Aggregator
关于黑产团伙批量搭建高仿真钓鱼网站大规模传播银狐木马的风险提示
3 weeks 6 days ago
CVE-2026-44791
3 weeks 6 days ago
Currently trending CVE - Hype Score: 10
CVE-2026-44790
3 weeks 6 days ago
Currently trending CVE - Hype Score: 10
CVE-2026-45584
3 weeks 6 days ago
Currently trending CVE - Hype Score: 15 - Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
CVE-2026-31532
3 weeks 6 days ago
Currently trending CVE - Hype Score: 13 - In the Linux kernel, the following vulnerability has been resolved:
can: raw: fix ro->uniq use-after-free in raw_rcv()
raw_release() unregisters raw CAN receive filters via can_rx_unregister(),
but receiver deletion is deferred with call_rcu(). This leaves a window
where ...
CVE-2026-31694
3 weeks 6 days ago
Currently trending CVE - Hype Score: 13 - In the Linux kernel, the following vulnerability has been resolved:
fuse: reject oversized dirents in page cache
fuse_add_dirent_to_cache() computes a serialized dirent size from the
server-controlled namelen field and copies the dirent into a single
page-cache page. The ...
CVE-2026-45829
3 weeks 6 days ago
Currently trending CVE - Hype Score: 1 - A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in ...
CVE-2024-32002
3 weeks 6 days ago
Currently trending CVE - Hype Score: 1 - Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into ...
【安全更新】微软3月安全更新多个产品高危漏洞通告
3 weeks 6 days ago
阅读: 14通告编号:NS-2026-0005TAG:安全更新、Windows、Office、SQL Server、Azure漏洞危害:攻击者利
CVE-2026-47783 | memcached up to 1.6.41 sasl_server_userdb_checkpass timing discrepancy (EUVD-2026-31065 / Nessus ID 315754)
3 weeks 6 days ago
A vulnerability, which was classified as problematic, has been found in memcached up to 1.6.41. Affected by this issue is the function sasl_server_userdb_checkpass. Performing a manipulation results in observable timing discrepancy.
This vulnerability is reported as CVE-2026-47783. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-9101 | MongoDB Compass up to 1.49.5 prototype pollution (WID-SEC-2026-1617)
3 weeks 6 days ago
A vulnerability labeled as problematic has been found in MongoDB Compass. This vulnerability affects unknown code. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is handled as CVE-2026-9101. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-9087 | Keycloak on Red Hat authorization (WID-SEC-2026-1616)
3 weeks 6 days ago
A vulnerability marked as problematic has been reported in Keycloak on Red Hat. This issue affects some unknown processing. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-9087. Local access is required to approach this attack. No exploit exists.
vuldb.com
CVE-2026-0393 | CODESYS Visualization 4.2.0.0/4.8.0.0 Concurrent Login insufficiently protected credentials (vde-2026-052 / WID-SEC-2026-1619)
3 weeks 6 days ago
A vulnerability was found in CODESYS Visualization 4.2.0.0/4.8.0.0. It has been rated as problematic. This affects an unknown part of the component Concurrent Login. The manipulation leads to insufficiently protected credentials.
This vulnerability is referenced as CVE-2026-0393. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-20239 | Splunk Enterprise/Cloud Platform log file (SVD-2026-0503 / Nessus ID 315750)
3 weeks 6 days ago
A vulnerability, which was classified as problematic, has been found in Splunk Enterprise and Cloud Platform. This affects an unknown function. Performing a manipulation results in sensitive information in log files.
This vulnerability is identified as CVE-2026-20239. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
【安全事件】Apifox桌面客户端遭供应链投毒分析
3 weeks 6 days ago
阅读: 15通告编号:NS-2026-0007TAG:Apifox、供应链攻击、CDN投毒危害程度:高版本:1.0
Maptoposter Online:把你爱的城市画成艺术海报
3 weeks 6 days ago
Matrix 首页推荐Matrix 是少数派的写作社区,我们主张分享真实的产品体验,有实用价值的经验与思考。我们会不定期挑选 Matrix 最优质的文章,展示来自用户的最真实的体验和观点。文章代表作者
CVE-2026-43434 | Linux Kernel up to 6.18.18/6.19.8 vma_lookup privilege escalation (Nessus ID 315706)
3 weeks 6 days ago
A vulnerability was found in Linux Kernel up to 6.18.18/6.19.8. It has been declared as problematic. This issue affects the function vma_lookup. The manipulation results in privilege escalation.
This vulnerability is identified as CVE-2026-43434. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-43333 | Linux Kernel up to 6.19.11 check_mem_access null pointer dereference (Nessus ID 315705)
3 weeks 6 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.11. Impacted is the function check_mem_access. This manipulation causes null pointer dereference.
This vulnerability is registered as CVE-2026-43333. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-43358 | Linux Kernel up to 6.18.18/6.19.8 try_release_subpage_extent_buffer infinite loop (Nessus ID 315704)
3 weeks 6 days ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.18/6.19.8. This affects the function try_release_subpage_extent_buffer. Such manipulation leads to infinite loop.
This vulnerability is documented as CVE-2026-43358. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com