Aggregator
10 Cybersecurity Priorities for E-Commerce Teams This Year
5 days 12 hours ago
Your platform is open 24 hours a day. So are the attacks.There’s no closing time in e-commerce, hen
JVN: FastStone Image Viewerにおけるファイル解析に関する複数の脆弱性
5 days 12 hours ago
CERT/CCから本件に関するアドバイザリが公表されました。
CVE-2026-44432 | urllib3 up to 2.6.x on Python HTTPResponse.drain_conn data amplification (Nessus ID 321968 / WID-SEC-2026-1923)
5 days 12 hours ago
A vulnerability labeled as problematic has been found in urllib3 up to 2.6.x on Python. Impacted is the function HTTPResponse.drain_conn. Such manipulation leads to highly compressed data.
This vulnerability is uniquely identified as CVE-2026-44432. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-12725 | Red Hat Enterprise Linux/OpenShift Container Platform heap-based overflow (EUVD-2026-38278 / Nessus ID 321969)
5 days 12 hours ago
A vulnerability marked as critical has been reported in Red Hat Enterprise Linux and OpenShift Container Platform. This vulnerability affects unknown code. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is known as CVE-2026-12725. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-44431 | urllib3 up to 2.6.x on Python ProxyManager.connection_from_url.urlopen information disclosure (Nessus ID 321968 / WID-SEC-2026-1923)
5 days 12 hours ago
A vulnerability marked as problematic has been reported in urllib3 up to 2.6.x on Python. The affected element is the function ProxyManager.connection_from_url.urlopen. Performing a manipulation results in information disclosure.
This vulnerability was named CVE-2026-44431. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-12549 | Red Hat Enterprise Linux up to 10 buffer access with incorrect length value (Nessus ID 321970)
5 days 12 hours ago
A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux 6/7/8/9/10. This affects an unknown part. Such manipulation leads to buffer access with incorrect length value.
This vulnerability is traded as CVE-2026-12549. The attack may be launched remotely. There is no exploit available.
Applying a patch is advised to resolve this issue.
vuldb.com
CNVD漏洞周报2026年第24期
5 days 12 hours ago
JVN: Microsoft Windows Recovery EnvironmentにおけるUEFI/BIOSパスワード制限回避の脆弱性
5 days 12 hours ago
CERT/CCから本件に関するアドバイザリが公表されました。
跳过 19,传苹果将在明年 20 周年庆推出 iPhone 20;豆包灰测打车功能;SpaceX 跌破首日发行价 | 极客早知道
5 days 12 hours ago
亚马逊投流 ChatGPT;智谱 GLM-5.5 或八月升级;SK 海力士大规模招聘引发行业巨震
FortiBleed: What Security Teams Need to Know (and Why This Story Is Bigger Than Fortinet)
5 days 12 hours ago
Most stories miss the most critical part of FortiBleed - the firewall wasn't the destinati
苹果批准可折叠iPhone的OLED面板生产
5 days 12 hours ago
苹果批准可折叠iPhone的OLED面板生产三星显示已获得苹果公司批准,开始为苹果首款可折叠iPhone进行OLED面板的模组生产。据悉,三星显示已开始运营其在越南的部分后端生产线,以履行今年交付约
CVE-2026-45909 | Linux Kernel up to 6.18.13/6.19.3 clk mtk_clk_register_gate initialization (WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.13/6.19.3. This affects the function mtk_clk_register_gate of the component clk. Executing a manipulation can lead to improper initialization.
This vulnerability appears as CVE-2026-45909. The attacker needs to be present on the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-45910 | Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3 rxe retransmit_timer use after free (Nessus ID 321065 / WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability has been found in Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3 and classified as critical. This impacts the function retransmit_timer of the component rxe. The manipulation leads to use after free.
This vulnerability is traded as CVE-2026-45910. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45907 | Linux Kernel up to 6.18.13/6.19.3 netdev_trylock deadlock (WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability classified as critical was found in Linux Kernel up to 6.18.13/6.19.3. The affected element is the function netdev_trylock. Such manipulation leads to deadlock.
This vulnerability is documented as CVE-2026-45907. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45908 | Linux Kernel up to 6.18.13/6.19.3 amdxdna amdxdna_ubuf_map memory leak (WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.13/6.19.3. The impacted element is the function amdxdna_ubuf_map of the component amdxdna. Performing a manipulation results in memory leak.
This vulnerability is reported as CVE-2026-45908. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-45906 | Linux Kernel up to 6.19.3 IRQ power_supply_changed use after free (WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability has been found in Linux Kernel up to 6.19.3 and classified as critical. Affected is the function power_supply_changed of the component IRQ Handler. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-45906. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45904 | Linux Kernel up to 6.19.3 EEH Driver pci_lock_rescan_remove do_lock deadlock (WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability has been found in Linux Kernel up to 6.19.3 and classified as critical. This vulnerability affects the function pci_lock_rescan_remove of the component EEH Driver. This manipulation of the argument do_lock causes deadlock.
This vulnerability is handled as CVE-2026-45904. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45905 | Linux Kernel up to 6.19.3 net/ipv4/route.c icmp_route_lookup information exposure (WID-SEC-2026-1700)
5 days 12 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.164/6.6.127/6.12.74/6.18.13/6.19.3. Affected by this issue is the function icmp_route_lookup of the file net/ipv4/route.c. Such manipulation leads to information exposure through error message.
This vulnerability is listed as CVE-2026-45905. The attack must be carried out locally. There is no available exploit.
You should upgrade the affected component.
vuldb.com
苹果宣布将废弃AirPort实用工具 不过暂时只是警告没有给出具体停用日期
5 days 12 hours ago
2026年6月23日 09:00软件资讯01.12K