Posts of last few hours
A vulnerability categorized as problematic has been discovered in Red Hat Advanced Cluster Management for Kubernetes. Affected is an unknown function of the component search-indexer. Executing a manipulation can lead to improper synchronization.
This vulnerability is handled as CVE-2026-76827. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/393437
A vulnerability identified as problematic has been detected in ash-project ash up to 3.32.0. Affected by this issue is the function apply_constraints of the file lib/ash/type/string.ex of the component String Length Validation. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2026-82752. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/399346
A vulnerability identified as problematic has been detected in Tcpdump Group libpcap up to 1.10.6. This issue affects some unknown processing of the component BPF Interpreter. The manipulation leads to divide by zero.
This vulnerability is traded as CVE-2026-6244. An attack has to be approached locally. There is no exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/399360
A vulnerability categorized as problematic has been discovered in Tcpdump Group libpcap up to 1.10.6. This vulnerability affects unknown code of the component BPF Interpreter. Executing a manipulation can lead to buffer overflow.
This vulnerability appears as CVE-2026-31912. The attack requires local access. There is no available exploit.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/399359
A vulnerability was found in Tcpdump Group libpcap up to 1.10.6. It has been rated as critical. This affects the function abort of the component BPF Interpreter. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2026-31911. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
https://vuldb.com/vuln/399358
A vulnerability was found in Tcpdump Group libpcap up to 1.9.x/1.10.6. It has been declared as critical. Affected by this issue is some unknown functionality. Such manipulation leads to memory leak.
This vulnerability is documented as CVE-2026-18313. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/399357
A vulnerability was found in Tcpdump Group libpcap up to 1.8.x/1.9.x/1.10.6. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Packet Message Handler. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2026-18238. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/399356
A vulnerability was found in code-projects Hotel and Tourism Reservation in PHP 1.0 and classified as problematic. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-86217. The attack may be launched remotely. Furthermore, there is an exploit available.
https://vuldb.com/vuln/399355
A vulnerability has been found in code-projects Hotel and Tourism Reservation in PHP 1.0 and classified as problematic. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting.
This vulnerability is listed as CVE-2026-86216. The attack may be initiated remotely. In addition, an exploit is available.
https://vuldb.com/vuln/399354
A vulnerability, which was classified as problematic, was found in Tcpdump Group libpcap up to 1.10.6. This affects an unknown function of the component BPF Interpreter. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is tracked as CVE-2026-0799. The attack is restricted to local execution. No exploit exists.
You should upgrade the affected component.
https://vuldb.com/vuln/399353
A vulnerability, which was classified as problematic, has been found in Tcpdump Group libpcap up to 1.10.6. The impacted element is an unknown function of the component BPF Interpreter. Performing a manipulation results in infinite loop.
This vulnerability is identified as CVE-2026-6554. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/399352
Submit #897301 / VDB-399355
https://vuldb.com/submit/897301
Submit #897300 / VDB-399354
https://vuldb.com/submit/897300
A vulnerability classified as problematic was found in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration.
This vulnerability is referenced as CVE-2026-86215. It is possible to launch the attack remotely. Furthermore, an exploit is available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
The project was informed of the problem early through an issue report but has not responded yet.
https://vuldb.com/vuln/399351
本文复现奶龙杯 CTF 中四道 Pwn 题目的解题过程,涵盖静态链接 ROP、栈对齐绕过、Seccomp 下自修改代码构造 ORW 链及格式化字符串泄露 Canary 结合栈溢出利用。
https://xz.aliyun.com/news/92716
仅持 USAGE 权限的账号,纯用 SQL 打穿 MariaDB:GRANT PROXY 空认证语义缺陷把 root 密码覆盖为空完成提权,SYS_REFCURSOR 游标数组 UAF 配合堆喷射与 JOP 链,容器内以 mysql 用户执行任意命令。含源码走读、修复 diff 与本机复现。
https://xz.aliyun.com/news/92718
Directus 默认 SSRF 黑名单只防了 AWS 那个 metadata 地址——国产云(腾讯云 169.254.0.23、阿里云 100.100.100.200)一个都没拦。链 A 用 editor 账号打 import 端点直接拉回实例指纹;链 B 用 Webhook Flow 零账号匿名触发。配套 import-ssrf-audit.py 加 --metadata-check 模式,3
https://xz.aliyun.com/news/92720
本文完整复盘了 HackTheBox Certificate 域靶机的渗透过程。攻击链始于 Web 端的文件上传功能: 利用 ZIP 打包加空字节截断绕过扩展名白名单与内容审查, 成功落地 WebShell 拿到初始立足点; 随后从数据库配置文件中提取凭据, 离线破解 bcrypt 弱口令, 横向至首个域用户; 接着分析目标遗留的流量包, 从 Kerberos AS-REP 报文中提取密文并爆破出
https://xz.aliyun.com/news/92721
FastGPT v4.14.8 沙箱四层防护(模块黑名单/AST 检查/open 守卫/import 守卫)全被一条 inspect 四步链穿透:currentframe().f_back.f_globals 拿到 worker 模块全局字典,直接调出 _original_open 读 /etc/passwd、_original_import 绕过黑名单。配套 fastgpt-sandbox-au
https://xz.aliyun.com/news/92724
Latest Blog Posts
- 1 week 6 days ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago