A vulnerability was found in hs-web hsweb-framework up to 5.0.1. It has been rated as critical. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename leads to path traversal.
This vulnerability is traded as CVE-2026-11470. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is suggested to install a patch to address this issue.
A vulnerability categorized as critical has been discovered in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection.
This vulnerability is known as CVE-2026-11471. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in Google Chrome on Windows. It has been declared as critical. This impacts an unknown function of the component Aura. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-11631. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. [...]
The researcher Chaotic Eclipse released a PoC for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems. Security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, has published a new proof-of-concept exploit for a RoguePlanet Microsoft Defender zero-day. The flaw relies on a race condition that can provide attackers with […]