最近六个月的全部 CVE,每天更新。
直接来自 National Vulnerability Database 的已公开漏洞,附带严重程度、CWE 类别和受影响产品。可搜索、可筛选,今天新增的也能马上看到。
- 过去 24 小时 294 条
- 过去 7 天 2,895 条
- 过去六个月 58,248 条
来源:NVD(National Vulnerability Database) · 更新于 2026年9月23日
显示 2 条中的 2 条
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CWE-159tornadoweb tornadoSuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handl