📊 2026-07-08 漏洞情报日报 · 200 条 · 高危 91
每日漏洞情报汇总 · 2026-07-08
📊 2026-07-08 漏洞情报日报
📋 共 200 条
🔥 高危/严重 91 条
🚨 CISA-KEV 4 条
💣 Exploit-DB-RSS 8 条 🔥2
🐙 GitHub-Advisory 74 条 🔥35
🛡️ NVD-Latest 54 条 🔥54
⚔️ Sploitus 60 条
🤖 今日安全态势分析
🎯 今日重点关注
- Apache Camel 多组件高危链 (CVE-2026-56140, CVE-2026-53913, CVE-2026-48204 等): 今日集中披露7个CVSS 9.8的严重漏洞,覆盖AWS SNS/SQS、Keycloak、MongoDB Gridfs等多个组件。攻击者可通过输入验证缺陷或认证绕过,远程执行代码或窃取凭据,利用难度低,影响范围极广。
- EGroupware 远程代码执行 (CVE-2026-27823): 企业协作平台EGroupware存在严重RCE漏洞,已登录用户(包括自助注册用户)可利用此漏洞在服务器上执行任意命令,可能造成全站沦陷和数据泄露。
- Better Auth 多重身份认证缺陷 (CVE-2026-53512, CVE-2026-53513): 流行的身份验证库Better Auth被发现OAuth刷新令牌重放和SSRF漏洞,攻击者结合利用可绕过身份验证、劫持用户账号并访问内部网络,影响大量使用该库的现代Web应用。
📈 威胁趋势
- 远程代码执行 (RCE): 今日RCE漏洞数量最多且危害极高。EGroupware、Goploy和Langroid均曝出严重RCE漏洞,且包含绕过沙箱、绕过安全验证等高级利用手法,威胁等级为严重。
- 输入验证与认证绕过: Apache Camel系列漏洞与Discuz! X5.0 (CVE-2026-49952) 共同构成今日第二大威胁集群。攻击者利用输入过滤不严或认证逻辑缺陷,可实现未授权访问和命令注入。
- 供应链与库依赖风险: Better Auth、Langroid和Decompress库的漏洞凸显了第三方组件安全的重要性。开发者直接使用存在缺陷的依赖将导致整个应用遭受SSRF、沙箱逃逸及恶意文件写入等攻击。
- 信息泄露与访问控制: Goploy存在的跨命名空间IDOR漏洞以及Nessus的SQL注入漏洞,表明内部网络应用和安全管理平台依然是数据窃取的重要目标。
🛡️ 缓解建议
- 立即升级Apache Camel及相关应用: 针对今日披露的大量Apache Camel CVSS 9.8漏洞,建议运维团队立即将Camel升级至厂商发布的安全版本。同时,检查并更新EGroupware、Discuz! X5.0及Nessus等受影响产品至最新补丁。
- 审查并加固身份认证库: 如果项目使用了Better Auth或Langroid组件,请立即将其更新至最新稳定版本,并启用所有可用的安全加固配置(如SSH IP过滤、严格的正则验证规则)。在修复完成前,建议暂时禁用用户自助注册功能。
- 执行最小化端口暴露原则: 检查并收敛Apache Camel、IoTDB(CVE-2026-24014)等关键组件的内部RPC接口,确保其不暴露在不可信网络环境中。对于压缩工具类库,建议在解压前进行文件名和路径遍历检查。
🚨 CISA-KEV(4 条)
Unknown (4 条)
- CVE-2026-48282 - Adobe ColdFusion Path Traversal Vulnerability
CVE-2026-48282
CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability 产品: Adobe ColdFusion 描述: Adobe ColdFusion contains a path traversal vulnerability that could lead… - CVE-2026-56290 - Joomlack Page Builder Improper Access Control Vulnerability
CVE-2026-56290
CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability 产品: Joomlack Page Builder 描述: Joomlack Page Builder contains an improper access…
…另有 2 条 Unknown 级漏洞(已省略)
💣 Exploit-DB-RSS(8 条)
Critical (1 条)
- [webapps] Discuz! X5.0 - Authentication Bypass
CVE-2026-49952Critical 9.1
# Exploit Title: Discuz! X5.0 - Authentication Bypass # CVE: CVE-2026-49952 # Date: 2026-06-26 # Exploit Author: …
High (1 条)
- [remote] Hydra - Stack Buffer Overflow
CVE-2026-56766High 7.5
# Exploit Title: Hydra - Stack Buffer Overflow # CVE: CVE-2026-56766 # Date: 2026-06-26 # Exploit Author: Mohammed…
Medium (1 条)
- [webapps] Tenable Nessus 10.12.1 - SQL Injection
CVE-2026-57588cve-2026-57588Medium 4.3
# Exploit Title: Tenable Nessus 10.12.1 - SQL Injection # CVE: CVE-2026-57588 # Date: 2026-06-26 # Exploit Author: …
Low (1 条)
- [webapps] Flowise 3.1.3 - arbitrary code execution
CVE-2026-58057Low 2.3
# Exploit Title: Flowise 3.1.3 - arbitrary code execution # CVE: CVE-2026-58057 # Date: 2026-06-29 # Exploit Author: …
Unknown (4 条)
- [remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter
# Exploit Title: iOS Bluetooth PAN - Zero-Cost Ethernet Gateway (USB Port 62078) # Date: 2026-06-23 # Exploit Author: Fares Dahoumane (Silent Killer) # Vendor… - [webapps] WordPress Bricks Builder Theme - RCE
CVE-2024-25600
# Exploit Title: WordPress Bricks Builder Theme - RCE # Date: 2026-06-25 # Exploit Author: Jared Brits (K3ysTr0K3R) # Vendor Homepage:…
…另有 2 条 Unknown 级漏洞(已省略)
🐙 GitHub-Advisory(74 条)
Critical (7 条)
- CVE-2026-27823 - EGroupware has a Remote Code Execution Vulnerability
CVE-2026-27823Critical
## Summary A critical vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker… - CVE-2026-53512 - Better Auth: OAuth refresh-token replay via missing client authentication on oid
CVE-2026-53512Critical
