Aggregator
Self directed learning
1 month ago
抢先加入AI时代顶尖安全团队!阿里云2027届实习生招聘来了!
1 month ago
欢迎投递简历!
缓存投毒导致的 XSS 接管账号
1 month ago
缓存投毒导致的 XSS 接管账号正文通过缓存投毒导致的 XSS 接管账号。
JVN: Musetheque V4 情報公開 for IPKNOWLEDGEにおける複数の脆弱性
1 month ago
富士通Japan株式会社が提供するMusetheque V4 情報公開 for IPKNOWLEDGEには、複数の脆弱性が存在します。
Linux的最新漏洞允许非特权用户读取Root拥有的文件
1 month ago
继Dirty Frag、Fragnesia以及其他最近几天暴露出来的Linux内核漏洞之后,现在最新的漏洞是ssh-keysign-pwn。通过 ssh-keysign-pwn,非特权用户能够读取Ro
CVE-2026-44541 | Ethyca Fides fides.js fides_description cross site scripting
1 month ago
A vulnerability classified as problematic has been found in Ethyca Fides. Affected by this vulnerability is an unknown functionality of the file fides.js. This manipulation of the argument fides_description causes cross site scripting.
This vulnerability is handled as CVE-2026-44541. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-0432 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics AMD Chipset Driver default permission (EUVD-2026-30497)
1 month ago
A vulnerability described as critical has been identified in AMD Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7020 Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 3000 Desktop Processors, Ryzen Threadripper PRO 3000 WX-Series Processors, Ryzen 7030 Mobile Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen 9000HX Processors, Ryzen AI 300 Processors, Athlon 3000 Desktop Processors with Radeon Graphics, Ryzen Threadripper PRO 5000 WX-Series Processors, Ryzen Threadripper 7000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 4000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen AI Max 300 Processors, Ryzen AI 400 Processors, Ryzen Embedded R1000 Processors, Ryzen Embedded R2000 Processors, Ryzen Embedded V1000 Processors, Ryzen Embedded V2000 Processors, EPYC Embedded 8004 Processors, Ryzen Embedded 8000 Processors, Ryzen Embedded 7000 Processors, EPYC Embedded 9005 Processors, Ryzen Embedded 9000 Processors, EPYC 9004 Processors, EPYC 7003 Processors, EPYC 7002 Processors, EPYC 7001 Processors, EPYC 4004 Processors, EPYC 9005 Processors, Instinct MI300A Processors, EPYC 9V64H Processor, EPYC 8004 Processors and EPYC 4005 Processors. Affected is an unknown function of the component AMD Chipset Driver. The manipulation results in incorrect default permissions.
This vulnerability is known as CVE-2026-0432. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2026-8612 | OALDERS WWW::Mechanize::Cached up to 1.x on Perl HTTP Response /tmp/FileCache get permission assignment
1 month ago
A vulnerability marked as problematic has been reported in OALDERS WWW::Mechanize::Cached up to 1.x on Perl. This impacts the function get of the file /tmp/FileCache of the component HTTP Response Handler. The manipulation leads to incorrect permission assignment.
This vulnerability is traded as CVE-2026-8612. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-52540 | AMD Ryzen 7035 Processors with Radeon Graphics Management Frame out-of-bounds write (EUVD-2025-209864)
1 month ago
A vulnerability labeled as critical has been found in AMD Ryzen 7035 Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics and Ryzen Embedded 8000 Processors. This affects an unknown function of the component Management Frame Handler. Executing a manipulation can lead to out-of-bounds write.
