Aggregator
CVE-2025-48521 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics use after free (EUVD-2025-209863)
CVE-2025-48519 | AMD Ryzen 7035 Processors with Radeon Graphics Management Frame out-of-bounds write (EUVD-2025-209866)
CVE-2025-0045 | AMD Athlon 3000 Mobile Processors with Radeon Graphics buffer overflow (EUVD-2025-209862)
CVE-2025-48520 | AMD Ryzen 7035 Processors with Radeon Graphics prior 7.06.02.123 Management Frame out-of-bounds (EUVD-2025-209865)
CVE-2026-45375 | SiYuan up to 3.6.5 Setting plugin.json cross site scripting (GHSA-27qc-m5gf-jv5r)
CVE-2026-45371 | SiYuan up to 3.6.x /api/graph/getGraph model.Conf.Save improper authorization (GHSA-gmmv-4cc5-wr9r)
CVE-2026-0438 | AMD Ryzen 7040 Mobile Processors with Radeon Graphics data resource access without connection pooling
BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking
BAADTokenBroker BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys. It can: Request
The post BAADTokenBroker Abuses Microsoft Entra ID Device-Bound Keys for PRT Hijacking appeared first on Penetration Testing Tools.
CVE-2024-36345 | AMD EPYC 4004 System Management Mode improper access control for volatile memory containing boot code
CVE-2026-8621 | openclaw crabbox up to 0.11.x improper authentication
CVE-2026-45148 | SiYuan up to 3.6.x Publish Service authorization (GHSA-fmh9-gpqh-g53g)
CVE-2026-44592 | wavelens gradient 1.1.0 NixOS /proto missing authentication (GHSA-49w6-gf3p-96m2)
CVE-2025-48512 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics prior 7.04.09.545 Installation Directory default permission (EUVD-2025-209861)
CVE-2026-45147 | SiYuan up to 3.6.x /api/tag/getTag model.Conf.Save sort improper authorization (GHSA-6r88-8v7q-q4p2)
CVE-2026-44670 | SiYuan up to 3.6.x Transaction cross site scripting (GHSA-2h64-c999-c9r6)
Codex终于支持移动端 开发者可在ChatGPT中控制Codex for macOS执行任务或审批
ChatGPT 手机版新增远程操作 Codex:电脑干活,手机盯进度|牛马程序员,永不停歇
特朗普称中国同意订购200架波音飞机
Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access
A maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller is being actively exploited in the wild, allowing unauthenticated remote attackers to fully bypass authentication and seize administrative control of enterprise network infrastructure. Tracked as CVE-2026-20182 with a CVSS score of 10.0, the flaw puts SD-WAN deployments across on-premises, cloud, and government environments at critical risk. […]
The post Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access appeared first on Cyber Security News.