Am I affected? Users are affected if all of the following are true: - Their application uses `better-auth` and has enabled at least one of: `oidcProvider()`… - CVE-2026-53513 - @better-auth/sso provider registration has server-side request forgery via unval
CVE-2026-53513Critical
Am I affected? Users are affected if all of the following are true: - Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable… - CVE-2026-53552 - Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and pro
CVE-2026-53552Critical
Summary `Project.AddFile`, `Project.EditFile`, `Project.RemoveFile`, and `Project.Edit` in `cmd/server/api/project/handler.go` accept a project or project-file… - CVE-2026-53486 - Decompress: Archive extraction can create files and links outside of the target
CVE-2026-53486Critical
Impact When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the… - CVE-2026-54760 - Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted
CVE-2026-54760Critical
# SQLChatAgent `_validate_query` dangerous-pattern regex is bypassable via quoted/commented/qualified function names ## Summary The `SQLChatAgent`… - CVE-2026-54769 - Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitiga
CVE-2026-54769Critical
Advisory Details **Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent **Description**: Summary Langroid is…
High (28 条)
- CVE-2026-33655 - New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
CVE-2026-33655High
## Summary The default SSRF protection configuration did not apply IP filtering to hostnames. With `ApplyIPFilterForDomain` disabled by default, URL validation… - CVE-2026-34151 - XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in J
CVE-2026-34151High
Impact With Jetty 12+ a user can craft a URL to access any resource the Jetty instance is allowed to access. For example… - CVE-2026-40187 - EGroupware has Authenticated RCE via Malicious eTemplate Upload
CVE-2026-40187High
## Summary An authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS… - CVE-2025-46719 - Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownToke
CVE-2025-46719High
Summary A vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The… - CVE-2026-26192 - Open WebUI vulnerable to Stored XSS via iFrame in citations model
CVE-2026-26192High
Summary Manually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats… - CVE-2026-26193 - Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
CVE-2026-26193High
Summary Manually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a… - GHSA-fqf6-gxhh-2xhw - uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (s High
`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `--backup`/`-b` and returns `BackupMode::None` when only `--suffix` is… - CVE-2026-53514 - Better Auth vulnerable to unauthorized invitation acceptance via unverified emai
CVE-2026-53514High
Am I affected? Users are affected if all of the following are true: - Their application uses `better-auth` with the `organization` plugin (`import {… - CVE-2026-53516 - Better Auth has an account takeover issue via OAuth auto-link to unverified pre
CVE-2026-53516High
Am I affected? Users are affected if all of the following are true: - Their application uses `better-auth` at a version `< 1.6.11` on the stable line, or any… - GHSA-86j7-9j95-vpqj - Better Auth has stored XSS in the auth-server origin via javascript: redirect_ur High
Am I affected? Check each condition. Users are affected when all of the first three hold. - Their application enables the `oidc-provider` plugin or the `mcp`… - GHSA-9h47-pqcx-hjr4 - Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advert High
