Aggregator
火绒小问答--「个人版」感染型病毒与浏览器主页被劫持处理指南
3 months 1 week ago
火绒小问答--「个人版」感染型病毒/浏览器主页被劫持处理指南
火绒新增重要合作伙伴 精准赋能企业终端安全
3 months 1 week ago
火绒新增重要合作伙伴 精准赋能企业终端安全
CVE-2026-26704 | SourceCodester Pharmacy Point of Sale System 1.0 view_category.php sql injection
3 months 1 week ago
A vulnerability was found in SourceCodester Pharmacy Point of Sale System 1.0. It has been classified as critical. This impacts an unknown function of the file /pharmacy/view_category.php. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2026-26704. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-26705 | SourceCodester Pharmacy Point of Sale System 1.0 view_product.php sql injection
3 months 1 week ago
A vulnerability classified as critical has been found in SourceCodester Pharmacy Point of Sale System 1.0. The affected element is an unknown function of the file /pharmacy/view_product.php. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-26705. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-28357 | NocoDB up to 0.301.2 cross site scripting (EUVD-2026-9199)
3 months 1 week ago
A vulnerability has been found in NocoDB up to 0.301.2 and classified as problematic. The impacted element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-28357. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-28396 | NocoDB up to 0.301.2 Password Reset session expiration (EUVD-2026-9211)
3 months 1 week ago
A vulnerability was found in NocoDB up to 0.301.2. It has been rated as problematic. This affects an unknown function of the component Password Reset Handler. Performing a manipulation results in session expiration.
This vulnerability is identified as CVE-2026-28396. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-28361 | NocoDB up to 0.301.2 MCP Token Service authorization (EUVD-2026-9210)
3 months 1 week ago
A vulnerability identified as critical has been detected in NocoDB up to 0.301.2. Affected is an unknown function of the component MCP Token Service. The manipulation leads to authorization bypass.
This vulnerability is listed as CVE-2026-28361. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-28399 | NocoDB up to 0.301.2 unit sql injection (EUVD-2026-9214)
3 months 1 week ago
A vulnerability labeled as critical has been found in NocoDB up to 0.301.2. Affected by this vulnerability is an unknown functionality. The manipulation of the argument unit results in sql injection.
This vulnerability is cataloged as CVE-2026-28399. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-28397 | NocoDB up to 0.301.2 cross site scripting (EUVD-2026-9212)
3 months 1 week ago
A vulnerability described as problematic has been identified in NocoDB up to 0.301.2. This affects an unknown part. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-28397. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-28398 | NocoDB up to 0.301.2 cross site scripting (EUVD-2026-9213)
3 months 1 week ago
A vulnerability classified as problematic has been found in NocoDB up to 0.301.2. This vulnerability affects unknown code. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-28398. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-28401 | NocoDB up to 0.301.2 v-html HTML injection (EUVD-2026-9215)
3 months 1 week ago
A vulnerability, which was classified as problematic, was found in NocoDB up to 0.301.2. The affected element is an unknown function of the component v-html. The manipulation results in HTML injection.
This vulnerability is known as CVE-2026-28401. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-28358 | NocoDB up to 0.301.2 Password Forgot Endpoint response discrepancy (EUVD-2026-9207)
3 months 1 week ago
A vulnerability was found in NocoDB up to 0.301.2. It has been classified as problematic. The affected element is an unknown function of the component Password Forgot Endpoint. This manipulation causes observable response discrepancy.
The identification of this vulnerability is CVE-2026-28358. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-28359 | NocoDB up to 0.301.2 TipTap Editor cross site scripting (EUVD-2026-9208)
3 months 1 week ago
A vulnerability was found in NocoDB up to 0.301.2. It has been declared as problematic. The impacted element is an unknown function of the component TipTap Editor. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-28359. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-28360 | NocoDB up to 0.301.2 credentials storage (EUVD-2026-9209)
3 months 1 week ago
A vulnerability categorized as problematic has been discovered in NocoDB up to 0.301.2. This impacts an unknown function. Executing a manipulation can lead to unprotected storage of credentials.
This vulnerability is tracked as CVE-2026-28360. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-25828 | Antynea grub-btrfs up to 2026-01-31 resolve_device root os command injection
3 months 1 week ago
A vulnerability has been found in Antynea grub-btrfs up to 2026-01-31 and classified as critical. This affects the function resolve_device. Performing a manipulation of the argument root results in os command injection.
This vulnerability is identified as CVE-2026-25828. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com
CVE-2025-56320 | Enterprise Contract Management Portal 22.4.0 Chat Box cross site scripting (EUVD-2025-34913)
3 months 1 week ago
A vulnerability was found in Enterprise Contract Management Portal 22.4.0. It has been declared as problematic. The impacted element is an unknown function of the component Chat Box. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-56320. The attack can be executed remotely. There is not any exploit available.
vuldb.com
Confucius组织针对巴基斯坦部署AnonDoor后门的攻击活动分析
3 months 1 week ago
Confucius组织是一个具有长期针对南亚地区的APT组织,自2013年活跃至今,主要目的是窃取敏感信息。近期我们在日常威胁狩猎中观察到该组织持续发起新型攻击,采用多层“白加黑”利用技术,并结合Pyc功能模块内存加载恶意代码,用于隐蔽恶意行为。
利用大模型进行大规模去匿名化
3 months 1 week ago
根据海量数据训练并能快速检索相关信息的大模型大幅降低了网络开盒(或叫去匿名化)的成本。一个人可仅仅通过少数特征被个别界定,比如仅通过邮政编码、出生日期和性别,87% 的美国人口即可被个别界定。根据发表在预印本平台 arXiv 的一篇论文,大模型能用于大规模的去匿名化,能高精度的识别网络上的匿名用户。研究人员设计了一个攻击流程:提取身份特征,搜索候选匹配,通过推理验证匹配结果减少误判。传统的去匿名工作需要专业调查人员花费数小时或更长时间,大模型不仅花费时间更少,而且可以大幅扩大规模。利用大模型,以关联 Hacker News 匿名账号和 LinkedIn 实名账号为例,系统能在维持 99% 精度的情况下,将回索率从 0.1% 大幅提升至 45.1%。回索率(Recall)被用于衡量模型找回所有相关信息的能力。研究人员指出,保护网民匿名性的旧方法不再有效。
CVE-2026-2634 | Mozilla Firefox up to 147.3 on iOS Web Contents clickjacking (Nessus ID 300439 / WID-SEC-2026-0497)
3 months 1 week ago
A vulnerability was found in Mozilla Firefox up to 147.3 on iOS. It has been declared as problematic. This affects an unknown function of the component Web Contents Handler. Executing a manipulation can lead to clickjacking.
This vulnerability is tracked as CVE-2026-2634. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com