Aggregator
Please support the site operations by clicking ads.
火绒小问答--「个人版」近期top问题解答
16 hours 31 minutes ago
火绒小问答--「个人版」近期top问题解答
火绒企业版2.0功能升级|跨平台漏洞检测上线 查杀支持断点续杀
16 hours 31 minutes ago
火绒企业版2.0功能升级|跨平台漏洞检测上线 查杀支持断点续杀
国家网信办发布近期网络安全、数据安全、个人信息保护等领域执法典型案例
16 hours 31 minutes ago
浏览器的"信任"被伪造:KREMLIN 攻破 Chrome 完整性校验,1500+ 巴西网银主机沦陷
16 hours 33 minutes ago
不上架应用商店、无需用户授权——攻击者伪造 Chromium 自身的完整性校验值,让浏览器“自愿”加载恶意扩展;C2 配置写入以太坊智能合约充当“死信箱”,1,515 台受感染主机已被观测,98.75% 位于巴西。
Submit #938556: pbootcmspro PbootCMS <=V3.2.22 Incomplete Denylist to Cross-Site Scripting [Accepted]
16 hours 33 minutes ago
Submit #938556 / VDB-405518
rockmelodeis
Submit #935194: wuzhicms <=4.1.0 SSRF [Accepted]
16 hours 47 minutes ago
Submit #935194 / VDB-405512
ZAST.AI
NIST and CISA finalize playbook to stop token theft and forgery
16 hours 51 minutes ago
NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR 8587), explains how agencies and cloud providers can strengthen key management, token verification, and token lifecycle controls. It also covers how identity providers and authorization servers should be designed and managed. “This publication provides implementation considerations for … More →
The post NIST and CISA finalize playbook to stop token theft and forgery appeared first on Help Net Security.
Anamarija Pogorelec
Fedora 45 Beta 释出
17 hours 5 minutes ago
Fedora 项目宣布释出 Fedora 45 Beta,正式版预计于 10 月 20 日释出。Fedora 45 的主要变化包括:用 kmscon 取代了内核控制台(in-kernel console),提供了更流畅的渲染,更出色的 Unicode 与字体支持,增强了系统稳定性;默认要求在安装前验证软件包签名的有效性,防止意外安装未签名的软件包;通过 oo7 标准化桌面密钥管理,取代了 GNOME Keyring 和 KWallet 等后端实现;软件方面的更新包括 GNOME 51,Go 1.27、Python 3.15、GCC 16.2、Glibc 2.44、LLVM 23、RPM 6.1 等等。
Submit #935193: wuzhicms <=4.1.0 SQL Injection [Duplicate]
17 hours 10 minutes ago
Submit #935193 / VDB-250342
ZAST.AI
CVE-2026-28609 | Google Android 14/15/16/16-qpr2 MatroskaExtractor.cpp out-of-bounds write
17 hours 11 minutes ago
A vulnerability classified as very critical has been found in Google Android 14/15/16/16-qpr2. Affected by this issue is some unknown functionality of the file MatroskaExtractor.cpp. Performing a manipulation results in out-of-bounds write.
This vulnerability was named CVE-2026-28609. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2026-28604 | Google Android up to 17 use after free
17 hours 11 minutes ago
A vulnerability classified as very critical was found in Google Android 14/15/16/16-qpr2/17. This affects an unknown part. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-28604. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2026-28603 | Google Android up to 17 AppRestrictionsFragment.java assertSafeToStartCustomActivity privileges management
17 hours 11 minutes ago
A vulnerability, which was classified as problematic, has been found in Google Android 14/15/16/16-qpr2/17. The affected element is the function assertSafeToStartCustomActivity of the file AppRestrictionsFragment.java. This manipulation causes improper privilege management.
The identification of this vulnerability is CVE-2026-28603. The attack can only be executed locally. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2026-28607 | Google Android 15/16/16-qpr2/17 privileges management
17 hours 11 minutes ago
A vulnerability, which was classified as very critical, was found in Google Android 15/16/16-qpr2/17. The impacted element is an unknown function. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-28607. The attack can only be performed from a local environment. No exploit is available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2026-28611 | Google Android 15/16 NFC Payment Session NfcService.java privileges management
17 hours 11 minutes ago
A vulnerability has been found in Google Android 15/16 and classified as very critical. This affects an unknown function of the file NfcService.java of the component NFC Payment Session. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2026-28611. The attack can be initiated remotely. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2026-28618 | Google Android 16/16-QPR2/17 oapv.c dec_frm_prepare heap-based overflow
17 hours 11 minutes ago
A vulnerability was found in Google Android 16/16-QPR2/17. It has been classified as very critical. Affected is the function dec_frm_prepare of the file oapv.c. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-28618. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2026-28616 | Google Android Setup Wizard privileges management
17 hours 11 minutes ago
A vulnerability was found in Google Android. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Setup Wizard. This manipulation causes improper privilege management.
This vulnerability is registered as CVE-2026-28616. The attack needs to be launched locally. No exploit is available.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2026-28617 | Google Android 15/16/16-qpr2/17 WifiNetworkSuggestionsManager WifiNetworkSuggestionsManager.java resource consumption
17 hours 11 minutes ago
A vulnerability categorized as problematic has been discovered in Google Android 15/16/16-qpr2/17. This affects an unknown part of the file WifiNetworkSuggestionsManager.java of the component WifiNetworkSuggestionsManager. Such manipulation leads to resource consumption.
This vulnerability is documented as CVE-2026-28617. The attack needs to be performed locally. There is not any exploit available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-28612 | Google Android 16/16-qpr2/17 ActivityStarter ActivityStarter.java resolveActivity redirect
17 hours 11 minutes ago
A vulnerability identified as problematic has been detected in Google Android 16/16-qpr2/17. This vulnerability affects the function resolveActivity of the file ActivityStarter.java of the component ActivityStarter. Performing a manipulation results in open redirect.
This vulnerability is reported as CVE-2026-28612. The attack is possible to be carried out remotely. No exploit exists.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2026-28613 | Google Android up to 17 ChannelImpl ChannelImpl.java initAppLinkTypeAndIntent input validation
17 hours 11 minutes ago
A vulnerability labeled as critical has been found in Google Android 14/15/16/16-qpr2/17. This issue affects the function initAppLinkTypeAndIntent of the file ChannelImpl.java of the component ChannelImpl. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2026-28613. The attack requires local access. There is no available exploit.
It is advisable to implement a patch to correct this issue.
vuldb.com