Aggregator
Submit #785881: NocoBase 2.0.23 Sandbox Issue [Accepted]
CVE-2026-6220 | HummerRisk up to 1.5.0 Video File Download URL ServerService.java ServerService.addServer streamIp server-side request forgery
CVE-2026-6219 | aandrew-me ytDownloader up to 3.20.2 Compressor Feature src/compressor.js child_process.exec command injection
Submit #785855: HummerRisk 1.5.0 Injection [Accepted]
Iran-Linked CyberAv3ngers Sets Sights on Water Utilities and Industrial Controllers
An Iran-backed cyber threat group called CyberAv3ngers has grown from a noise-making hacktivist outfit into a serious threat targeting critical infrastructure across the United States. The group, formally connected to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC), has been operating since at least 2020 and has steadily sharpened its tools and techniques with each […]
The post Iran-Linked CyberAv3ngers Sets Sights on Water Utilities and Industrial Controllers appeared first on Cyber Security News.
CVE-2026-6219 | aandrew-me ytDownloader up to 3.20.2 Compressor Feature src/compressor.js child_process.exec command injection
CVE-2026-6218 | aandrew-me ytDownloader up to 3.20.2 Error Details Panel createTextNode cross site scripting
Без слежки, без рекламы, без утечек. Что известно о XChat — новом мессенджере от Илона Маска
Submit #785844: Aandrew-me ytDownloader 3.20.2 Command Injection [Duplicate]
Submit #785843: Aandrew-me ytDownloader 3.20.2 Command Injection [Accepted]
Submit #785842: Aandrew-me ytDownloader 3.20.2 Remote code execution via DOM XSS [Accepted]
MacSync Stealer Campaign Impacting U.S. SLTT macOS Users
CVE-2026-36923 | SourceCodester Cab Management System 1.0 view_booking.php sql injection (EUVD-2026-21924)
CVE-2026-36922 | SourceCodester Cab Management System 1.0 view_category.php sql injection (EUVD-2026-21922)
CVE-2026-36920 | SourceCodester Online Reviewer System 1.0 questions-view.php sql injection (EUVD-2026-21920)
长期接触农药可能诱发糖尿病
CVE-2026-6216 | DbGate up to 7.1.4 SVG Icon String FontIcon.svelte applicationIcon cross site scripting
CVE-2026-6215 | DbGate up to 7.1.4 REST/GraphQL openApiDriver.ts apiServerUrl1 server-side request forgery
How Anthropic’s New AI Model Is Challenging Traditional Vulnerability Testing
There has been a vulnerability sitting in OpenBSD for 27 years. OpenBSD, the operating system specifically built with security as […]
The post How Anthropic’s New AI Model Is Challenging Traditional Vulnerability Testing appeared first on HawkEye.