Aggregator
【安全圈】执法机构捣毁 'AudiA6' 勒索软件加密货币洗钱服务
1 week ago
【安全圈】一名乌克兰公民承认参与了Conti勒索软件行动
1 week ago
【安全圈】超过 400 个 Arch Linux 软件包被攻破,用于推送 rootkit 和信息窃取程序
1 week ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
【安全圈】一名乌克兰公民承认参与了Conti勒索软件行动
1 week ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
【安全圈】执法机构捣毁 'AudiA6' 勒索软件加密货币洗钱服务
1 week ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2025-7010 | Gen Digital Avast Antivirus up to 25021208 on Windows PDF File recursion (ID 25021208 / EUVD-2025-210129)
1 week ago
A vulnerability was found in Gen Digital Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One and Avast Business Antivirus up to 25021208 on Windows and classified as problematic. Impacted is an unknown function of the component PDF File Handler. Executing a manipulation can lead to uncontrolled recursion.
This vulnerability appears as CVE-2025-7010. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-7011 | Gen Digital Avast Antivirus on Windows Installation out-of-bounds (ID 25021208 / EUVD-2025-210130)
1 week ago
A vulnerability identified as critical has been detected in Gen Digital Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One and Avast Business Antivirus on Windows. This affects an unknown function of the component Installation Handler. Performing a manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2025-7011. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-7019 | Gen Digital Avast Antivirus up to 25020100 on Windows XML File stack-based overflow (ID 25020100 / EUVD-2025-210133)
1 week ago
A vulnerability was found in Gen Digital Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One and Avast Business Antivirus up to 25020100 on Windows. It has been classified as critical. The affected element is an unknown function of the component XML File Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-7019. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-11442 | Allegra 8.1.10.5 exportReport path traversal (ZDI-26-357 / EUVD-2026-36633)
1 week ago
A vulnerability marked as critical has been reported in Allegra 8.1.10.5. This impacts the function exportReport. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-11442. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-11443 | Allegra 8.1.6.22 downloadAttachment cross site scripting (ZDI-26-358 / EUVD-2026-36634)
1 week ago
A vulnerability was found in Allegra 8.1.6.22 and classified as problematic. The affected element is the function downloadAttachment. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-11443. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-12089 | aurelienlws LWS Optimize Plugin up to 3.3.19 on WordPress combine_current_css path traversal (EUVD-2026-36635)
1 week ago
A vulnerability classified as critical was found in aurelienlws LWS Optimize Plugin up to 3.3.19 on WordPress. Affected by this issue is the function combine_current_css. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-12089. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-9848 | emarket-design Customer Support Ticket System & Helpdesk Plugin up to 6.0.4 on WordPress Query Parameter wp_ticket_com_posts_request sql injection (EUVD-2026-36636)
1 week ago
A vulnerability, which was classified as critical, has been found in emarket-design Customer Support Ticket System & Helpdesk Plugin up to 6.0.4 on WordPress. This affects the function wp_ticket_com_posts_request of the component Query Parameter Handler. This manipulation causes sql injection.
This vulnerability is registered as CVE-2026-9848. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
Он совсем кроха, но готов завоевать Луну: как мини робот-трансформер помогает исследовать космос
1 week ago
Зачем нужны огромные луноходы, когда есть SORA-Q размером с мяч?
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
1 week ago
Anthropic has suspended access to its two most capable AI models, Fable 5 and Mythos 5, for
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
1 week ago
The US government has ordered Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5, forcing the company to suspend both models worldwide. Anthropic is complying but disputes the basis, calling the cited jailbreak narrow and the capability widely available elsewhere. [...]
Ax Sharma
银狐黑产组织最新攻击趋势深度分析报告
1 week ago
银狐黑产组织最新攻击趋势深度分析报告
【叠加618优惠更划算】冰与火的战歌:Windows内核攻防实战
1 week ago
HumanBug15 年实战经验,手把手教落地
AI 辅助分析|CyberGame 高分 Web 题:缓存投毒攻击链路拆解
1 week ago
看雪论坛作者ID:不歪
【叠加618优惠更划算】冰与火的战歌:Windows内核攻防实战
1 week ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证