Am I affected? Users are affected if all of the following are true: - Their application uses `better-auth` at a version below the patched release. - Their… - CVE-2026-53517 - Better Auth: OAuth refresh-token rotation forks the token family on concurrent r
CVE-2026-53517High
Am I affected? Users are affected if all of the following are true: - Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`,… - CVE-2026-53518 - @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent r
CVE-2026-53518High
Am I affected? Users are affected if all of the following are true: - Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`,… - GHSA-j8v8-g9cx-5qf4 - @better-auth/scim: Account/provider takeover via missing owner binding on non-or High
Am I affected? Users are affected if all of these hold: - They install and register the `@better-auth/scim` plugin (`plugins: [scim()]`). - They create SCIM… - CVE-2026-53530 - ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary s
CVE-2026-53530High
Summary The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter… - CVE-2026-53553 - Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote
CVE-2026-53553High
> [ Click here to jump to the Simplified Chinese version (点击跳转到简体中文版本)](#goploy-系统任意文件读取) # Goploy System Arbitrary File Read Vulnerability ## Basic… - CVE-2026-54771 - Langroid: handle_message() executes user-supplied tool JSON without sender verif
CVE-2026-54771High
## Summary A Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are… - CVE-2026-54641 - OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
CVE-2026-54641High
Summary A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying… - CVE-2026-54640 - OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAss
CVE-2026-54640High
Summary The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS… - CVE-2026-55076 - Coder's OIDC email_verified type coercion bypass enables account takeover via un
CVE-2026-55076High
Summary Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the… - CVE-2026-55075 - Coder vulnerable to OIDC account takeover via email-based user matching and emai
CVE-2026-55075High
Summary Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing… - CVE-2026-55077 - Coder: User-admin role can reset owner account password
CVE-2026-55077High
Summary The `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner`… - CVE-2026-55427 - Coder vulnerable to SSH config injection via unsanitized server-supplied values
CVE-2026-55427High
Summary `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing… - CVE-2026-55429 - Coder's workspace app upsert allows cross-workspace agent rebinding via user-con
CVE-2026-55429High
Summary `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's… - CVE-2026-55428 - Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs i
CVE-2026-55428High
Summary The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The… - CVE-2026-55431 - Coder's session token leaked to arbitrary hosts via `coder open app` for externa
CVE-2026-55431High
Summary `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN`… - CVE-2026-55436 - Coder's AI Bridge Proxy skips TLS certificate verification in default configurat
CVE-2026-55436High
Summary The AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure… - CVE-2026-55426 - Linuxfabrik Monitoring Plugins have local privilege escalation using embedded co
CVE-2026-55426High
Summary When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands.…
Medium (32 条)
- CVE-2026-44342 - New API is vulnerable to CSRF through user email binding
CVE-2026-44342Medium
## Summary The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could… - CVE-2026-44512 - ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero In
CVE-2026-44512Medium
