最近六个月的全部 CVE,每天更新。
直接来自 National Vulnerability Database 的已公开漏洞,附带严重程度、CWE 类别和受影响产品。可搜索、可筛选,今天新增的也能马上看到。
- 过去 24 小时 198 条
- 过去 7 天 2,191 条
- 过去六个月 58,432 条
来源:NVD(National Vulnerability Database) · 更新于 2026年9月24日
显示 4 条中的 4 条
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CWE-141microsoft edge_chromiumInsufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP param
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. Th
CWE-141cisco unified_computing_systemImproper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.Cookies.encode/2 function in lib/plug/conn/cookies.ex builds the Set-Cookie response heade