快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 354457
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2026-25878 |
FroshAdminer Adminer UI is accessible without admin session
|
MEDIUM | 6.9 | 2026-02-09 |
FriendsOfShopware FroshPlatformAdminer
|
CVE NVD | |
| CVE-2026-25806 |
PlaciPy has Missing Authorization Checks on Student Management Endpoints (IDOR)
|
MEDIUM | 5.3 | 2026-02-09 |
Praskla-Technology assessment-placipy
|
CVE NVD | |
| CVE-2026-25810 |
PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts
|
MEDIUM | 5.3 | 2026-02-09 |
Praskla-Technology assessment-placipy
|
CVE NVD | |
| CVE-2026-25876 |
PlaciPy is Missing Authorization on Assessment Results Endpoint
|
MEDIUM | 5.3 | 2026-02-09 |
Praskla-Technology assessment-placipy
|
CVE NVD | |
| CVE-2026-25791 |
Sliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of Service
|
HIGH | 7.5 | 2026-02-09 |
BishopFox sliver
|
CVE NVD | |
| CVE-2026-25765 |
Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url
|
MEDIUM | 5.8 | 2026-02-09 |
lostisland faraday
|
CVE NVD | |
| CVE-2026-25761 |
Command injection via crafted filenames in Super-linter Action
|
HIGH | 8.8 | 2026-02-09 |
super-linter super-linter
|
CVE NVD | |
| CVE-2026-25740 |
Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module
|
MEDIUM | 5.8 | 2026-02-09 |
NixOS nixpkgs
|
CVE NVD | |
| CVE-2026-25639 |
Axios affected by Denial of Service via __proto__ Key in mergeConfig
|
HIGH | 7.5 | 2026-02-09 |
axios axios
|
CVE NVD | |
| CVE-2026-25528 |
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
|
MEDIUM | 5.8 | 2026-02-09 |
langchain-ai langsmith-sdk
|
CVE NVD | |
| CVE-2026-25498 |
Craft has a potential authenticated Remote Code Execution via malicious attached Behavior
|
HIGH | 8.6 | 2026-02-09 |
craftcms cms
craftcms cms
|
CVE NVD | |
| CVE-2026-25497 |
Craft has a GraphQL Asset Mutation Privilege Escalation
|
HIGH | 8.6 | 2026-02-09 |
craftcms cms
craftcms cms
|
CVE NVD | |
| CVE-2026-25496 |
Craft has a stored XSS in Number Prefix & Suffix Fields
|
MEDIUM | 4.8 | 2026-02-09 |
craftcms cms
craftcms cms
|
CVE NVD | |
| CVE-2026-25495 |
Craft has a SQL Injection in Element Indexes via criteria[orderBy]
|
HIGH | 8.7 | 2026-02-09 |
craftcms cms
craftcms cms
|
CVE NVD | |
| CVE-2026-25494 |
Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation
|
MEDIUM | 6.9 | 2026-02-09 |
craftcms cms
|
CVE NVD | |
| CVE-2026-25493 |
Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
|
MEDIUM | 6.9 | 2026-02-09 |
craftcms cms
craftcms cms
|
CVE NVD | |
| CVE-2026-25492 |
Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
|
MEDIUM | 5.3 | 2026-02-09 |
craftcms cms
craftcms cms
|
CVE NVD | |
| CVE-2026-2246 |
AprilRobotics apriltag apriltag.c apriltag_detector_detect memory corruption
|
MEDIUM | 4.8 | 2026-02-09 |
AprilRobotics apriltag
AprilRobotics apriltag
+4个
|
CVE NVD | |
| CVE-2026-25491 |
Craft has a Stored XSS in Entry Types Name
|
LOW | 1.9 | 2026-02-09 |
craftcms cms
|
CVE NVD | |
| CVE-2026-25057 |
Zip Slip in MarkUs config upload allowing RCE
|
CRITICAL | 9.1 | 2026-02-09 |
MarkUsProject Markus
|
CVE NVD |