Summary Null pointer dereference (SIGSEGV) in `Upsample_6_7::adapt_upsample_6_7()` (`onnx/version_converter/adapters/upsample_6_7.h:31`) when… - CVE-2026-45016 - EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
CVE-2026-45016Medium
Summary The function processes image URLs embedded in an HTML email body without validating or restricting URI schemes. The check `!str_starts_with($myUrl,… - CVE-2025-46571 - Open WebUI allows limited stored XSS vila uploaded html file
CVE-2025-46571Medium
Summary Low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id,… - CVE-2026-34225 - Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
CVE-2026-34225Medium
Summary There is a blind server side request forgery in the functionality that allows editing an image via a prompt. The affected function will perform a GET… - CVE-2026-53509 - @aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks
CVE-2026-53509Medium
Summary A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of… - GHSA-59qp-cfj3-rp64 - netfoil has a domain name filter bypass via multiple questions Medium
Summary Potential bypass of domain name filter by crafting a DNS request with multiple questions, with the first question being legitimate. Impact Depends on a… - GHSA-p2fr-6hmx-4528 - @better-auth/oauth-provider may provide access tokens for unauthorized audiences Medium
Am I affected? Users are affected if all of the following hold: - Their application depends on `@better-auth/oauth-provider` on any stable `1.6.x` release…
…另有 24 条 Medium 级漏洞(已省略)
Low (7 条)
- GHSA-3g4q-2f67-2gvh - netfoil has a resource leak in LRU cache Low
Summary When an entry was removed from the LRU cache, a pointer to the removed element was not properly cleaned up. Impact A local attacker can get netfoil to… - GHSA-7856-g3gv-9wq8 - netfoil: Attacker controlled data written to logs Low
Summary Domain names were written to the log without first being validated to contain allowed characters. Impact Depends on how the logs were used. - GHSA-2vg6-77g8-24mp - Better Auth: Stale sessions persist after user deletion across admin, anonymous, Low
Am I affected? Users are affected if all of the following are true: - They configure `secondaryStorage` on `betterAuth(...)` (Redis, KV, or any external…
…另有 4 条 Low 级漏洞(已省略)
🛡️ NVD-Latest(54 条)
Critical (17 条)
- CVE-2026-56140 Improper Input Validation vulnerability in Apache Camel AWS SNS component. The
CVE-2026-56140Critical 9.8
CVE-2026-56140 CVSS:9.8 Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a… - CVE-2026-53913 Improper Authentication, Missing Authentication for Critical Function, Not Faili
CVE-2026-53913Critical 9.8
CVE-2026-53913 CVSS:9.8 Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache… - CVE-2026-48204 Improper Input Validation, Improper Access Control vulnerability in Apache Camel
CVE-2026-48204Critical 9.8
CVE-2026-48204 CVSS:9.8 Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The… - CVE-2026-46456 Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. Th
CVE-2026-46456Critical 9.8
CVE-2026-46456 CVSS:9.8 Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes… - CVE-2026-46455 Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component
CVE-2026-46455Critical 9.8
CVE-2026-46455 CVSS:9.8 Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper… - CVE-2026-46454 Improper Input Validation vulnerability in Apache Camel Cometd Component. The c
CVE-2026-46454Critical 9.8
CVE-2026-46454 CVSS:9.8 Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD)… - CVE-2026-43867 Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component.
