Aggregator
GISEC GLOBAL 2026 – The Middle East & Africa’s Largest Cybersecurity Event
1 week 6 days hence
Weekly Threat Bulletin – April 22nd, 2026
20 hours 54 minutes hence
These are the top threats you should know about this week.
CVE-2026-6310 | Google Chrome up to 147.0.7727.55 Dawn use after free (ID 497969 / Nessus ID 307658)
1 hour 45 minutes ago
A vulnerability, which was classified as critical, was found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Dawn. The manipulation results in use after free.
This vulnerability is identified as CVE-2026-6310. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-6311 | Google Chrome up to 147.0.7727.55 on Windows Accessibility uninitialized variable (ID 498201 / Nessus ID 307658)
1 hour 45 minutes ago
A vulnerability has been found in Google Chrome on Windows and classified as problematic. Affected by this issue is some unknown functionality of the component Accessibility. This manipulation causes use of uninitialized variable.
This vulnerability is tracked as CVE-2026-6311. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-6360 | Google Chrome up to 147.0.7727.55 Fileystem use after free (ID 497880 / Nessus ID 307658)
1 hour 45 minutes ago
A vulnerability classified as critical has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Fileystem. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-6360. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
2 hours 2 minutes ago
Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC.
According to new research published by Check Point, the command-and-control (C2 or C&C) server linked to SystemBC has led to the discovery of a botnet of more than 1,570 victims.
"SystemBC establishes SOCKS5 network tunnels within
The Hacker News
CVE-2026-6784 | Mozilla Firefox up to 149 memory corruption (Nessus ID 307899)
2 hours 16 minutes ago
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 149. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2026-6784. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-6785 | Mozilla Firefox up to 149 memory corruption (Nessus ID 307899)
2 hours 16 minutes ago
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 149. Affected by this issue is some unknown functionality. The manipulation results in memory corruption.
This vulnerability was named CVE-2026-6785. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-34080 | flatpak xdg-dbus-proxy up to 0.1.6 improper validation of unsafe equivalence in input (GHSA-vjp5-hjfm-7677 / Nessus ID 307902)
2 hours 16 minutes ago
A vulnerability has been found in flatpak xdg-dbus-proxy up to 0.1.6 and classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes improper validation of unsafe equivalence in input.
The identification of this vulnerability is CVE-2026-34080. The attack can only be executed locally. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-6786 | Mozilla Firefox up to 149 memory corruption (Nessus ID 307899)
2 hours 16 minutes ago
A vulnerability has been found in Mozilla Firefox up to 149 and classified as critical. This affects an unknown part. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2026-6786. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-41253 | iTerm2 up to 3.6.9 File inclusion of functionality from untrusted control sphere (EUVD-2026-23656 / Nessus ID 307903)
2 hours 17 minutes ago
A vulnerability was found in iTerm2 up to 3.6.9. It has been rated as problematic. This impacts an unknown function of the component File Handler. The manipulation leads to inclusion of functionality from untrusted control sphere.
This vulnerability is traded as CVE-2026-41253. An attack has to be approached locally. There is no exploit available.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2022-20552 | Google Android 13.0 btif_a2dp_sink.cc btif_a2dp_sink_command_ready out-of-bounds (A-243922806 / EUVD-2022-25812)
2 hours 25 minutes ago
A vulnerability was found in Google Android 13.0. It has been declared as problematic. Affected by this vulnerability is the function btif_a2dp_sink_command_ready of the file btif_a2dp_sink.cc. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is registered as CVE-2022-20552. The attack needs to be launched locally. No exploit is available.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2022-20551 | Google Android 12.0/13.0 AudioFlinger.cpp createTrack Local Privilege Escalation (A-243376549 / EUVD-2022-25811)
2 hours 25 minutes ago
A vulnerability classified as problematic has been found in Google Android 12.0/13.0. This vulnerability affects the function createTrack of the file AudioFlinger.cpp. This manipulation causes Local Privilege Escalation.
This vulnerability appears as CVE-2022-20551. The attack requires local access. There is no available exploit.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-20550 | Google Android 13.0 Local Privilege Escalation (A-242845514 / EUVD-2022-25810)
2 hours 25 minutes ago
A vulnerability has been found in Google Android 13.0 and classified as problematic. This issue affects some unknown processing. This manipulation causes Local Privilege Escalation.
This vulnerability is handled as CVE-2022-20550. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2026-6309 | Google Chrome up to 147.0.7727.55 Viz use after free (ID 497846 / Nessus ID 307658)
3 hours 2 minutes ago
A vulnerability classified as critical has been found in Google Chrome. This affects an unknown function of the component Viz. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-6309. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-35206 | Helm up to 3.20.1/4.1.3 Chart path traversal (GHSA-hr2v-4r36-88hr / Nessus ID 307885)
3 hours 2 minutes ago
A vulnerability was found in Helm up to 3.20.1/4.1.3. It has been classified as critical. This vulnerability affects unknown code of the component Chart Handler. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-35206. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-55199 | Helm up to 3.18.4 JSON Schema File /dev/zero ref allocation of resources (GHSA-9h84-qmv7-982p / Nessus ID 307885)
3 hours 2 minutes ago
A vulnerability was found in Helm up to 3.18.4. It has been classified as problematic. The affected element is an unknown function of the file /dev/zero of the component JSON Schema File Handler. Performing a manipulation of the argument ref results in allocation of resources.
This vulnerability was named CVE-2025-55199. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-2049 | GIMP HDR File Parser heap-based overflow (Nessus ID 307887)
3 hours 2 minutes ago
A vulnerability classified as critical has been found in GIMP. This vulnerability affects unknown code of the component HDR File Parser. This manipulation causes heap-based buffer overflow.
This vulnerability appears as CVE-2026-2049. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.
vuldb.com
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
3 hours 18 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