Aggregator
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 3 weeks hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
2 weeks 4 days hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 1 minute ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
西班牙下令屏蔽 Archive.today 及相关存档网站
3 hours 13 minutes ago
西班牙政府下令屏蔽 Archive.today 及相关镜像域名 Archive.is、Archive.ph 和 Archive.li。Archive.today 等网站被广泛用于绕过付费墙,此前由于托管了 DDoS 脚本(至今还在)而被维基百科屏蔽。但西班牙的屏蔽与此无关,而是由于有人投诉该存档网站上有违规内容。此举属于行政决定,而非法院裁决。
Ubuntu 26.10 改用 Linux 7.3 Kernel
3 hours 34 minutes ago
即将于下个月推出的 Ubuntu 26.10 将采用 Linux 7.3 Kernel,而不是原计划的 Linux 7.2。Linux 7.3 目前还是 RC3,预计最快于 10 月 18 日释出正式版,可能会延期一周到 10 月 25 日。而 Ubuntu 26.10 将于 10 月 1 日冻结内核,10 月 15 日释出正式版本,这意味着届时它使用的 7.3 Kernel 仍然会是 RC 状态。Ubuntu 项目此前已宣布它将会紧跟最新内核版本,而 26.10 是一个短期版本,因此 Ubuntu 团队将紧跟上游内核版本。
360数字安全集团与星链南天达成京东渠道战略合作
4 hours 5 minutes ago
以高品质数字安全服务惠及政企单位
360发布“U+隐私搜索”,护航中国—东盟AI数据安全合作
4 hours 5 minutes ago
中国—东盟AI部长圆桌会议举行,360发布“U+隐私搜索”
对所有亿万富翁征收 3% 的税能拯救数百万人的生命
4 hours 15 minutes ago
面向中低收入国家的人道主义与发展援助资金 Official development assistance(ODA)过去两年被大幅削减,但如果对亿万富翁征税,将可以填补资金缺口,有望拯救数百万人的生命。全世界资产逾 10 亿美元的亿万富翁超过 3000 人,他们的总资产达到创纪录的 20.1 万亿美元,比上一年增加了 4 万亿美元。如果对这些财富征收 3% 的税,有望在 2030 年让将死亡人数减少 2950 万;征收 1% 的财富税则可减少 1510 万死亡人数。研究人员表示,在贫富差距日益悬殊且财富高度集中的当今世界,研究结果显示,旨在支持全球发展的替代性财富再分配政策,有潜力缓解 ODA 资金削减带来的负面影响。他们同时强调,结果是基于模型估算。少数国家已实施了财富税。西班牙于 202 2年开征团结财富税(solidarity wealth tax),对净资产逾 300 万欧元的个人征收 1.7%-3.5% 的税款。法国也曾讨论过征收 2% 的财富税,但相关提案遭到了参议院的否决。
CVE-2026-86555 | ZTE SmartLife missing encryption
4 hours 23 minutes ago
A vulnerability classified as problematic was found in ZTE SmartLife. The impacted element is an unknown function. The manipulation results in missing encryption of sensitive data.
This vulnerability is known as CVE-2026-86555. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2026-94101 | Netcore NBR200V2 1.3.241127.071246 /usr/bin/routerd vlan_load_form_uci wan_num buffer overflow
4 hours 43 minutes ago
A vulnerability classified as very critical has been found in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow.
This vulnerability is traded as CVE-2026-94101. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94100 | Netcore NBR200V2 1.3.241127.071246 WAN VLAN Reconfiguration /usr/bin/routerd wan_config_set_vlan vlan_wanX.ports buffer overflow
4 hours 43 minutes ago
A vulnerability described as very critical has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow.
This vulnerability appears as CVE-2026-94100. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94099 | Netcore NBR200V2 1.3.241127.071246 Backup Restore restore.cgi QUERY_STRING command injection
4 hours 43 minutes ago
A vulnerability marked as very critical has been reported in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection.
This vulnerability is reported as CVE-2026-94099. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94098 | Netcore NBR200V2 1.3.241127.071246 Firmware Upgrade CGI Endpoint /www/cgi-bin/upgrade QUERY_STRING command injection
4 hours 43 minutes ago
A vulnerability labeled as very critical has been found in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection.
This vulnerability is documented as CVE-2026-94098. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94097 | Netcore NBR200V2 1.3.241127.071246 CGI Diagnostic Endpoint network_tools param/key/val command injection
4 hours 43 minutes ago
A vulnerability identified as very critical has been detected in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection.
This vulnerability is registered as CVE-2026-94097. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94096 | Netcore NBR200V2 1.3.241127.071246 LAN IP Configuration /usr/bin/network_tools ipv4 command injection
4 hours 44 minutes ago
A vulnerability categorized as very critical has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection.
This vulnerability is cataloged as CVE-2026-94096. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94095 | Netcore NBR200V2 1.3.241127.071246 Traceroute Diagnostic Feature /usr/bin/network_tools url command injection
4 hours 44 minutes ago
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. It has been rated as very critical. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection.
This vulnerability is listed as CVE-2026-94095. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-94094 | OpenClaw up to 2026.9.5 Canvas Host Route server.ts createCanvasHostHandler denial of service
4 hours 55 minutes ago
A vulnerability was found in OpenClaw up to 2026.9.5. It has been declared as problematic. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-94094. The attack can be launched remotely. Moreover, an exploit is present.
Fix suggestion's "streaming/size-limit" was never shipped - latest 2026.9.5 still buffers the whole file via readFile() (src/canvas/serve.runtime.ts:17,114), unlike the sibling WS path which caps at 64KB. The vendor was contacted early about this disclosure.
vuldb.com
Cyber League 2026 - Major
5 hours 3 minutes ago
Name: Cyber League 2026 - Major (an Cyber League event.)
Date: Sept. 19, 2026, 2 a.m. — 20 Sept. 2026, 02:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://cyberleague.co/
Rating weight: 0
Event organizers: DIV0-N0H4TS
Date: Sept. 19, 2026, 2 a.m. — 20 Sept. 2026, 02:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://cyberleague.co/
Rating weight: 0
Event organizers: DIV0-N0H4TS
WATCHLIST
5 hours 3 minutes ago
Name: WATCHLIST (an WatchList CTF event.)
Date: Sept. 19, 2026, 3:30 a.m. — 20 Sept. 2026, 03:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.xposedornot.com/
Rating weight: 0
Event organizers: WatchList CTF
Date: Sept. 19, 2026, 3:30 a.m. — 20 Sept. 2026, 03:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.xposedornot.com/
Rating weight: 0
Event organizers: WatchList CTF