Aggregator
网商银行:AI Agent重构威胁运营,打造数字银行智能安全体系
2 weeks 3 days ago
AI正在重构金融安全运营的底层逻辑,数字银行威胁运营正面临全新挑战。
网商银行:AI Agent重构威胁运营,打造数字银行智能安全体系
2 weeks 3 days ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2026-6352 | GitLab up to 18.11.6/19.0.3/19.1.1 GraphQL Operations improper authorization
2 weeks 3 days ago
A vulnerability identified as critical has been detected in GitLab up to 18.11.6/19.0.3/19.1.1. This affects an unknown function of the component GraphQL Operations. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-6352. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-59818 | etcd-io etcd up to 3.5.31/3.6.12 gRPC Client Authentication certificate validation
2 weeks 3 days ago
A vulnerability categorized as problematic has been discovered in etcd-io etcd up to 3.5.31/3.6.12. The impacted element is an unknown function of the component gRPC Client Authentication Handler. Executing a manipulation can lead to improper certificate validation.
This vulnerability appears as CVE-2026-59818. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-5923 | HP Poly CCX/Poly Edge E/Poly Trio C60 Webpage authorization
2 weeks 3 days ago
A vulnerability was found in HP Poly CCX, Poly Edge E and Poly Trio C60. It has been rated as problematic. The affected element is an unknown function of the component Webpage. Performing a manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-5923. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-58191 | Appium up to 10.6.x Route /test/guinea-pig compileLodashTemplate throwError/comments/User-Agent cross site scripting
2 weeks 3 days ago
A vulnerability was found in Appium up to 10.6.x. It has been declared as problematic. Impacted is the function compileLodashTemplate of the file /test/guinea-pig of the component Route Handler. Such manipulation of the argument throwError/comments/User-Agent leads to cross site scripting.
This vulnerability is documented as CVE-2026-58191. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-59723 | Cline up to 3.0.29 Cline Hub Dashboard isAuthorizedBrowserRequest provider improper authorization
2 weeks 3 days ago
A vulnerability was found in Cline up to 3.0.29. It has been classified as critical. This issue affects the function isAuthorizedBrowserRequest of the component Cline Hub Dashboard. This manipulation of the argument provider causes improper authorization.
This vulnerability is registered as CVE-2026-59723. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-55778 | parse-community Parse Server up to 8.6.80/9.9.1-alpha.10 FileUpload cross site scripting
2 weeks 3 days ago
A vulnerability was found in parse-community Parse Server up to 8.6.80/9.9.1-alpha.10 and classified as problematic. This vulnerability affects unknown code of the component FileUpload. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-55778. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-58192 | Appium up to 1.1.5 Storage Plugin /storage/delete fs.rimraf Name path traversal
2 weeks 3 days ago
A vulnerability has been found in Appium up to 1.1.5 and classified as critical. This affects the function fs.rimraf of the file /storage/delete of the component Storage Plugin. The manipulation of the argument Name leads to relative path traversal.
This vulnerability is listed as CVE-2026-58192. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-54784 | CoreWCF up to 1.9.0 SPNEGO SecurityContextToken Negotiation improper authentication
2 weeks 3 days ago
A vulnerability, which was classified as critical, was found in CoreWCF up to 1.9.0. Affected by this issue is some unknown functionality of the component SPNEGO SecurityContextToken Negotiation. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2026-54784. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-57481 | parse-community parse-server up to 8.6.82/9.9.1-alpha.12 LiveQuery improper authorization
2 weeks 3 days ago
A vulnerability, which was classified as problematic, has been found in parse-community parse-server up to 8.6.82/9.9.1-alpha.12. Affected by this vulnerability is an unknown functionality of the component LiveQuery. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-57481. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-54783 | CoreWCF up to 1.8.0/1.9.0 WS-Security Signature Verifier authentication replay
2 weeks 3 days ago
A vulnerability classified as critical was found in CoreWCF up to 1.8.0/1.9.0. Affected is an unknown function of the component WS-Security Signature Verifier. Such manipulation leads to authentication bypass by capture-replay.
This vulnerability is referenced as CVE-2026-54783. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-57480 | parse-community parse-server up to 8.6.81/9.9.1-alpha.11 REST API infinite loop
2 weeks 3 days ago
A vulnerability classified as problematic has been found in parse-community parse-server up to 8.6.81/9.9.1-alpha.11. This impacts an unknown function of the component REST API. This manipulation causes infinite loop.
The identification of this vulnerability is CVE-2026-57480. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-54782 | CoreWCF up to 1.8.0/1.9.0 SAML Token Validation improper authentication
2 weeks 3 days ago
A vulnerability described as critical has been identified in CoreWCF up to 1.8.0/1.9.0. This affects an unknown function of the component SAML Token Validation. The manipulation results in improper authentication.
This vulnerability was named CVE-2026-54782. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-15128 | Google Chrome up to 150.0.7871.47 Forms cross site scripting
2 weeks 3 days ago
A vulnerability marked as problematic has been reported in Google Chrome. The impacted element is an unknown function of the component Forms. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-15128. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
苹果公司折叠机预计不会出现量产延期
2 weeks 3 days ago
苹果公司折叠机预计不会出现量产延期日前,有市场消息称,苹果公司首款折叠机产品或因产品组装复杂、良率较低等原因延期发售。记者就此采访多位果链企业人士获悉,苹果公司折叠机产品方案早已确定,目前相关企业已进
CVE-2026-15127 | Google Chrome up to 150.0.7871.47 WebGL cross site scripting
2 weeks 3 days ago
A vulnerability labeled as problematic has been found in Google Chrome. The affected element is an unknown function of the component WebGL. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-15127. The attack can be executed remotely. There is not any exploit available.
vuldb.com
The Model Chooses a Future Before It Says a Token
2 weeks 3 days ago
What I learned from ICML 2026 through interpretability, alignment, post-training, and agent safety
TensorLock:恢复大模型供应链中缺失的模型依赖关系
2 weeks 3 days ago
TensorLock通过公开模型权重恢复缺失的模型依赖关系,支撑大模型供应链的风险溯源与缓解。