Aggregator
CVE-2016-9081 | Joomla CMS up to 3.6.3 credentials management (EDB-40637 / Nessus ID 94355)
CVE-2016-9401 | GNU Bash popd use after free (RHSA-2017:1931 / Nessus ID 96233)
CVE-2026-44423 | shellhub-io shellhub up to 0.24.1 /api/sessions/ authorization (GHSA-9w9c-9w8m-w89q / EUVD-2026-30187)
CVE-2026-39428 | Cubecart up to 6.5.x cross site scripting (GHSA-gvxc-5v7r-272m / EUVD-2026-30157)
CVE-2026-45054 | CubeCart up to 6.6.x Admin Password admin.php?_g=orders&node=transactions sqlSafe sort sql injection (GHSA-rm2f-rpcq-6w9f / EUVD-2026-30171)
CVE-2026-45055 | CubeCart up to 6.7.1 Request Header /index.php?_a=recover User::passwordRequest password recovery (GHSA-7pvc-gxc4-chmc / EUVD-2026-30172)
CVE-2026-43967 | absinthe-graphql absinthe up to 1.10.1 algorithmic complexity (GHSA-9mhv-8h52-q7q2 / EUVD-2026-28800)
CVE-2026-8178 | Amazon Redshift JDBC Driver up to 2.2.1 externally-controlled input to select classes or code (GHSA-wmmv-vvg5-993q / EUVD-2026-28814)
为什么部分人特别招蚊子?
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)
Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Like Dirty Frag, it affects the same Linux module (xfrm-ESP). In fact, according to Dirty Frag discoverer Hyunwoo Kim, Fragnesia was “accidentally activated” by the patch fixing one of the original Dirty Frag vulnerabilities (i.e., CVE-2026-43284). CVE-2026-46300 explained Fragnesia was … More →
The post Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) appeared first on Help Net Security.
CVE-2014-0216 | Moodle up to 2.4.6 blocks/html/lib.php block_html_pluginfile access control (EUVD-2022-3226 / Nessus ID 74237)
CVE-2022-27773 | Ivanti EPM privileges management (EUVD-2022-32269)
CVE-2022-27647 | Netgear R6700v3 1.0.4.120_10.0.91 libreadycloud.so name/email os command injection (ZDI-22-524 / EUVD-2022-32148)
CVE-2022-27648 | KOYO Screen Creator 0.1.1.1 SCA2 File Parser stack-based overflow (ZDI-22-543 / EUVD-2022-32149)
CVE-2022-27646 | Netgear R6700v3 1.0.4.120_10.0.91 circled circleinfo.txt stack-based overflow (ZDI-22-523 / EUVD-2022-32147)
Голосовые помощники почти научились врать убедительно. Но одна вещь их всё ещё выдаёт
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
The ransomware group Nitrogen claimed responsibility for the attack and said it stole 8 terabytes of data spanning more than 11 million files belonging to the company’s top customers.
The post Major tech manufacturer Foxconn confirms cyberattack hit North American factories appeared first on CyberScoop.