Aggregator
CVE-2026-43433 | Linux Kernel up to 6.18.18/6.19.8 rust_binder toctou (Nessus ID 315710)
3 weeks 6 days ago
A vulnerability was found in Linux Kernel up to 6.18.18/6.19.8. It has been classified as critical. This vulnerability affects unknown code of the component rust_binder. The manipulation leads to time-of-check time-of-use.
This vulnerability is referenced as CVE-2026-43433. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-43455 | Linux Kernel up to 6.19.8 mctp_flow_prepare_output deserialization (Nessus ID 315711)
3 weeks 6 days ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.166/6.6.129/6.12.77/6.18.18/6.19.8. This affects the function mctp_flow_prepare_output. Such manipulation leads to deserialization.
This vulnerability is documented as CVE-2026-43455. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-43322 | Linux Kernel up to 6.19.11 Bluetooth le_read_features_complete use after free (Nessus ID 315712)
3 weeks 6 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.11. Affected is the function le_read_features_complete of the component Bluetooth. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-43322. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-43335 | Linux Kernel up to 6.19.11 interconnect null pointer dereference (Nessus ID 315714)
3 weeks 6 days ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.19.11. The affected element is an unknown function of the component interconnect. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-43335. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-43462 | Linux Kernel up to 6.18.18/6.19.8 net emac_tx_mem_map privilege escalation (Nessus ID 315715)
3 weeks 6 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.18/6.19.8. This issue affects the function emac_tx_mem_map of the component net. Performing a manipulation results in privilege escalation.
This vulnerability was named CVE-2026-43462. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
【安全事件】axios前端库npm供应链投毒预警通告
3 weeks 6 days ago
阅读: 13通告编号:NS-2026-0008TAG:axios、npm、供应链攻击危害程度:高版本:1.0
CVE-2026-8368 | OALDERS LWP::UserAgent up to 6.82 on Perl insufficiently protected credentials (Nessus ID 315716)
3 weeks 6 days ago
A vulnerability classified as problematic was found in OALDERS LWP::UserAgent up to 6.82 on Perl. This issue affects some unknown processing. The manipulation results in insufficiently protected credentials.
This vulnerability was named CVE-2026-8368. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-47372 | RRWO Crypt::SaltedHash up to 0.09 on Perl rand weak prng (Nessus ID 316023)
3 weeks 6 days ago
A vulnerability marked as problematic has been reported in RRWO Crypt::SaltedHash up to 0.09 on Perl. This affects the function rand. Performing a manipulation results in cryptographically weak prng.
This vulnerability is reported as CVE-2026-47372. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.
vuldb.com
【安全更新】微软4月安全更新多个产品高危漏洞通告
3 weeks 6 days ago
阅读: 18通告编号:NS-2026-0009TAG:安全更新、Windows、Office、Visual Studio、SQL Server
从 Codex Windows Sandbox 引发的一些终端安全思考
3 weeks 6 days ago
3月4号面试了安克创新的【终端安全专家】岗位,不过面试结果是挂了。通过面试复盘发现面试时长只有15分钟,但回答基本没有到位。
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
3 weeks 6 days ago
A sweeping automated supply chain attack codenamed “Megalodon” struck GitHub on May 18, 2026, injecting malicious CI/CD backdoors into over 5,500 repositories in less than six hours, marking one of the most aggressive GitHub Actions poisoning campaigns ever recorded. SafeDep discovered that between approximately 11:36 and 17:48 UTC on May 18, 2026, the Megalodon campaign […]
The post Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours appeared first on Cyber Security News.
Guru Baran
SpaceX计划在得州奥斯丁附近建设一座10吉瓦太阳能工厂
3 weeks 6 days ago
SpaceX计划在得州奥斯丁附近建设一座10吉瓦太阳能工厂据悉 SpaceX 正计划在美国得克萨斯州奥斯汀附近建造一座规模庞大的10吉瓦 (GW) 太阳能制造工厂。此举是马斯克旨在为外太空人工智能(A
方便高效!飞书加密文在线“解密预览”
3 weeks 6 days ago
阅读: 1飞书作为当下热门主流协同办公软件,凭借简洁流畅的操作体验与全面实用的办公功能,如今被越来越多企业与职场人士广泛选用,成为日常办公
后知后觉:腾讯TIM PC客户端竟然已经被弃用 显示版本过低无法登录
3 weeks 6 days ago
2026年5月22日 10:21软件资讯01.46K
【安全事件】Xinference PyPI遭供应链投毒预警通告
3 weeks 6 days ago
阅读: 2文档编号 NS-2026-0010TAG:Xinference、PyPI、供应链攻击危害程度:高版本:1.0
CVE-2026-43494 | Linux Kernel up to 7.1-rc3 rds iov_iter_get_pages2 infinite loop (EUVD-2026-31267 / Nessus ID 316034)
3 weeks 6 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.1-rc3. The impacted element is the function iov_iter_get_pages2 of the component rds. The manipulation leads to infinite loop.
This vulnerability is traded as CVE-2026-43494. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
【已复现】Linux内核权限提升漏洞(CVE-2026-31431)
3 weeks 6 days ago
阅读: 4通告编号 NS-2026-0011TAG:Linux、kernel、CVE-2026-31431漏洞危害
注意喚起: Palo Alto Networks製PAN-OSにおける認証回避の脆弱性(CVE-2026-0265)に関する注意喚起 (公開)
3 weeks 6 days ago
【漏洞通告】Linux内核权限提升漏洞(Dirty Frag)
3 weeks 6 days ago
阅读: 15通告编号 NS-2026-0012TAG:Linux、kernel、Dirty Frag漏洞危害:攻