Aggregator
CVE-2022-49357 | Linux Kernel up to 5.4.197/5.10.120/5.15.45/5.17.13/5.18.2 EFI Runtime Service quirks.c efi_crash_gracefully_on_page_fault denial of service (Nessus ID 249320)
1 month ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.4.197/5.10.120/5.15.45/5.17.13/5.18.2. This issue affects the function efi_crash_gracefully_on_page_fault of the file arch/x86/platform/efi/quirks.c of the component EFI Runtime Service. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2022-49357. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
0,00006 секунды — и решётка готова. Китай показал абсолютную точность сборки кубитов
1 month ago
Как выстроить армию из 2024 атомов с точностью 99,9%?
CVE-2022-49799 | Linux Kernel up to 5.10.155/5.15.79/6.0.9 tracing register_synth_event memory corruption (Nessus ID 249320)
1 month ago
A vulnerability was found in Linux Kernel up to 5.10.155/5.15.79/6.0.9 and classified as critical. This issue affects the function register_synth_event of the component tracing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2022-49799. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49880 | Linux Kernel up to 6.0.7 ext4 ext4_da_release_space allocation of resources (Nessus ID 249320 / WID-SEC-2025-0922)
1 month ago
A vulnerability was found in Linux Kernel up to 6.0.7. It has been rated as problematic. Affected by this issue is the function ext4_da_release_space of the component ext4. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2022-49880. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49823 | Linux Kernel up to 5.10.155/5.15.79/6.0.9 ata ata_tdev_add null pointer dereference (Nessus ID 249320)
1 month ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.10.155/5.15.79/6.0.9. This issue affects the function ata_tdev_add of the component ata. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2022-49823. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-53143 | Linux Kernel up to 6.2.6 ext4 fsmap_head off-by-one (Nessus ID 249320 / WID-SEC-2025-0932)
1 month ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.2.6. This affects the function fsmap_head of the component ext4. The manipulation leads to off-by-one.
This vulnerability is uniquely identified as CVE-2023-53143. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49839 | Linux Kernel up to 5.10.156/5.15.79/6.0.9 scsi sas_phy_add null pointer dereference (Nessus ID 249320 / WID-SEC-2025-0922)
1 month ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.156/5.15.79/6.0.9. This affects the function sas_phy_add of the component scsi. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2022-49839. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49901 | Linux Kernel up to 6.0.7 null_blk.ko allocation of resources (Nessus ID 249320 / WID-SEC-2025-0922)
1 month ago
A vulnerability was found in Linux Kernel up to 6.0.7 and classified as problematic. Affected by this issue is the function null_blk.ko. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2022-49901. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49885 | Linux Kernel up to 5.10.153/5.15.77/6.0.7 ACPI ghes_estatus_pool_init integer overflow (EUVD-2025-12883 / Nessus ID 249320)
1 month ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.10.153/5.15.77/6.0.7. Affected is the function ghes_estatus_pool_init of the component ACPI. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2022-49885. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-49890 | Linux Kernel up to 6.0.7 capabilities vfs_getxattr_alloc memory leak (Nessus ID 249320)
1 month ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.0.7. Affected is the function vfs_getxattr_alloc of the component capabilities. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2022-49890. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Obot MCP Gateway: Open-source platform to securely manage the adoption of MCP servers
1 month ago
Obot MCP Gateway is a free, open-source gateway that enables IT organizations to securely manage and scale adoption of Model Context Protocol (MCP) servers. MCPs are becoming the standard for how AI agents interface with real-world systems. Without a control layer, organizations risk shadow infrastructure, data exposure, and fragmented adoption. “MCP servers are the connective tissue between AI and the enterprise,” said Sheng Liang, CEO of Acorn Labs. “But without proper controls, they create more … More →
The post Obot MCP Gateway: Open-source platform to securely manage the adoption of MCP servers appeared first on Help Net Security.
Help Net Security
广岛和长崎核爆幸存者死于辐射致癌的比例比预期的低
1 month ago
根据发表在《Journal of Biological Physics and Chemistry》上的一项研究,80 年前广岛和长崎核爆辐射的初期幸存者中,不到 1% 的人已经死于或将死于癌症。据估计到 1945 年底,广岛约有 14 万人、长崎约有 7.4 万人死于爆炸冲击波、高温和急性放射性中毒。高剂量辐射暴露会增加罹患癌症的风险。布里斯托尔(Bristol)大学的风险管理学教授 Philip Thomas 估计 32.4 万名幸存者中只有约 3100 人已经或将会死于辐射诱发的白血病或实体瘤。根据日本厚生劳动省的数据,目前仍有 99130 名原爆幸存者,其中 4738 人被认为有资格获得因辐射引起的疾病的特殊医疗补助。伦敦癌症研究所癌症流行病学教授 Amy Berrington 对这一研究表示,电离辐射风险是复杂的问题,有些人会夸大,还有人则试图轻描淡写,Thomas 的研究与此前的研究总体上是一致的。她表示需要谨慎推广这一结论,而好消息是辐射没有跨代健康影响。
【通知】第三届全国大学生开源情报数据采集与分析大赛开始报名啦!提供免费培训
1 month ago
【情报】湾湾是如何挖掘大陆军事情报的?
1 month ago
因利用公开信息挖掘大陆军事信息的台湾温约瑟(Joseph Wen)最近又出版了新书,讲述其利用开源情报方法挖掘大陆军方信息的过程。从该书不仅可以了解开源情报的挖掘方法,也可知道哪些地方有相关信息泄露。
CVE-2025-7688 | Add User Meta Plugin up to 1.0.1 on WordPress Setting cross-site request forgery (EUVD-2025-25003)
1 month ago
A vulnerability labeled as problematic has been found in Add User Meta Plugin up to 1.0.1 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-7688. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-5844 | Radius Blocks Plugin up to 2.2.1 on WordPress subHeadingTagName cross site scripting
1 month ago
A vulnerability identified as problematic has been detected in Radius Blocks Plugin up to 2.2.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument subHeadingTagName leads to cross site scripting.
This vulnerability is handled as CVE-2025-5844. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-8720 | Plugin README Parser Plugin up to 1.3.15 on WordPress target cross site scripting
1 month ago
A vulnerability categorized as problematic has been discovered in Plugin README Parser Plugin up to 1.3.15 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation of the argument target leads to cross site scripting.
This vulnerability is known as CVE-2025-8720. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-8080 | Alobaidi Captcha Plugin up to 1.0.3 on WordPress Setting cross site scripting
1 month ago
A vulnerability was found in Alobaidi Captcha Plugin up to 1.0.3 on WordPress. It has been rated as problematic. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-8080. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-8604 | WP Table Builder Plugin up to 2.0.12 on WordPress Shortcode cross site scripting (EUVD-2025-24988)
1 month ago
A vulnerability was found in WP Table Builder Plugin up to 2.0.12 on WordPress. It has been declared as problematic. This issue affects some unknown processing of the component Shortcode Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-8604. The attack may be initiated remotely. There is no exploit available.
vuldb.com