Aggregator
亚马逊开始将AI购物技术出售给其他零售商
4 days 1 hour ago
亚马逊开始将AI购物技术出售给其他零售商亚马逊一直在使用自主研发的AI技术,帮助用户比较产品并代其购买或重新订购商品。现在,该公司正在将该技术授权给其他零售商,因为亚马逊力求成为整个网络上AI购物的支
顺丰科技梁博:安全运营、威胁情报&狩猎的AI重构与进化
4 days 1 hour ago
大模型正在给攻防双方带来全新的机遇与挑战。
派早报:鸿蒙智行发布新一代问界 M9、蔚来正式推出 ES9 等
4 days 1 hour ago
鸿蒙智行发布新一代问界 M95 月 27 日,鸿蒙智行正式推出全新一代问界 M9,提供标准版与 Ultimate 领世加长版两款车型。新车引入超 140 项新技术及 40 项行业首创,车身尺寸分别为
CVE-2026-36355 | Realtek rtl819x Jungle SDK up to 3.4.14B rtl8192cd Wi-Fi Kernel Driver 8192cd_cfg.h _IOCTL_DEBUG_CMD_ access control (EDB-52580)
4 days 1 hour ago
A vulnerability classified as critical has been found in Realtek rtl819x Jungle SDK up to 3.4.14B. This affects the function _IOCTL_DEBUG_CMD_ in the library 8192cd_cfg.h of the component rtl8192cd Wi-Fi Kernel Driver. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-36355. The attack can only be done within the local network. Additionally, an exploit exists.
vuldb.com
CVE-2026-43284 | Linux Kernel up to 6.6.137/6.12.86/6.18.27/7.0.4 xfrm skb_splice_from_iter write-what-where condition (EUVD-2026-28535 / EDB-52585)
4 days 1 hour ago
A vulnerability was found in Linux Kernel up to 6.6.137/6.12.86/6.18.27/7.0.4 and classified as critical. Affected by this issue is the function skb_splice_from_iter of the component xfrm. Executing a manipulation can lead to write-what-where condition.
The identification of this vulnerability is CVE-2026-43284. The attack needs to be done within the local network. Furthermore, there is an exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-43500 | Linux Kernel up to 6.18.28/7.0.5/7.1-rc2 rxrpc rxrpc_input_call_event infinite loop (EDB-52585 / Nessus ID 313681)
4 days 1 hour ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.28/7.0.5/7.1-rc2. Affected by this vulnerability is the function rxrpc_input_call_event of the component rxrpc. Such manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2026-43500. The attack can only be initiated within the local network. Moreover, an exploit is present.
The affected component should be upgraded.
vuldb.com
CVE-2026-36356 | GoAhead Web Server 9607.LE.1.0-0011 on MeiG SetRemoteAccessCfg os command injection (EDB-52581)
4 days 1 hour ago
A vulnerability was found in GoAhead Web Server 9607.LE.1.0-0011 on MeiG and classified as critical. Impacted is an unknown function of the file /action/SetRemoteAccessCfg. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-36356. It is possible to launch the attack remotely. Furthermore, an exploit is available.
vuldb.com
CVE-2026-6815 | Casdoor up to 2.328.0 path traversal (EDB-52584)
4 days 1 hour ago
A vulnerability, which was classified as critical, has been found in Casdoor up to 2.328.0. The affected element is an unknown function. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-6815. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2022-2883 | Octopus Deploy ZIP File denial of service (EUVD-2022-35115)
4 days 2 hours ago
A vulnerability was found in Octopus Deploy and classified as problematic. This issue affects some unknown processing of the component ZIP File Handler. The manipulation results in denial of service.
This vulnerability is known as CVE-2022-2883. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2022-2879 | Google Go File Header Reader.Read resource consumption (FEDORA-2022-59a20edab2 / EUVD-2022-35111)
4 days 2 hours ago
A vulnerability labeled as problematic has been found in Google Go. The impacted element is the function Reader.Read of the component File Header Handler. Executing a manipulation can lead to resource consumption.
This vulnerability is handled as CVE-2022-2879. The attack can be executed remotely. There is not any exploit available.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2022-2880 | Google Go net-http request smuggling (FEDORA-2022-59a20edab2 / EUVD-2022-35112)
4 days 2 hours ago
A vulnerability described as critical has been identified in Google Go. This impacts an unknown function of the component net-http. The manipulation results in http request smuggling.
This vulnerability was named CVE-2022-2880. The attack may be performed from remote. There is no available exploit.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2022-2882 | GitLab Community Edition/Enterprise Edition up to 15.2.4/15.3.3/15.4.0 Access Token exposure of resource (Issue 37108 / EUVD-2022-35114)
4 days 2 hours ago
A vulnerability, which was classified as problematic, was found in GitLab Community Edition and Enterprise Edition up to 15.2.4/15.3.3/15.4.0. The affected element is an unknown function of the component Access Token Handler. Such manipulation leads to exposure of resource.
This vulnerability is listed as CVE-2022-2882. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2022-2874 | vim up to 9.0.0220 null pointer dereference (EUVD-2022-35106 / Nessus ID 224714)
4 days 2 hours ago
A vulnerability classified as problematic has been found in vim. Affected by this vulnerability is an unknown functionality. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2022-2874. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
SEO poisoning e chatbot AI dirottati per un malware miner
4 days 2 hours ago
Robinhood宣布股民可接入第三方智能体
4 days 2 hours ago
Robinhood宣布股民可接入第三方智能体AI智能体(AI Agent)亲自上阵炒股的时代终于来了。有着美国 “散户大本营” 称号的互联网券商Robinhood周三宣布,即日起推出“智能体交易”功能
6月1日正式实施《网络安全等级保护数据安全基本要求》
4 days 2 hours ago
等保标准。
6月1日正式实施《网络安全等级保护数据安全基本要求》
4 days 2 hours ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2026-1561 | IBM WebSphere Application Server Liberty up to 26.0.0.3 server-side request forgery (Nessus ID 313186 / WID-SEC-2026-1687)
4 days 2 hours ago
A vulnerability labeled as critical has been found in IBM WebSphere Application Server Liberty up to 26.0.0.3. This affects an unknown function. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-1561. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
The Small Model Cliff
4 days 3 hours ago
CASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain Incidents