CVE-2026-43867Critical 9.8
CVE-2026-43867 CVSS:9.8 Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key… - CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances us
CVE-2026-24014Critical 9.8
CVE-2026-24014 CVSS:9.8 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path… - CVE-2026-14808 Prog Management System developed by PROG MIS has a Exposure of Sensitive Inf
CVE-2026-14808Critical 9.8
CVE-2026-14808 CVSS:9.8 Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote… - CVE-2026-14807 ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability,
CVE-2026-14807Critical 9.8
CVE-2026-14807 CVSS:9.8 ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to… - CVE-2025-53830 Anti-Virus for ownCloud is an anti-virus application for file storage, synchroni
CVE-2025-53830Critical 9.1
CVE-2025-53830 CVSS:9.1 Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of… - CVE-2025-53827 ownCloud Core is the server-side component of the file storage, synchronization,
CVE-2025-53827Critical 9.1
CVE-2025-53827 CVSS:9.1 ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions… - CVE-2026-48205 Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in A
CVE-2026-48205Critical 9.1
CVE-2026-48205 CVSS:9.1 Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read… - CVE-2026-48203 Improper Neutralization of Special Elements in Output Used by a Downstream Compo
CVE-2026-48203Critical 9.1
CVE-2026-48203 CVSS:9.1 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation,… - CVE-2026-40047 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection
CVE-2026-40047Critical 9.1
CVE-2026-40047 CVSS:9.1 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The… - CVE-2026-24013 Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift
CVE-2026-24013Critical 9.1
CVE-2026-24013 CVSS:9.1 Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the… - CVE-2026-6382 The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPre
CVE-2026-6382Critical 9.1
CVE-2026-6382 CVSS:9.1 The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress…
High (37 条)
- CVE-2026-46590 Deserialization of Untrusted Data vulnerability in Apache Camel PQC component.
CVE-2026-46590High 8.8
CVE-2026-46590 CVSS:8.8 Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key… - CVE-2026-11962 The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type
CVE-2026-11962High 8.8
CVE-2026-11962 CVSS:8.8 The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing… - CVE-2026-11855 The Simple Membership WordPress plugin before 4.7.5 does not verify the authenti
CVE-2026-11855High 8.8
CVE-2026-11855 CVSS:8.8 The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret… - CVE-2026-10830 The AllCoach WordPress plugin before 1.0.2 does not verify that an email addres
CVE-2026-10830High 8.8
CVE-2026-10830 CVSS:8.8 The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint… - CVE-2026-4249 The throttling event handling mechanism in multiple WSO2 products accepts user-s
CVE-2026-4249High 8.6
CVE-2026-4249 CVSS:8.6 The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of… - CVE-2025-53828 SharePoint for ownCloud is an application for using SharePoint with the file sto
CVE-2025-53828High 8.5
CVE-2025-53828 CVSS:8.5 SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud… - CVE-2026-59195 pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package nam
CVE-2026-59195High 8.2
CVE-2026-59195 CVSS:8.2 pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and… - CVE-2026-46591 Improper Neutralization of Special Elements in Data Query Logic vulnerability in
CVE-2026-46591High 8.2
CVE-2026-46591 CVSS:8.2 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer… - CVE-2026-49297 Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanF
CVE-2026-49297High 8.1
CVE-2026-49297 CVSS:8.1 Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned… - CVE-2026-43865 Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast compon
CVE-2026-43865High 8.1
CVE-2026-43865 CVSS:8.1 Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages… - CVE-2026-42527 Deserialization of Untrusted Data vulnerability in Apache Camel. The default Ob
CVE-2026-42527High 8.1
CVE-2026-42527 CVSS:8.1 Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache… - CVE-2026-40859 Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vert
CVE-2026-40859High 8.1
CVE-2026-40859 CVSS:8.1 Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies… - CVE-2026-12083 The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site
CVE-2026-12083High 8.1
CVE-2026-12083 CVSS:8.1 The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not… - CVE-2025-53829 ownCloud is a file storage, synchronization, and sharing application. In ownClou
CVE-2025-53829High 8.0
CVE-2025-53829 CVSS:8.0 ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with… - CVE-2026-11766 The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise a
