Aggregator
权限绕过思路
4 weeks 1 day ago
正文复现步骤: 登录 https://speakerkit.state.gov/系统会将你跳转到名为 “spk
JVN: Jupyter Serverにおけるオープンリダイレクトの脆弱性
4 weeks 1 day ago
Jupyter Development Teamが提供するJupyter Serverには、オープンリダイレクトの脆弱性が存在します。
摩托罗拉手机回应劫持亚马逊购物商城 是错误配置现在已经修正行为
4 weeks 1 day ago
欢迎「智元」入驻补天专属SRC!
4 weeks 1 day ago
6月4日前提交漏洞可以参加补天专属SRC端午活动,赢补天端午礼盒~
Anthropic Updates Claude Code With Security Plugin and Faster Performance
4 weeks 1 day ago
Anthropic has rolled out a significant update to Claude Code, its AI-powered terminal coding tool, introducing a real-time security-guidance plugin alongside performance improvements that promise a smoother developer experience across the board. Security Plugin Catches Vulnerabilities in Real Time The new security-guidance plugin is available to all Claude Code users and can be installed directly […]
The post Anthropic Updates Claude Code With Security Plugin and Faster Performance appeared first on Cyber Security News.
Guru Baran
CVE-2026-34786 | Rack up to 2.2.22/3.1.20/3.2.5 Rack::Static validate before canonicalize (GHSA-q4qf-9j86-f5mh / Nessus ID 307009)
4 weeks 1 day ago
A vulnerability was found in Rack up to 2.2.22/3.1.20/3.2.5. It has been classified as problematic. Affected is the function Rack::Static. The manipulation leads to incorrect behavior order: validate before canonicalize.
This vulnerability is uniquely identified as CVE-2026-34786. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-34826 | Rack up to 2.2.22/3.1.20/3.2.5 Rack::Utils resource consumption (GHSA-x8cg-fq8g-mxfx / Nessus ID 304830)
4 weeks 1 day ago
A vulnerability, which was classified as problematic, has been found in Rack up to 2.2.22/3.1.20/3.2.5. The affected element is the function Rack::Utils. This manipulation causes resource consumption.
This vulnerability appears as CVE-2026-34826. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33929 | Apache PDFBox Examples up to 2.0.36/3.0.7 ExtractEmbeddedFiles path traversal (WID-SEC-2026-1687)
4 weeks 1 day ago
A vulnerability classified as critical was found in Apache PDFBox Examples up to 2.0.36/3.0.7. This vulnerability affects unknown code of the component ExtractEmbeddedFiles. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-33929. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-34785 | Rack up to 2.2.22/3.1.20/3.2.5 Request Path /css Rack::Static partial string comparison (GHSA-h2jq-g4cq-5ppq / Nessus ID 305959)
4 weeks 1 day ago
A vulnerability described as problematic has been identified in Rack up to 2.2.22/3.1.20/3.2.5. This vulnerability affects the function Rack::Static of the file /css of the component Request Path Handler. Executing a manipulation can lead to partial string comparison.
This vulnerability is registered as CVE-2026-34785. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-34230 | Rack up to 2.2.22/3.1.20/3.2.5 Rack::Utils resource consumption (GHSA-v569-hp3g-36wr / Nessus ID 304839)
4 weeks 1 day ago
A vulnerability classified as problematic has been found in Rack up to 2.2.22/3.1.20/3.2.5. This issue affects the function Rack::Utils. The manipulation leads to resource consumption.
This vulnerability is documented as CVE-2026-34230. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-34763 | Rack up to 2.2.22/3.1.20/3.2.5 Regular Expression Rack::Directory permissive regular expression (GHSA-7mqq-6cf9-v2qp / Nessus ID 304833)
4 weeks 1 day ago
A vulnerability classified as problematic was found in Rack up to 2.2.22/3.1.20/3.2.5. Impacted is the function Rack::Directory of the component Regular Expression Handler. The manipulation results in permissive regular expression.
This vulnerability is reported as CVE-2026-34763. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-33195 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DiskService#path_for path traversal (GHSA-9xrj-h377-fr87 / WID-SEC-2026-1687)
4 weeks 1 day ago
A vulnerability was found in rails activestorage and classified as critical. The affected element is the function DiskService#path_for. Such manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-33195. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-33202 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DiskService#delete_prefixed injection (GHSA-73f9-jhhh-hr5m / WID-SEC-2026-1687)
4 weeks 1 day ago
A vulnerability was found in rails activestorage. It has been classified as problematic. The impacted element is the function DiskService#delete_prefixed. Performing a manipulation results in injection.
This vulnerability was named CVE-2026-33202. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
信息安全漏洞周报(2026年第21期)
4 weeks 1 day ago
根据国家信息安全漏洞库(CNNVD)统计,本周(2026年5月18日至2026年5月24日)安全漏洞情况如下
CVE-2026-33176 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 resource consumption (GHSA-2j26-frm8-cmj9 / Nessus ID 313174)
4 weeks 1 day ago
A vulnerability categorized as problematic has been discovered in rails activesupport. This affects an unknown part. Such manipulation leads to resource consumption.
This vulnerability is referenced as CVE-2026-33176. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33173 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DirectUploadsController intent by broadcast receiver (GHSA-qcfx-2mfw-w4cg / WID-SEC-2026-1687)
4 weeks 1 day ago
A vulnerability categorized as problematic has been discovered in rails activestorage. Affected is the function DirectUploadsController. The manipulation results in improper verification of intent by broadcast receiver.
This vulnerability is identified as CVE-2026-33173. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33174 | rails activestorage up to 7.2.3.1/8.0.4.1/8.1.2.1 memory allocation (GHSA-r46p-8f7g-vvvg / WID-SEC-2026-1687)
4 weeks 1 day ago
A vulnerability identified as problematic has been detected in rails activestorage up to 7.2.3.1/8.0.4.1/8.1.2.1. Affected by this vulnerability is an unknown functionality. This manipulation causes uncontrolled memory allocation.
This vulnerability is tracked as CVE-2026-33174. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-33170 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 html_unsafe cross site scripting (GHSA-89vf-4333-qx8v / WID-SEC-2026-1687)
4 weeks 1 day ago
A vulnerability classified as problematic was found in rails activesupport. This affects the function html_unsafe. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-33170. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-26961 | Rack up to 2.2.22/3.1.20/3.2.5 Content-Type Header Rack::Multipart interpretation conflict (GHSA-vgpv-f759-9wx3 / Nessus ID 307009)
4 weeks 1 day ago
A vulnerability was found in Rack up to 2.2.22/3.1.20/3.2.5 and classified as problematic. This impacts the function Rack::Multipart of the component Content-Type Header Handler. Executing a manipulation can lead to interpretation conflict.
This vulnerability is handled as CVE-2026-26961. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com