Aggregator
Memfit AI 长期记忆:让渗透 Agent 告别 “失忆”,练就实战肌肉记忆
2 months 2 weeks ago
C.O.R.E. P.A.C.T. 模型加持,跨越 AI 专家级最后一道坎
CVE-2026-5175 | Devolutions Server up to 2026.1.11 Multi-factor Authentication Management API authorization (DEVO-2026-0010 / WID-SEC-2026-0958)
2 months 2 weeks ago
A vulnerability has been found in Devolutions Server up to 2026.1.11 and classified as problematic. This impacts an unknown function of the component Multi-factor Authentication Management API. Performing a manipulation results in missing authorization.
This vulnerability was named CVE-2026-5175. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-4828 | Devolutions Server up to 2026.1.11 OAuth Login weak authentication (DEVO-2026-0010 / WID-SEC-2026-0958)
2 months 2 weeks ago
A vulnerability was found in Devolutions Server up to 2026.1.11. It has been declared as critical. This impacts an unknown function of the component OAuth Login. Executing a manipulation can lead to weak authentication.
This vulnerability is tracked as CVE-2026-4828. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-4924 | Devolutions Server up to 2026.1.11 2FA weak authentication (DEVO-2026-0010 / WID-SEC-2026-0958)
2 months 2 weeks ago
A vulnerability was found in Devolutions Server up to 2026.1.11. It has been rated as critical. Affected is an unknown function of the component 2FA. The manipulation leads to weak authentication.
This vulnerability is listed as CVE-2026-4924. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-4925 | Devolutions Server up to 2026.1.11 Users MFA Feature authorization (DEVO-2026-0010 / WID-SEC-2026-0958)
2 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in Devolutions Server up to 2026.1.11. Affected by this vulnerability is an unknown functionality of the component Users MFA Feature. The manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2026-4925. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-4927 | Devolutions Server up to 2026.1.11 Users MFA Feature insertion of sensitive information into sent data (DEVO-2026-0010 / WID-SEC-2026-0958)
2 months 2 weeks ago
A vulnerability classified as problematic has been found in Devolutions Server up to 2026.1.11. Impacted is an unknown function of the component Users MFA Feature. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is traded as CVE-2026-4927. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-3877 | VertiGIS FM up to 10.13.402 cross site scripting (WID-SEC-2026-0959)
2 months 2 weeks ago
A vulnerability classified as problematic was found in VertiGIS FM up to 10.13.402. Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-3877. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-4829 | Devolutions Server up to 2026.1.11 OAuth improper authentication (DEVO-2026-0010 / WID-SEC-2026-0958)
2 months 2 weeks ago
A vulnerability described as critical has been identified in Devolutions Server up to 2026.1.11. This issue affects some unknown processing of the component OAuth. Executing a manipulation can lead to improper authentication.
This vulnerability appears as CVE-2026-4829. The attack may be performed from remote. There is no available exploit.
vuldb.com
Nigerian romance scammer jailed after being caught out by fellow fraudster
2 months 2 weeks ago
「AI开源组件安全风险」系列二:VulnAgent发现 NVIDIA 3个AI基础设施漏洞,并获官方致谢
2 months 2 weeks ago
一、 引言:当AI基础设施成为攻击目标随着大语言模型(LLM)的爆发式发展,AI 训练和推理框架已成为支撑整
「AI开源组件安全风险」系列二:VulnAgent发现 NVIDIA 3个AI基础设施漏洞,并获官方致谢
2 months 2 weeks ago
腾讯安全云鼎实验室发现AI框架高危反序列化漏洞,获NVIDIA致谢!
Поиграл в "чистильщик" — получил root. NoVoice показала, как легко взломать Android
2 months 2 weeks ago
Вредоносный код NoVoice научился выживать после сброса настроек смартфона до заводских.
CVE-2024-23284 | Apple iOS/iPadOS Web Content ui layer (FEDORA-2024-7ee03010c5)
2 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Apple iOS and iPadOS. Affected by this issue is some unknown functionality of the component Web Content Handler. Such manipulation leads to improper restriction of rendered ui layers.
This vulnerability is uniquely identified as CVE-2024-23284. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2024-23284 | Apple Safari Web Content ui layer (FEDORA-2024-7ee03010c5)
2 months 2 weeks ago
A vulnerability has been found in Apple Safari and classified as critical. This affects an unknown part of the component Web Content Handler. Performing a manipulation results in improper restriction of rendered ui layers.
This vulnerability was named CVE-2024-23284. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2024-23284 | Apple macOS Web Content ui layer (FEDORA-2024-7ee03010c5)
2 months 2 weeks ago
A vulnerability was found in Apple macOS and classified as critical. This vulnerability affects unknown code of the component Web Content Handler. Executing a manipulation can lead to improper restriction of rendered ui layers.
The identification of this vulnerability is CVE-2024-23284. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-23284 | Apple watchOS Web Content ui layer (FEDORA-2024-7ee03010c5)
2 months 2 weeks ago
A vulnerability was found in Apple watchOS. It has been classified as critical. This issue affects some unknown processing of the component Web Content Handler. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is referenced as CVE-2024-23284. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-23286 | Apple visionOS Image buffer overflow
2 months 2 weeks ago
A vulnerability was found in Apple visionOS. It has been declared as critical. Impacted is an unknown function of the component Image Handler. The manipulation results in buffer overflow.
This vulnerability is identified as CVE-2024-23286. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23286 | Apple tvOS Image buffer overflow
2 months 2 weeks ago
A vulnerability was found in Apple tvOS. It has been rated as critical. The affected element is an unknown function of the component Image Handler. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2024-23286. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-23286 | Apple iOS/iPadOS Image buffer overflow
2 months 2 weeks ago
A vulnerability categorized as critical has been discovered in Apple iOS and iPadOS. The impacted element is an unknown function of the component Image Handler. Such manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2024-23286. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com