Aggregator
安全热点周报:n8n 严重安全漏洞已遭利用,仍有 24700 个实例处于暴露状态
2 months 3 weeks ago
今日(2026年3月14日)OpenClaw 最新安全动态总结
2 months 3 weeks ago
斯特兰蒂斯与小米等商讨合作振兴欧洲业务
2 months 3 weeks ago
好,我需要帮用户总结这篇文章的内容,控制在100字以内。首先,文章主要讲的是斯特兰蒂斯与小米、小鹏等中国车企商讨合作,目的是振兴欧洲业务。斯特兰蒂斯的高管已经与这些公司的管理层会面,讨论了整改方案,包括收购旗下品牌如玛莎拉蒂的股份。此外,还涉及获取汽车制造产能,中国企业希望在欧洲扩大布局。最后,斯特兰蒂斯发表声明表示这是正常业务流程的一部分,并不对猜测置评。
接下来,我需要将这些信息浓缩到100字以内。要确保涵盖主要点:斯特兰蒂斯、小米、小鹏、欧洲业务振兴、合作讨论、收购股份、产能获取、企业布局扩大、声明回应。
可能的结构是:斯特兰蒂斯正与小米和小鹏等中国车企探讨合作,旨在振兴其欧洲业务。讨论内容包括收购旗下品牌股份及获取制造产能。斯特兰蒂斯对此表示这是正常业务流程的一部分。
这样大约70字左右,符合要求。
斯特兰蒂斯正与小米和小鹏等中国车企探讨合作,以振兴其欧洲业务。双方讨论了收购旗下品牌股份及获取制造产能的可能性。斯特兰蒂斯对此表示这是正常业务流程的一部分。
В Москве запустили «белые списки» сайтов на фоне отключений интернета. Что это значит и как теперь всё работает
2 months 3 weeks ago
Ограничения мобильного интернета в Москве действуют с 6 марта.
CVE-2025-70129 | PluXml up to 5.8.22 Anti Spam-Captcha (Nessus ID 302206)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in PluXml up to 5.8.22. Affected is an unknown function of the component Anti Spam-Captcha. The manipulation results in an unknown weakness.
This vulnerability is cataloged as CVE-2025-70129. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-22248 | GLPI up to 11.0.4 PHP Instantiation deserialization (Nessus ID 302205)
2 months 3 weeks ago
A vulnerability was found in GLPI up to 11.0.4. It has been classified as problematic. This impacts an unknown function of the component PHP Instantiation. This manipulation causes deserialization.
This vulnerability is registered as CVE-2026-22248. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-3846 | Mozilla Firefox up to 148.0.1 CSS Parser cross-domain policy (EUVD-2026-10504 / Nessus ID 302204)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 148.0.1. Impacted is an unknown function of the component CSS Parser. Performing a manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is cataloged as CVE-2026-3846. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-31817 | OliveTin up to 3000.11.1 StartAction API saveLogs path traversal (GHSA-364q-w7vh-vhpc)
2 months 3 weeks ago
A vulnerability was found in OliveTin up to 3000.11.1. It has been rated as critical. This issue affects the function saveLogs of the component StartAction API. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-31817. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-70802 | Tenda G1V3.1si 3.1si/16.01.7.8 /etc_ro/shadow hard-coded password
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Tenda G1V3.1si 3.1si/16.01.7.8. This issue affects some unknown processing of the file /etc_ro/shadow. Performing a manipulation results in use of hard-coded password.
This vulnerability is identified as CVE-2025-70802. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-3943 | H3C ACG1000-AK230 up to 20260227 ?aaa_portal_auth_local_submit suffix command injection
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in command injection.
This vulnerability is reported as CVE-2026-3943. The attack can be launched remotely. Moreover, an exploit is present.
The vendor is investigating and remediating this issue.
vuldb.com
CVE-2026-3944 | itsourcecode University Management System 1.0 /att_add.php Name sql injection
2 months 3 weeks ago
A vulnerability has been found in itsourcecode University Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /att_add.php. This manipulation of the argument Name causes sql injection.
This vulnerability appears as CVE-2026-3944. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2024-14026 | QNAP QTS/QuTS hero os command injection (qsa-24-54)
2 months 3 weeks ago
A vulnerability classified as critical has been found in QNAP QTS and QuTS hero. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is listed as CVE-2024-14026. It is possible to launch the attack on the physical device. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-14024 | QNAP Video Station up to 5.8.1 certificate validation (qsa-24-24)
2 months 3 weeks ago
A vulnerability classified as critical was found in QNAP Video Station up to 5.8.1. This vulnerability affects unknown code. The manipulation results in improper certificate validation.
This vulnerability is cataloged as CVE-2024-14024. An attack on the physical device is feasible. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-14025 | QNAP Video Station up to 5.8.1 sql injection (qsa-24-24)
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in QNAP Video Station up to 5.8.1. This issue affects some unknown processing. This manipulation causes sql injection.
This vulnerability is registered as CVE-2024-14025. It is feasible to perform the attack on the physical device. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-3805 | cURL up to 8.18.0 SMB Request use after free (Nessus ID 302096 / WID-SEC-2026-0690)
2 months 3 weeks ago
A vulnerability classified as critical has been found in cURL up to 8.18.0. Impacted is an unknown function of the component SMB Request Handler. This manipulation causes use after free.
This vulnerability is tracked as CVE-2026-3805. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-32060 | OpenClaw up to 2026.2.14 apply_patch path traversal
2 months 3 weeks ago
A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.2.14. The affected element is the function apply_patch. The manipulation results in path traversal.
This vulnerability is known as CVE-2026-32060. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-32061 | OpenClaw up to 2026.2.16 path traversal
2 months 3 weeks ago
A vulnerability labeled as critical has been found in OpenClaw up to 2026.2.16. This affects an unknown function. Such manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-32061. Local access is required to approach this attack. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-1965 | cURL up to 8.18.0 Negotiate-authenticated Request authentication bypass (Nessus ID 302096 / WID-SEC-2026-0690)
2 months 3 weeks ago
A vulnerability categorized as problematic has been discovered in cURL. Affected by this vulnerability is an unknown functionality of the component Negotiate-authenticated Request Handler. Such manipulation leads to authentication bypass by primary weakness.
This vulnerability is uniquely identified as CVE-2026-1965. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-3783 | cURL up to 8.18.0 OAuth2 Bearer Token insufficiently protected credentials (Nessus ID 302096 / WID-SEC-2026-0690)
2 months 3 weeks ago
A vulnerability labeled as problematic has been found in cURL. This affects an unknown part of the component OAuth2 Bearer Token Handler. Executing a manipulation can lead to insufficiently protected credentials.
The identification of this vulnerability is CVE-2026-3783. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com