Aggregator
2026 字节跳动奖学金申请启动!首次开放全球申请,增加奖励名额
1 month ago
向未至处,探索智能边界
2026 字节跳动奖学金申请启动!首次开放全球申请,增加奖励名额
1 month ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2026-8051 | Ivanti Virtual Traffic Manager up to 22.9r3 os command injection (Nessus ID 315230)
1 month ago
A vulnerability, which was classified as critical, has been found in Ivanti Virtual Traffic Manager up to 22.9r3. Impacted is an unknown function. This manipulation causes os command injection.
The identification of this vulnerability is CVE-2026-8051. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8836 | lwIP up to 2.2.1 snmpv3 USM src/apps/snmp/snmp_msg.c snmp_parse_inbound_frame msgAuthenticationParameters stack-based overflow (Bug 68194 / Nessus ID 315227)
1 month ago
A vulnerability marked as critical has been reported in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow.
This vulnerability was named CVE-2026-8836. The attack may be initiated remotely. There is no available exploit.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2026-41702 | Vmware Fusion up to 25H2U1 toctou (EUVD-2026-30510 / Nessus ID 315231)
1 month ago
A vulnerability categorized as critical has been discovered in Vmware Fusion. This issue affects some unknown processing. Such manipulation leads to time-of-check time-of-use.
This vulnerability is listed as CVE-2026-41702. The attack must be carried out locally. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-43491 | Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3 SERVER Message qrtr_ns_worker resource consumption (Nessus ID 315312)
1 month ago
A vulnerability has been found in Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3 and classified as critical. This affects the function qrtr_ns_worker of the component SERVER Message Handler. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2026-43491. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
vuldb.com
Codex已经重置本周使用配额并将正常重置窗口顺延7天 至于重置原因暂时未知
1 month ago
CVE-2025-53892
1 month ago
Currently trending CVE - Hype Score: 33 - Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, ...
CVE-2026-42945
1 month ago
Currently trending CVE - Hype Score: 3 - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) ...
Сейф, золото и девушка в галстуке. 26-летний москвич под диктовку мошенников вынес из отцовского сейфа 13,3 миллиона рублей и пять золотых слитков
1 month ago
Мошенники убедили парня, что его аккаунт на «Госуслугах» взломан.
GitHub 内部仓库疑遭未授权访问,TeamPCP 据称正在出售 GitHub 内部源代码
1 month ago
事件仍在调查中
GitHub 内部仓库疑遭未授权访问,TeamPCP 据称正在出售 GitHub 内部源代码
1 month ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2022-28686 | AVEVA Edge uncontrolled search path (ZDI-22-1125 / EUVD-2022-33128)
1 month ago
A vulnerability was found in AVEVA Edge. It has been rated as critical. Impacted is an unknown function. The manipulation leads to uncontrolled search path.
This vulnerability is uniquely identified as CVE-2022-28686. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2022-28647 | Bentley MicroStation CONNECT 10.16.2.034 IFC File Parser out-of-bounds (ZDI-22-617 / EUVD-2022-33089)
1 month ago
A vulnerability, which was classified as problematic, was found in Bentley MicroStation CONNECT 10.16.2.034. Affected is an unknown function of the component IFC File Parser. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2022-28647. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2022-28645 | Bentley MicroStation CONNECT 10.16.02.34 DGN File Parser out-of-bounds (ZDI-22-610 / EUVD-2022-33087)
1 month ago
A vulnerability described as problematic has been identified in Bentley MicroStation CONNECT 10.16.02.34. Affected by this vulnerability is an unknown functionality of the component DGN File Parser. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2022-28645. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2022-28646 | Bentley MicroStation CONNECT 10.16.2.034 IFC File Parser out-of-bounds write (ZDI-22-616 / EUVD-2022-33088)
1 month ago
A vulnerability, which was classified as critical, has been found in Bentley MicroStation CONNECT 10.16.2.034. This impacts an unknown function of the component IFC File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2022-28646. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Non-Human Identities: The Next Security Blind Spot
1 month ago
Public NYC Health System Notifying 1.8M of Hack
1 month ago
Incident Involved an Unnamed Third-Party Vendor
New York City's municipal healthcare system is notifying nearly 2 million patients of a hacking incident discovered earlier this year involving a third-party vendor. The breach compromised a long list of information, including biometric data such as fingerprints.
New York City's municipal healthcare system is notifying nearly 2 million patients of a hacking incident discovered earlier this year involving a third-party vendor. The breach compromised a long list of information, including biometric data such as fingerprints.
Europe Prepares to Hunker Down Against Bug Finding AI Models
1 month ago
Commission VP Henna Virkkunen Pledges Action in Tuesday Parliamentary Session
The European Commission is defending its response to the advent of artificial intelligence models with strong cybersecurity bug dissecting capabilities while promising measures to protect the European Union from what many expect to be an imminent onslaught of AI-powered attacks.
The European Commission is defending its response to the advent of artificial intelligence models with strong cybersecurity bug dissecting capabilities while promising measures to protect the European Union from what many expect to be an imminent onslaught of AI-powered attacks.