Aggregator
CVE-2026-42516 | CDAC-Noida e-Sushrut Hospital Management Information System encoded authorization (CIVN-2026-0207 / EUVD-2026-26201)
CVE-2026-4019 | Complianz Plugin up to 7.4.5 on WordPress REST API Endpoint cmplz_rest_consented_content authorization (EUVD-2026-26200)
CVE-2026-42518 | CDAC-Noida e-Sushrut Hospital Management Information System hard-coded key (CIVN-2026-0207 / EUVD-2026-26204)
CVE-2026-42517 | CDAC-Noida e-Sushrut Hospital Management Information System Base64 Encoding authorization (CIVN-2026-0207 / EUVD-2026-26203)
CVE-2026-3325 | CRM Sistemas de Fidelización MegaCMS 12.0.0 POST Request get_provincias id_territorio sql injection (EUVD-2026-26199)
CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Microsoft Windows. On April 28, 2026, the agency officially added this security flaw to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability impacts the Microsoft Windows Shell and is actively being exploited in real-world attacks. Organizations worldwide […]
The post CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks appeared first on Cyber Security News.
Submit #803495: geekgod382 filesystem-mcp-server 4e3e83852b1395de0a437bd4fd66376422f4ea0c Path Traversal [Accepted]
Игрушка-психолог, игрушка-учитель, игрушка-шпион. Знакомьтесь: ИИ-компаньон для вашего ребёнка
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks
A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked as CVE-2026-25874 with a critical CVSS score of 9.3, the flaw allows unauthenticated attackers to execute arbitrary system commands on vulnerable host machines. With nearly 24,000 stars on GitHub, this […]
The post Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks appeared first on Cyber Security News.
What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
AI彻底取代产品经理?言之凿凿,却为时尚早
CVE-2026-7398 | florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 Upload Endpoint app.py upload Name path traversal
Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks
Google has released a critical security update for its Chrome desktop browser to address 30 security vulnerabilities, including four severe flaws that could enable Remote Code Execution (RCE) attacks. The Stable channel has been updated to version 147.0.7727.137/138 for Windows and Mac, and to 147.0.7727.137 for Linux. Google is rolling out this update gradually over […]
The post Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks appeared first on Cyber Security News.