Aggregator
CVE-2026-14787 | radareorg radare2 up to 6.1.6 pb Print Command libr/core/cmd_print.inc cmd_print integer overflow (Issue 26048 / EUVD-2026-41797)
CVE-2026-55379 | Pillow up to 12.2.x BDF Font Parser PIL/BdfFontFile.py bdf_char width/height memory allocation (Nessus ID 325356)
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
CVE-2026-14789 | radareorg radare2 up to 6.1.6 Memory64ListStream Parser mdmp.c stack-based overflow (Issue 26051 / EUVD-2026-41800)
CVE-2026-14803 | Mojo::JSON up to 9.46 Perl Decoder _decode_value memory allocation (EUVD-2026-41798 / Nessus ID 325357)
CVE-2026-14786 | radareorg radare2 up to 6.1.6 libr/util/str.c r_str_word_get0set integer overflow (Issue 26047 / EUVD-2026-41796)
CVE-2026-57871 | MicroRealEstate up to 1.0.0-alpha3 path traversal (EUVD-2026-42008)
CVE-2026-58315 | SEIKO EPSON Page Handler cross-site request forgery (EUVD-2026-42007)
CVE-2026-14345 | getwpfunnels WPFunnels Plugin up to 3.12.7 Log wpfnl_show_log postData injection (EUVD-2026-42009)
CVE-2026-12277 | Frontend File Manager Plugin up to 23.6 File Deletion wp-config.php file inclusion (EUVD-2026-42011)
CVE-2026-10834 | WP Travel Engine Plugin up to 6.8.0 file inclusion (EUVD-2026-42010)
CVE-2026-12375 | uncanny-automator-pro Plugin up to 7.3.0.5 backdoor (EUVD-2026-42012)
CVE-2026-4375 | DoLeads Integrator Plugin/wp2epub Plugin up to 0.65 Plugin Installer code injection (EUVD-2026-42013)
Эксперимент, о котором никто не знал. Anthropic тайно следила за пользователями из Китая — и теперь объясняется
Tenda Authentication Backdoor Grants Attackers Full Administrative Access
A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials. The flaw affects multiple firmware versions across several Tenda router models, including the FH1201, W15E, AC10, AC5, and AC6 series. The issue, tracked as CVE-2026-11405, was published by the CERT Coordination […]
The post Tenda Authentication Backdoor Grants Attackers Full Administrative Access appeared first on Cyber Security News.
16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory
A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed “Januscape,” exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained unnoticed for nearly 16 years, affects KVM’s x86 shadow memory management logic and impacts both […]
The post 16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory appeared first on Cyber Security News.