Aggregator
Submit #816075: GPAC MP4Box <= 2.4.0 (master commit 7508ccc and earlier) Null pointer dereference (Denial of Service) [Accepted]
Submit #815798: Teable < release.2026-04-21T08-57-20Z.1513 DOM-Based XSS, Open Redirect [Accepted]
Critical Memcached SASL Vulnerability Let Attackers Infer Valid Usernames
A newly disclosed security issue in Memcached has raised concerns after developers confirmed a timing side-channel vulnerability in its SASL authentication mechanism that could allow attackers to infer valid usernames, now tracked as CVE‑2026‑47783. The flaw was addressed in the recently released Memcached version 1.6.42, a security-focused update that fixes multiple critical bugs affecting stability […]
The post Critical Memcached SASL Vulnerability Let Attackers Infer Valid Usernames appeared first on Cyber Security News.
共研智能体岗位标准 360牵头推进AI人才规范化发展!
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)
Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required. “The attack complexity is Low (AC:L) because … More →
The post High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) appeared first on Help Net Security.
CVE-2026-9565 | haojing8312 WorkClaw up to 0.6.4 Blacklist bash.rs is_dangerous os command injection
Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates
A newly disclosed vulnerability in Apache CXF, tracked as CVE-2026-44930, is raising concerns among enterprise users relying on its XKMS (XML Key Management Specification) services. The flaw, classified as an important severity issue, affects the LDAP-based certificate repository component and could allow attackers to retrieve arbitrary digital certificates from vulnerable systems. Apache CXF is widely […]
The post Apache CXF LDAP Injection Vulnerability Let Attacker Retrieve Arbitrary Certificates appeared first on Cyber Security News.
CVE-2026-9564 | SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0 view_patient Remarks cross site scripting
CVE-2026-9562 | sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5 Dashboard access control
Submit #815713: haojing8312 WorkClaw v0.1.0 - v0.6.3 Incomplete Blacklist [Accepted]
ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks
ConnectWise has disclosed a high-impact security vulnerability in its Automate platform that could allow attackers to bypass critical security checks and execute malicious code under specific conditions. The flaw, tracked as CVE-2026-9089, affects versions of ConnectWise Automate before 2026.5 and has been assigned a CVSS score of 8.8, highlighting its potential severity in managed service […]
The post ConnectWise Automate Vulnerability Let Attackers Bypass Security Checks appeared first on Cyber Security News.