Aggregator
美对Anthropic出口管制 加拿大总理:过度依赖少数模型存在风险
1 day 8 hours ago
美对Anthropic出口管制 加拿大总理:过度依赖少数模型存在风险加拿大总理卡尼表示,美国实施出口禁令禁止所有外国用户访问Anthropic最新人工智能模型,这凸显了仅依赖少数几个强大AI工具的风险
2026,红队钓鱼的邪修手法
1 day 8 hours ago
主打一手意想不到
Looking for advice on getting into AI/LLM security and red teaming
1 day 8 hours ago
Java Attach API内存注入
1 day 8 hours ago
通过 Java Attach API的底层Unix Domain Socket通信协议,结合Linux内核memfd_create系统调用实现纯内存态Agent注入。
苹果或自研 Claw 代理机器人;Meta 内部爆发「AI 叛乱」;北航教授:中国无需复制 SpaceX
1 day 8 hours ago
外媒曝蚂蚁集团正秘密测试 AI 版支付宝;微软 CEO 纳德拉:光烧 Token 撑不起 AI 未来;余承东:我只能第一!彻底弃安卓 华为突破封锁麒麟回归
苹果或自研 Claw 代理机器人;Meta 内部爆发「AI 叛乱」;北航教授:中国无需复制 SpaceX
1 day 8 hours ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2026-46517 | InternLM LMDeploy dynamically-determined object attributes (EUVD-2026-35874)
1 day 9 hours ago
A vulnerability described as problematic has been identified in InternLM LMDeploy. Affected by this issue is some unknown functionality. Executing a manipulation can lead to dynamically-determined object attributes.
This vulnerability is handled as CVE-2026-46517. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-45329 | espressif esp-idf 5.5.4/6.0 RISC-V Machine Mode esp_secure_services.c pointer information disclosure (GHSA-w82j-7q63-7pqm)
1 day 9 hours ago
A vulnerability labeled as problematic has been found in espressif esp-idf 5.5.4/6.0. This impacts an unknown function of the file esp_secure_services.c of the component RISC-V Machine Mode. Such manipulation of the argument pointer leads to information disclosure.
This vulnerability is documented as CVE-2026-45329. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45328 | espressif esp-idf 5.5.4/6.0 esp_secure_services.c input validation (GHSA-mmgp-73p4-92xp)
1 day 9 hours ago
A vulnerability marked as problematic has been reported in espressif esp-idf 5.5.4/6.0. Affected is an unknown function of the file esp_secure_services.c. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2026-45328. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-59382 | QNAP QTS/QuTS hero/QuTScloud external control of assumed-immutable web parameter (qsa-26-10)
1 day 9 hours ago
A vulnerability was found in QNAP QTS, QuTS hero and QuTScloud and classified as problematic. The affected element is an unknown function. Executing a manipulation can lead to external control of assumed-immutable web parameter.
The identification of this vulnerability is CVE-2025-59382. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-66276 | QNAP QTS/QuTS hero 5.2.7.3256 Remote Code Execution (qsa-25-56)
1 day 9 hours ago
A vulnerability was found in QNAP QTS and QuTS hero 5.2.7.3256. It has been classified as critical. The impacted element is an unknown function. The manipulation leads to Remote Code Execution.
This vulnerability is referenced as CVE-2025-66276. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-24717 | QNAP QTS/QuTS hero path traversal (qsa-26-34)
1 day 9 hours ago
A vulnerability has been found in QNAP QTS and QuTS hero and classified as critical. This vulnerability affects unknown code. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-24717. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-22899 | QNAP File Station 5 5.5.6.5208 User Account null pointer dereference (qsa-26-19 / EUVD-2026-35973)
1 day 9 hours ago
A vulnerability categorized as problematic has been discovered in QNAP File Station 5 5.5.6.5208. This affects an unknown function of the component User Account Handler. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-22899. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-62851 | QNAP License Center up to 1.9.55 path traversal (qsa-26-28)
1 day 9 hours ago
A vulnerability was found in QNAP License Center up to 1.9.55. It has been classified as critical. This affects an unknown function. This manipulation causes path traversal.
This vulnerability is handled as CVE-2025-62851. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41003 | Vmware Spring Security up to 7.0.5 RelyingPartyRegistration cross site scripting (CNNVD-202606-2875)
1 day 9 hours ago
A vulnerability was found in Vmware Spring Security up to 7.0.5. It has been classified as problematic. This issue affects some unknown processing of the component RelyingPartyRegistration. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-41003. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41694 | Vmware Spring Security up to 7.0.5 SAML Response signature verification (CNNVD-202606-2873)
1 day 9 hours ago
A vulnerability classified as problematic was found in Vmware Spring Security up to 7.0.5. Affected is an unknown function of the component SAML Response Handler. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is handled as CVE-2026-41694. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-46518 | OpenEMR up to 8.0.0 PUT API multiprintcss_header cross site scripting (GHSA-4gh4-q39r-45wf / EUVD-2026-35869)
1 day 9 hours ago
A vulnerability was found in OpenEMR. It has been rated as problematic. Affected is the function multiprintcss_header of the component PUT API. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-46518. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41401 | libyang up to 5.4.2 YANG XML Document lyd_parser_set_data_flags use after free (Nessus ID 321038)
1 day 9 hours ago
A vulnerability, which was classified as critical, has been found in libyang up to 5.4.2. This affects the function lyd_parser_set_data_flags of the component YANG XML Document Handler. This manipulation causes use after free.
This vulnerability appears as CVE-2026-41401. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-42579 | Netty up to 4.1.133.Final/4.2.13.Final Domain Name input validation (Nessus ID 321020)
1 day 9 hours ago
A vulnerability labeled as problematic has been found in Netty up to 4.1.133.Final/4.2.13.Final. The affected element is an unknown function of the component Domain Name Handler. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2026-42579. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com