulnerability has been detected in code-projects Internship Managemen
CVE-2026-14700High 7.3
CVE-2026-14700 CVSS:7.3 A security vulnerability has been detected in code-projects Internship Management System 1.0. The impacted element is an unknown… - CVE-2026-14695 A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Manageme
CVE-2026-14695High 7.3
CVE-2026-14695 CVSS:7.3 A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_client of… - CVE-2026-14690 A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Man
CVE-2026-14690High 7.3
CVE-2026-14690 CVSS:7.3 A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function… - CVE-2026-14688 A vulnerability was identified in itsourcecode Online Hotel Management System 1.
CVE-2026-14688High 7.3
CVE-2026-14688 CVSS:7.3 A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. The affected element is an unknown function of the… - CVE-2026-14660 A vulnerability was found in code-projects Online Job Portal 1.0. The affected e
CVE-2026-14660High 7.3
CVE-2026-14660 CVSS:7.3 A vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php.… - CVE-2026-14654 A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart S
CVE-2026-14654High 7.3
CVE-2026-14654 CVSS:7.3 A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file… - CVE-2026-14653 A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart S
CVE-2026-14653High 7.3
CVE-2026-14653 CVSS:7.3 A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file… - CVE-2026-14652 A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script
CVE-2026-14652High 7.3
CVE-2026-14652 CVSS:7.3 A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file… - CVE-2026-14649 A vulnerability was detected in code-projects Online Voting System 1.0. Impacted
CVE-2026-14649High 7.3
CVE-2026-14649 CVSS:7.3 A vulnerability was detected in code-projects Online Voting System 1.0. Impacted is the function test_input of the file /saveVote.php.… - CVE-2026-14648 A security vulnerability has been detected in code-projects Online Voting System
CVE-2026-14648High 7.3
CVE-2026-14648 CVSS:7.3 A security vulnerability has been detected in code-projects Online Voting System up to 0.x/1.0. This issue affects the function… - CVE-2026-14642 A vulnerability was identified in SourceCodester Class and Exam Timetabling Syst
CVE-2026-14642High 7.3
CVE-2026-14642 CVSS:7.3 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown… - CVE-2026-14641 A vulnerability was determined in SourceCodester Class and Exam Timetabling Syst
CVE-2026-14641High 7.3
CVE-2026-14641 CVSS:7.3 A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown… - CVE-2026-14640 A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0.
CVE-2026-14640High 7.3
CVE-2026-14640 CVSS:7.3 A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php… - CVE-2026-14635 A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstr
CVE-2026-14635High 7.3
CVE-2026-14635 CVSS:7.3 A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This… - CVE-2026-14622 A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 5214
CVE-2026-14622High 7.3
CVE-2026-14622 CVSS:7.3 A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This… - CVE-2026-53478 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release ver
CVE-2026-53478High 7.2
CVE-2026-53478 CVSS:7.2 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version… - CVE-2026-49815 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release ver
CVE-2026-49815High 7.2
CVE-2026-49815 CVSS:7.2 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version… - CVE-2026-49814 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release ver
CVE-2026-49814High 7.2
CVE-2026-49814 CVSS:7.2 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version… - CVE-2026-9148 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-9148High 7.2
CVE-2026-9148 CVSS:7.2 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in… - CVE-2026-13040 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vuln
CVE-2026-13040High 7.2
CVE-2026-13040 CVSS:7.2 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… - CVE-2026-57348 Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions
CVE-2026-57348High 7.2
CVE-2026-57348 CVSS:7.2 Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. 产品: - CVE-2026-9834 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plug
CVE-2026-9834High 7.2
CVE-2026-9834 CVSS:7.2 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection… - CVE-2026-57356 Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19
CVE-2026-57356High 7.1
CVE-2026-57356 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions. 产品: - CVE-2026-57351 Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 version
CVE-2026-57351High 7.1
CVE-2026-57351 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions. 产品: - CVE-2026-57350 Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
CVE-2026-57350High 7.1
CVE-2026-57350 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions. 产品: - CVE-2026-57349 Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.
CVE-2026-57349High 7.1
CVE-2026-57349 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions. 产品: - CVE-2026-57345 Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 ve
CVE-2026-57345High 7.1
CVE-2026-57345 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions. 产品: - CVE-2026-57344 Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versio
CVE-2026-57344High 7.1
CVE-2026-57344 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions. 产品: - CVE-2026-57343 Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
CVE-2026-57343High 7.1
CVE-2026-57343 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions. 产品: - CVE-2026-27430 Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
CVE-2026-27430High 7.1
CVE-2026-27430 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions. 产品: - CVE-2026-27426 Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business
CVE-2026-27426High 7.1
CVE-2026-27426 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions. 产品: - CVE-2026-27425 Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versio
CVE-2026-27425High 7.1
CVE-2026-27425 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions. 产品: - CVE-2026-27408 Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
CVE-2026-27408High 7.1
CVE-2026-27408 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions. 产品: - CVE-2026-27404 Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
CVE-2026-27404High 7.1
CVE-2026-27404 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions. 产品: - CVE-2026-27402 Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPr
CVE-2026-27402High 7.1
CVE-2026-27402 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions. 产品: - CVE-2025-69156 Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress The
CVE-2025-69156High 7.1
CVE-2025-69156 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions. 产品: - CVE-2025-69155 Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.
CVE-2025-69155High 7.1
CVE-2025-69155 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions. 产品: - CVE-2025-69154 Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Th
CVE-2025-69154High 7.1
CVE-2025-69154 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions. 产品: - CVE-2025-69153 Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69153High 7.1
CVE-2025-69153 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. 产品: - CVE-2025-69152 Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordP
CVE-2025-69152High 7.1
CVE-2025-69152 CVSS:7.1 Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. 产品:
⚔️ Sploitus(81 条)
Unknown (81 条)
- Exploit for CVE-2026-9290 exploit
CVE-2026-9290
Exploit for CVE-2026-9290 exploit - Exploit for CVE-2026-8713 exploit
CVE-2026-8713
Exploit for CVE-2026-8713 exploit
…另有 79 条 Unknown 级漏洞(已省略)
🤖 漏洞情报自动汇总 · 2026-07-06 · 数据来源: NVD / GitHub Advisory / Sploitus / CISA-KEV