Aggregator
【Neo4j数据库取证技术】
3 weeks 5 days ago
基础认识、结构解析到实战操作
SecWiki News 2026-05-22 Review
3 weeks 5 days ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
HPE security advisory (AV26-500)
3 weeks 5 days ago
Canadian Centre for Cyber Security
攻击者如何迫使微软发送钓鱼邮件
3 weeks 5 days ago
攻击者热衷于利用合法平台,使用 Gamma、Canva 和谷歌云端硬盘等工具托管钓鱼页面及其他恶意内容。
cPanel security advisory (AV26-499)
3 weeks 5 days ago
Canadian Centre for Cyber Security
Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers
3 weeks 5 days ago
When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios.
Jeffrey Schwartz
Ubiquiti security advisory (AV26-498)
3 weeks 5 days ago
Canadian Centre for Cyber Security
CVE-2026-8992 | Ivanti Secure Access Client up to 22.8R5 certificate validation (EUVD-2026-31445)
3 weeks 5 days ago
A vulnerability has been found in Ivanti Secure Access Client up to 22.8R5 and classified as problematic. The impacted element is an unknown function. The manipulation leads to improper certificate validation.
This vulnerability is uniquely identified as CVE-2026-8992. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-8353 | Concrete CMS up to 9.5.0 cross site scripting
3 weeks 5 days ago
A vulnerability, which was classified as problematic, was found in Concrete CMS up to 9.5.0. The affected element is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-8353. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-8340 | Concrete CMS up to 9.5.0 edit_file_contents cross-site request forgery
3 weeks 5 days ago
A vulnerability, which was classified as problematic, has been found in Concrete CMS up to 9.5.0. Impacted is the function edit_file_contents. Performing a manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2026-8340. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-46371 | Dell PowerFlex Manager prior IC 48.378.00/IC 48.383.00 risky encryption (dsa-2025-434)
3 weeks 5 days ago
A vulnerability classified as problematic was found in Dell PowerFlex Manager. This issue affects some unknown processing. Such manipulation leads to risky cryptographic algorithm.
This vulnerability is traded as CVE-2025-46371. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-32751 | Dell PowerFlex Manager prior IC 48.378.00/IC 48.383.00 sensitive information (dsa-2025-434)
3 weeks 5 days ago
A vulnerability classified as problematic has been found in Dell PowerFlex Manager. This vulnerability affects unknown code. This manipulation causes insecure storage of sensitive information.
This vulnerability appears as CVE-2025-32751. The attack requires local access. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-8347 | Concrete CMS up to 9.5.0 authorization
3 weeks 5 days ago
A vulnerability described as problematic has been identified in Concrete CMS up to 9.5.0. This affects an unknown part. The manipulation results in authorization bypass.
This vulnerability is reported as CVE-2026-8347. The attack can be launched remotely. No exploit exists.
vuldb.com
Тихий океан становится не таким тихим. Хакеры атаковали американские заморские территории
3 weeks 5 days ago
Правительство Северных Марианских островов признало масштабный взлом инфраструктуры.
CVE-2026-9256 | F5 NGINX Plus/NGINX Open Source prior 37.0.1.1/R32 P7/R36 P5 ngx_http_rewrite_module heap-based overflow (K000161377)
3 weeks 5 days ago
A vulnerability marked as critical has been reported in F5 NGINX Plus and NGINX Open Source. Affected by this issue is some unknown functionality of the component ngx_http_rewrite_module. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-9256. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-45145 | Follett Destiny Library Manager up to 22.5 image path traversal
3 weeks 5 days ago
A vulnerability labeled as critical has been found in Follett Destiny Library Manager up to 22.5. Affected by this vulnerability is an unknown functionality. Executing a manipulation of the argument image can lead to path traversal.
This vulnerability is registered as CVE-2025-45145. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
Former US execs plead guilty to aiding tech support scammers
3 weeks 5 days ago
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]
Sergiu Gatlan
CVE-2021-21508 | Dell VxRail 4.7.410/4.7.411 log file
3 weeks 5 days ago
A vulnerability identified as problematic has been detected in Dell VxRail 4.7.410/4.7.411. Affected is an unknown function. Performing a manipulation results in sensitive information in log files.
This vulnerability is cataloged as CVE-2021-21508. The attack must be initiated from a local position. There is no exploit available.
You should upgrade the affected component.
vuldb.com
Microsoft Edge security advisory (AV26-497)
3 weeks 5 days ago
Canadian Centre for Cyber Security