Aggregator
CVE-2025-67246 | Ludashi Driver prior 5.1025 IOCTL information disclosure
CVE-2021-47799 | Visual-Tools Visual Tools DVR VX16 4.2.28 sudo Setting privileges assignment (Exploit 50104 / EDB-50104)
CVE-2021-47843 | Tagstoo 2.0.1 cross site scripting (Exploit 49828 / EDB-49828)
CVE-2021-47784 | Cyberfox Web Browser 52.9.1 allocation of resources (Exploit 50336 / EDB-50336)
CVE-2021-47781 | Cmder Console Emulator 1.3.18 out-of-bounds write (Exploit 50401 / EDB-50401)
CVE-2021-47777 | Ribccs Build Smart ERP 21.0817 Login Validation Endpoint eidValue sql injection (Exploit 50445 / EDB-50445)
CVE-2025-66417 | glpi up to 11.0.2 Inventory Endpoint sql injection
CVE-2025-66292 | donknap dpanel up to 1.9.1 attach.go path path traversal
CVE-2021-47774 | En Kingdia CD Extractor 3.0.2 registration name out-of-bounds write (Exploit 50470 / EDB-50470)
CVE-2026-22265 | Roxy-WI up to 8.2.8.2 logs.py grep os command injection
Amarillo College Panhandle Regional Law Enforcement Academy Allegedly Breached, Exposing 11,253 Event Registration Records
Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center
A high-severity vulnerability in Windows Admin Center’s Azure Single Sign-On implementation has exposed Azure virtual machines and Arc-connected systems to unauthorized access across entire tenants. Cymulate Research Labs discovered the flaw, now tracked as CVE-2026-20965, which demonstrates how improper token validation can collapse security boundaries between individual machines and complete Azure environments. Microsoft patched the […]
The post Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center appeared first on Cyber Security News.
Аста ла виста, бейби. Microsoft официально закрыла историю самой спорной Windows
科技云报到:个人AI时代,超级智能体如何真正为你而来?
PatrickStash Database Allegedly Leaked with 1,980 Chilean Credit Cards at 85% Validity
Global Agencies Release New Guidance to Secure Industrial Networks
Critical WhisperPair flaw lets hackers track, eavesdrop via Bluetooth audio devices
Critical flaw lets hackers track, eavesdrop via Bluetooth audio devices
Google Ends Dark Web Report. What That Means and How to Stay Safe
Google has officially discontinued its Dark Web Report, the tool that alerted users when their personal information appeared in dark web breach...
The post Google Ends Dark Web Report. What That Means and How to Stay Safe appeared first on McAfee Blog.