CVE-2026-11766High 8.0
CVE-2026-11766 CVSS:8.0 The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea profile fields… - CVE-2026-6901 Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. Th
CVE-2026-6901High 7.7
CVE-2026-6901 CVSS:7.7 Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. 产品: - CVE-2026-9165 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Ce
CVE-2026-9165High 7.7
CVE-2026-9165 CVSS:7.7 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served… - CVE-2026-13708 Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading
CVE-2026-13708High 7.5
CVE-2026-13708 CVSS:7.5 Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol.… - CVE-2026-55994 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized
CVE-2026-55994High 7.5
CVE-2026-55994 CVSS:7.5 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability… - CVE-2026-55993 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized
CVE-2026-55993High 7.5
CVE-2026-55993 CVSS:7.5 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability… - CVE-2026-46726 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized
CVE-2026-46726High 7.5
CVE-2026-46726 CVSS:7.5 Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability… - CVE-2026-46592 Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2026-46592High 7.5
CVE-2026-46592 CVSS:7.5 Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The… - CVE-2026-46585 Improper Input Validation, Authorization Bypass Through User-Controlled Key vuln
CVE-2026-46585High 7.5
CVE-2026-46585 CVSS:7.5 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component. The… - CVE-2026-46457 Improper Input Validation vulnerability in Apache Camel NATS component. The cam
CVE-2026-46457High 7.5
CVE-2026-46457 CVSS:7.5 Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into… - CVE-2026-24012 Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interfac
CVE-2026-24012High 7.5
CVE-2026-24012 CVSS:7.5 Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and… - CVE-2026-14809 Prog Management System developed by PROG MIS has a SQL Injection vulnerability,
CVE-2026-14809High 7.5
CVE-2026-14809 CVSS:7.5 Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject… - CVE-2024-6228 The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does
CVE-2024-6228High 7.5
CVE-2024-6228 CVSS:7.5 The Notifications for Forms & WordPress Actions WordPress plugin before 2.6 does not validate a user-supplied value before using it to… - CVE-2026-6900 Improper certificate validation vulnerability in B&R Industrial Automation GmbH
CVE-2026-6900High 7.4
CVE-2026-6900 CVSS:7.4 Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. 产品: - CVE-2026-58380 A flaw was found in GIMP's PNM file format parser. When parsing a specially craf
CVE-2026-58380High 7.3
CVE-2026-58380 CVSS:7.3 A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes… - CVE-2026-49042 Improper Input Validation vulnerability in Apache Camel. This issue affects Apa
CVE-2026-49042High 7.3
CVE-2026-49042 CVSS:7.3 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0… - CVE-2026-46588 Improper Input Validation vulnerability in Apache Camel. This issue affects Apa
CVE-2026-46588High 7.3
CVE-2026-46588 CVSS:7.3 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2,… - CVE-2026-46587 Improper Input Validation vulnerability in Apache Camel. This issue affects Apa
CVE-2026-46587High 7.3
CVE-2026-46587 CVSS:7.3 Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: through 4.14.7, from 4.15.0 through 4.18.2,… - CVE-2026-43866 Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JM
CVE-2026-43866High 7.3
CVE-2026-43866 CVSS:7.3 Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in… - CVE-2026-14802 A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. Thi
CVE-2026-14802High 7.3
CVE-2026-14802 CVSS:7.3 A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file… - CVE-2026-59196 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias
CVE-2026-59196High 7.1
CVE-2026-59196 CVSS:7.1 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules… - CVE-2026-59194 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry co
CVE-2026-59194High 7.1
CVE-2026-59194 CVSS:7.1 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory… - CVE-2026-13705 Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bund
CVE-2026-13705High 7.1
CVE-2026-13705 CVSS:7.1 Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal…
⚔️ Sploitus(60 条)
Unknown (60 条)
- Exploit for Command Injection in Litellm exploit
Exploit for Command Injection in Litellm exploit - Exploit for Deserialization of Untrusted Data in Microsoft exploit
Exploit for Deserialization of Untrusted Data in Microsoft exploit
…另有 58 条 Unknown 级漏洞(已省略)
🤖 漏洞情报自动汇总 · 2026-07-08 · 数据来源: NVD / GitHub Advisory / Sploitus / CISA-KEV