快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 351381
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2026-23960 |
Argo Workflows affected by stored XSS in the artifact directory listing
|
HIGH | 7.3 | 2026-01-21 |
argoproj argo-workflows
argoproj argo-workflows
|
CVE NVD | |
| CVE-2026-23518 |
Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment
|
CRITICAL | 9.3 | 2026-01-21 |
fleetdm fleet
fleetdm fleet
+3个
|
CVE NVD | |
| CVE-2026-23517 |
Fleet has an Access Control vulnerability in debug/pprof endpoints
|
MEDIUM | 6.3 | 2026-01-21 |
fleetdm fleet
fleetdm fleet
+3个
|
CVE NVD | |
| CVE-2026-23526 |
CVAT vulnerable to privilege escalation of users with staff status
|
HIGH | 8.5 | 2026-01-21 |
cvat-ai cvat
|
CVE NVD | |
| CVE-2026-23516 |
CVAT vulnerable to XSS via skeleton SVG images
|
HIGH | 8.6 | 2026-01-21 |
cvat-ai cvat
|
CVE NVD | |
| CVE-2026-23499 |
Saleor vulnerable to stored XSS via Unrestricted File Upload
|
HIGH | 8.5 | 2026-01-21 |
saleor saleor
saleor saleor
+1个
|
CVE NVD | |
| CVE-2026-22849 |
Saleor lacks proper HTML sanitization in rich text fields
|
HIGH | 7.2 | 2026-01-21 |
saleor saleor
saleor saleor
+1个
|
CVE NVD | |
| CVE-2026-22822 |
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
|
CRITICAL | 9.3 | 2026-01-21 |
external-secrets external-secrets
|
CVE NVD | |
| CVE-2026-22808 |
Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability
|
MEDIUM | 5.5 | 2026-01-21 |
fleetdm fleet
fleetdm fleet
+2个
|
CVE NVD | |
| CVE-2026-22807 |
vLLM affected by RCE via auto_map dynamic module loading during model initialization
|
HIGH | 8.8 | 2026-01-21 |
vllm-project vllm
|
CVE NVD | |
| CVE-2026-22793 |
5ire vulnerable to Remote Code Execution (RCE) via ECharts
|
CRITICAL | 9.7 | 2026-01-21 |
nanbingxyz 5ire
|
CVE NVD | |
| CVE-2026-22792 |
5ire vulnerable to Remote Code Execution (RCE)
|
CRITICAL | 9.7 | 2026-01-21 |
nanbingxyz 5ire
|
CVE NVD | |
| CVE-2026-22598 |
ManageIQ vulnerable to DoS Attack when creating TimeProfiles
|
HIGH | 7.1 | 2026-01-21 |
ManageIQ manageiq
|
CVE NVD | |
| CVE-2026-21852 |
Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation
|
MEDIUM | 5.3 | 2026-01-21 |
anthropics claude-code
|
CVE NVD | |
| CVE-2025-69285 |
SQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerability
|
HIGH | 7.7 | 2026-01-21 |
dataease SQLBot
|
CVE NVD | |
| CVE-2025-69209 |
ArduinoCore-avr has Stack-Based Buffer Overflow in WString Float/Double Constructors
|
MEDIUM | 6.9 | 2026-01-21 |
arduino ArduinoCore-avr
|
CVE NVD | |
| CVE-2025-68141 |
EVerest vulnerable to null pointer dereference during DC_ChargeLoopRes document deserialization
|
HIGH | 7.4 | 2026-01-21 |
EVerest everest-core
|
CVE NVD | |
| CVE-2025-68140 |
EVerest allows null session ID to bypass session ID verification
|
MEDIUM | 4.3 | 2026-01-21 |
EVerest everest-core
|
CVE NVD | |
| CVE-2025-68139 |
In EVerest, by default, the EV is responsible for closing the connection if the module encounters an error during request processing
|
MEDIUM | 4.3 | 2026-01-21 |
EVerest everest-core
|
CVE NVD | |
| CVE-2025-12781 |
base64.b64decode() always accepts "+/" characters, despite setting altchars
|
MEDIUM | 6.3 | 2026-01-21 |
Python Software Foundation CPython
|
CVE NVD |