Aggregator
JetBrains security advisory (AV26-541)
3 weeks 3 days ago
Canadian Centre for Cyber Security
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
3 weeks 3 days ago
The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.
Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an
The Hacker News
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
3 weeks 3 days ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was
The Hacker News
Black X
3 weeks 3 days ago
You must login to view this content
cohenido
Black X
3 weeks 3 days ago
You must login to view this content
cohenido
Где пообедать в чужом городе? Ответ в заметках Фейнмана — нобелевский лауреат вывел формулу лучшего ужина
3 weeks 3 days ago
Математика точно знает, когда вам пора перестать искать новые места.
[Control systems] Siemens security advisory (AV26-540)
3 weeks 3 days ago
Canadian Centre for Cyber Security
New Threat Actor Black X
3 weeks 3 days ago
You must login to view this content
cohenido
Black X
3 weeks 3 days ago
You must login to view this content
cohenido
Black X
3 weeks 3 days ago
You must login to view this content
cohenido
Android security advisory – June 2026 monthly rollup (AV26-538) – Update 1
3 weeks 3 days ago
Canadian Centre for Cyber Security
CVE-2026-10705 | dask up to 3.0 HLL hyperloglog.py nunique_approx resource consumption (Issue 12403 / EUVD-2026-34064)
3 weeks 3 days ago
A vulnerability classified as problematic has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption.
This vulnerability is tracked as CVE-2026-10705. The attack is possible to be carried out remotely. No exploit exists.
The pull request to fix this issue awaits acceptance.
vuldb.com
CVE-2026-10704 | SourceCodester Pizzafy E-Commerce System 1.0 Administrative Control Panel admin_class_novo.php login Username sql injection (EUVD-2026-34063)
3 weeks 3 days ago
A vulnerability described as critical has been identified in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection.
This vulnerability is identified as CVE-2026-10704. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2026-10703 | EIPStackGroup OpENer up to 2.3.0 SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free (Issue 566 / EUVD-2026-34062)
3 weeks 3 days ago
A vulnerability marked as critical has been reported in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-10703. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
Submit #831411: dask 2026.3.0 Algorithmic Complexity / Hash Collision / Denial of Service [Accepted]
3 weeks 3 days ago
Submit #831411 / VDB-368018
Dem0
Submit #831321: SourceCodester Pizzafy E-Commerce System 1.0 SQL injection [Accepted]
3 weeks 3 days ago
Submit #831321 / VDB-368017
Fklov
Submit #830957: sourcecodester Hospital's Patient Records Management System V1.0 SQL injection [Duplicate]
3 weeks 3 days ago
Submit #830957 / VDB-201888
Fklov
Submit #830921: Linux OpENer (Open EtherNet/IP Stack) lastet Use After Free [Accepted]
3 weeks 3 days ago
Submit #830921 / VDB-368016
QvuQ_lkx
CVE-2026-40715 | Dell ThinOS 10 10.0765 access control (dsa-2026-214 / EUVD-2026-33979)
3 weeks 3 days ago
A vulnerability labeled as critical has been found in Dell ThinOS 10 10.0765. This impacts an unknown function. Executing a manipulation can lead to improper access controls.
The identification of this vulnerability is CVE-2026-40715. The attack can only be executed locally. There is no exploit available.
The affected component should be upgraded.
vuldb.com