Aggregator
CVE-2026-25149 | QwikDev qwik up to 1.18.x redirect (GHSA-92j7-wgmg-f32m / EUVD-2026-5169)
Шесть «нулевых дней», 58 уязвимостей и полный контроль над системой. Microsoft выпустила февральский Patch Tuesday
Zen-AI-Pentest: Open-source AI-powered penetration testing framework
Zen-AI-Pentest provides an open-source framework for scanning and exercising systems using a combination of autonomous agents and standard security utilities. The project aims to let users run an orchestrated sequence of reconnaissance, vulnerability scanning, exploitation, and reporting using AI guidance and industry tools like Nmap and Metasploit. It is written to support command line, API, and web interfaces. Multi-agent structure and integrated tools Zen-AI-Pentest organizes its functionality around a set of agents that handle discrete … More →
The post Zen-AI-Pentest: Open-source AI-powered penetration testing framework appeared first on Help Net Security.
GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks
A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers to crash servers, steal data, or hijack user sessions. Security experts urge administrators of self-managed instances to upgrade […]
The post GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks appeared first on Cyber Security News.
CVE-2026-24673 | Openeclass Open eClass up to 4.1 Decompression unrestricted upload
CVE-2026-24674 | Openeclass Open eClass up to 4.1 cross site scripting
CVE-2026-24665 | openeclass Open eClass up to 4.1 cross site scripting
CVE-2026-24671 | Openeclass Open eClass up to 4.1 cross site scripting
CVE-2026-24672 | Openeclass Open eClass up to 4.1 User Profile cross site scripting
CVE-2026-25483 | Craft CMS up to 4.10.0/5.5.1 History Message cross site scripting (GHSA-8478-rmjg-mjj5)
CVE-2026-25484 | Craft CMS up to 4.10.0/5.5.1 Product Type Name cross site scripting (GHSA-2h2m-v2mg-656c)
CVE-2026-25482 | Craft CMS up to 4.10.0/5.5.1 Order Status cross site scripting (GHSA-frj9-9rwc-pw9j)
CVE-2026-25485 | Craft CMS up to 4.10.0/5.5.1 Store Management Section cross site scripting (GHSA-w8gw-qm8p-j9j3)
CVE-2026-25486 | Craft CMS up to 5.5.1 Store Management Section Shipping Methods Name cross site scripting (GHSA-g92v-wpv7-6w22)
CVE-2026-25487 | Craft CMS up to 4.10.0/5.5.1 Store Management Section Tax Rates Name cross site scripting (GHSA-wqc5-485v-3hqh)
CVE-2026-25488 | Craft CMS up to 4.10.0/5.5.1 Store Management Section Name/Description cross site scripting (GHSA-p6w8-q63m-72c8)
CVE-2026-25489 | Craft CMS up to 4.10.0/5.5.1 Description cross site scripting (GHSA-v585-mf6r-rqrc)
Нейрослоп за $10 млн. Как генеративный ИИ превратил Супербоул в парад абсурда
Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely
Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. Disclosed on February 10, 2026, Microsoft Patch Tuesday updates, the vulnerability stems from improper neutralization of special elements in commands (CWE-77: Command Injection) and carries a CVSS […]
The post Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely appeared first on Cyber Security News.