This vulnerability appears as CVE-2025-52540. The attack requires local access. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-48521 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics use after free (EUVD-2025-209863)
1 month ago
A vulnerability identified as critical has been detected in AMD Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7020 Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 3000 Desktop Processors, Ryzen Threadripper PRO 3000WX Processors, Ryzen 7030 Mobile Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen AI 300 Processors, Athlon 3000 Desktop Processors with Radeon Graphics, Ryzen Threadripper PRO 5000 WX-Series Processors, Ryzen Threadripper 7000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 4000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 3000 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen Embedded V1000 Processors, Ryzen Embedded R1000 Processors, Ryzen Embedded R2000 Processors, Ryzen Embedded V2000 Processors, EPYC Embedded 4004 Processors, EPYC Embedded 8004 Processors, EPYC Embedded 4005 Processors, Ryzen Embedded 8000 Processors, Ryzen Embedded 7000 Processors, EPYC Embedded 9000 Processors, Ryzen Embedded 9000 Processors, EPYC 4004 Processors and EPYC 4005 Processors. The impacted element is an unknown function. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2025-48521. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2025-48519 | AMD Ryzen 7035 Processors with Radeon Graphics Management Frame out-of-bounds write (EUVD-2025-209866)
1 month ago
A vulnerability categorized as critical has been discovered in AMD Ryzen 7035 Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics and Ryzen Embedded 8000 Processors. The affected element is an unknown function of the component Management Frame Handler. Such manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2025-48519. The attack needs to be performed locally. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-0045 | AMD Athlon 3000 Mobile Processors with Radeon Graphics buffer overflow (EUVD-2025-209862)
1 month ago
A vulnerability was found in AMD Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics Ryzen 7035 Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7020 Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen Z1 Processors, Ryzen 5000 Desktop Processor with Radeon Graphics, Ryzen Threadripper PRO 3000 WX-Series Processors, Ryzen 7030 Mobile Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 9000HX Processors, Ryzen AI Max 300 Processors, Ryzen 9000 Desktop Processors, Ryzen Threadripper PRO 9000 WX-Series Processors, Ryzen Threadripper 9000 Processors, Ryzen Threadripper 7000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen Z2 Processors Extreme, Ryzen AI 300 Processors, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 3000 Desktop Processors, Ryzen 2000 Mobile Processors, Ryzen 5000 Desktop Processors, Ryzen 7000 Desktop Processors, Ryzen 8000 Desktop Processors, Ryzen Embedded R1000 Processors, Ryzen Embedded R2000 Processors, Ryzen Embedded V1000 Processors, Ryzen Embedded V2000 Processors, Ryzen Embedded 8000 Processors, Ryzen Embedded 7000 Processors, Ryzen Embedded 9000 Processors, EPYC Embedded 8004 Processors, EPYC Embedded 9005 Processors, EPYC Embedded 4005 Processors, EPYC Embedded 4004 Processors, EPYC 4004 Processors and EPYC 4005 Processors. It has been rated as critical. Impacted is an unknown function. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2025-0045. The attack needs to be launched locally. No exploit is available.
vuldb.com
CVE-2025-48520 | AMD Ryzen 7035 Processors with Radeon Graphics prior 7.06.02.123 Management Frame out-of-bounds (EUVD-2025-209865)
1 month ago
A vulnerability was found in AMD Ryzen 7035 Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics and Ryzen Embedded 8000 Processors. It has been declared as problematic. This issue affects some unknown processing of the component Management Frame Handler. The manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2025-48520. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-45375 | SiYuan up to 3.6.5 Setting plugin.json cross site scripting (GHSA-27qc-m5gf-jv5r)
1 month ago
A vulnerability was found in SiYuan up to 3.6.5. It has been classified as problematic. This vulnerability affects unknown code of the file plugin.json of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-45375. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-45371 | SiYuan up to 3.6.x /api/graph/getGraph model.Conf.Save improper authorization (GHSA-gmmv-4cc5-wr9r)
1 month ago
A vulnerability was found in SiYuan up to 3.6.x and classified as critical. This affects the function model.Conf.Save of the file /api/graph/getGraph. Executing a manipulation can lead to improper authorization.
This vulnerability is tracked as CVE-2026-45371. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-0438 | AMD Ryzen 7040 Mobile Processors with Radeon Graphics data resource access without connection pooling
1 month ago
A vulnerability has been found in AMD Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 9000HX Processors, Ryzen AI 300 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen AI Max 300 Processors, Ryzen Z1 Processors, Ryzen Z2 Processors Extreme, Ryzen Z2 Processors, Ryzen Threadripper 7000 Processors, Not public, Ryzen Threadripper 9000 Processors, Ryzen Threadripper PRO 9000 WX-Series Processors, Ryzen Embedded 9000 Processors, Ryzen Embedded 8000 Processors, Ryzen Embedded 7000 Processors, EPYC 4004 Processors and EPYC 4005 Processors and classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in data resource access without use of connection pooling.
This vulnerability is identified as CVE-2026-0438. The attack may be carried out on the physical device. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking
1 month ago
BAADTokenBroker BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys. It can: Request
The post BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking appeared first on Penetration Testing Tools.
ddos
CVE-2024-36345 | AMD EPYC 4004 System Management Mode improper access control for volatile memory containing boot code
1 month ago
A vulnerability, which was classified as problematic, was found in AMD EPYC 4004, EPYC 4005, Ryzen 6000 Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 9000HX Mobile Processors, Ryzen AI MAX, Ryzen AI 300 Processors, Ryzen Threadripper 7000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen Embedded 8000 Processors, Ryzen Embedded V3000 Processors, Ryzen Embedded 7000 Processors and Ryzen Embedded 9000 Processors. Affected by this vulnerability is an unknown functionality of the component System Management Mode. Such manipulation leads to improper access control for volatile memory containing boot code.
This vulnerability is referenced as CVE-2024-36345. The attack can only be performed from a local environment. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-8621 | openclaw crabbox up to 0.11.x improper authentication
1 month ago
A vulnerability, which was classified as critical, has been found in openclaw crabbox up to 0.11.x. Affected is an unknown function. This manipulation causes improper authentication.
The identification of this vulnerability is CVE-2026-8621. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com