Aggregator
CVE-2026-24476 | Shaarli up to 0.15.x Tag cross site scripting (GHSA-g3xq-mj52-f8pg / Nessus ID 296741)
CVE-2026-24490 | MobSF Mobile-Security-Framework-MobSF up to 4.4.4 APK cross site scripting
CVE-2025-14971 | Link Invoice Payment for WooCommerce Plugin up to 2.8.0 on WordPress authorization
CVE-2026-24811 | root-project root up to 6.36.00-rc1 zlib input validation
CVE-2026-1421 | code-projects Online Examination System 1.0 Add Pages cross site scripting
CVE-2026-1422 | code-projects Online Examination System 1.0 Login Page /index.php User sql injection
CVE-2026-1423 | code-projects Online Examination System 1.0 /admin_pic.php unrestricted upload
Veracode’s platform enhancements help prevent software supply chain attacks
Veracode announced significant platform innovations introduced through the second half of 2025. Headlining the release is Package Firewall, a preventive control for software supply chains, advancing the company’s mission to help organizations run secure software from code to cloud. With supply chain-related third-party breaches doubling year over year— from 15 to 30 percent according to the Verizon 2025 Data Breach Investigations Report— the need to strengthen security across the software ecosystem has never been greater. … More →
The post Veracode’s platform enhancements help prevent software supply chain attacks appeared first on Help Net Security.
渗透测试实战回忆录: 三次系统崩溃事件的技术复盘与攻防启示录
SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws
CVE-2026-23744:MCPJam Inspector 未授权命令注入远程代码执行代码层面调用链深度解析
AI Agent工具调用链劫持:从上下文污染到持久化后门的系统化攻防
Check Point Harmony SASE Windows Client Vulnerability Enables Privilege Escalation
A critical privilege-escalation vulnerability has been discovered in Check Point’s Harmony SASE (Secure Access Service Edge) Windows client software, affecting versions prior to 12.2. Tracked as CVE-2025-9142, the flaw allows local attackers to write or delete files outside the intended certificate working directory, potentially leading to system-level compromise. The vulnerability exists within the Service component of Perimeter81 […]
The post Check Point Harmony SASE Windows Client Vulnerability Enables Privilege Escalation appeared first on Cyber Security News.