Aggregator
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
2 months ago
Banks and financial institutions in Latin American countries like Brazil and Mexico have continued to be the target of a malware family called JanelaRAT.
A modified version of BX RAT, JanelaRAT is known to steal financial and cryptocurrency data associated with specific financial entities, as well as track mouse inputs, log keystrokes, take screenshots, and collect system metadata.
"One of the
The Hacker News
Почта для тех, кому есть что скрывать. Gmail разрешил шифровать письма с телефона, но только если вы за это заплатили
2 months ago
Gmail научился шифровать письма по-человечески.
CVE-2026-36946 | SourceCodester Computer and Mobile Repair Shop Management System 1.0 view_details.php sql injection (EUVD-2026-21966)
2 months ago
A vulnerability has been found in SourceCodester Computer and Mobile Repair Shop Management System 1.0 and classified as critical. This impacts an unknown function of the file /rsms/admin/inquiries/view_details.php. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2026-36946. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-36947 | SourceCodester Computer and Mobile Repair Shop Management System 1.0 view_service.php sql injection (EUVD-2026-21968)
2 months ago
A vulnerability was found in SourceCodester Computer and Mobile Repair Shop Management System 1.0 and classified as critical. Affected is an unknown function of the file /rsms/admin/services/view_service.php. Such manipulation leads to sql injection.
This vulnerability is listed as CVE-2026-36947. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-1462 | keras up to 3.13.1 TFSMLayer from_config deserialization (EUVD-2026-21970)
2 months ago
A vulnerability classified as critical was found in keras up to 3.13.1. This impacts the function from_config of the component TFSMLayer. The manipulation results in deserialization.
This vulnerability was named CVE-2026-1462. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-33858 | Apache Airflow up to 3.1.x deserialization (EUVD-2026-21978)
2 months ago
A vulnerability marked as critical has been reported in Apache Airflow up to 3.1.x. The affected element is an unknown function. Performing a manipulation results in deserialization.
This vulnerability is known as CVE-2026-33858. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-6182 | code-projects Simple Content Management System 1.0 /web/admin/login.php User sql injection (EUVD-2026-21980)
2 months ago
A vulnerability was found in code-projects Simple Content Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection.
This vulnerability is traded as CVE-2026-6182. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2026-36941 | SourceCodester Online Resort Management System 1.0 manage_room.php sql injection (EUVD-2026-21979)
2 months ago
A vulnerability described as critical has been identified in SourceCodester Online Resort Management System 1.0. The impacted element is an unknown function of the file /orms/admin/rooms/manage_room.php. Executing a manipulation can lead to sql injection.
This vulnerability is handled as CVE-2026-36941. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-6183 | code-projects Simple Content Management System 1.0 /web/index.php ID sql injection (EUVD-2026-21981)
2 months ago
A vulnerability was found in code-projects Simple Content Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection.
This vulnerability is known as CVE-2026-6183. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2026-33776 | Juniper Junos OS/Junos OS Evolved CLI Command authorization (JSA107866 / Nessus ID 305594)
2 months ago
A vulnerability was found in Juniper Junos OS and Junos OS Evolved and classified as problematic. Affected is an unknown function of the component CLI Command Handler. Such manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-33776. The attack needs to be performed locally. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-59969 | Juniper Junos OS Evolved on PTX evo-aftmand/evo-pfemand buffer overflow (JSA103159 / Nessus ID 305595)
2 months ago
A vulnerability has been found in Juniper Junos OS Evolved on PTX and classified as critical. The impacted element is an unknown function of the component evo-aftmand/evo-pfemand. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2025-59969. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-33787 | Juniper Junos OS up to 25.2R1-S1 CLI Command unusual condition (JSA107873 / Nessus ID 305597)
2 months ago
A vulnerability was found in Juniper Junos OS up to 25.2R1-S1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component CLI Command Handler. Performing a manipulation results in improper check for unusual conditions.
This vulnerability is reported as CVE-2026-33787. The attack requires a local approach. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-33779 | Juniper Junos OS up to 25.2R1-S2 on SRX Server Certificate Parser improper following of a certificate's chain of trust (JSA107823 / Nessus ID 305596)
2 months ago
A vulnerability marked as problematic has been reported in Juniper Junos OS up to 25.2R1-S2 on SRX. Affected by this issue is some unknown functionality of the component Server Certificate Parser. This manipulation causes improper following of a certificate's chain of trust.
This vulnerability is handled as CVE-2026-33779. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-33793 | Juniper Junos OS/Junos OS Evolved User Interface unnecessary privileges (JSA103142 / Nessus ID 305599)
2 months ago
A vulnerability categorized as critical has been discovered in Juniper Junos OS and Junos OS Evolved. This impacts an unknown function of the component User Interface. Executing a manipulation can lead to execution with unnecessary privileges.
This vulnerability appears as CVE-2026-33793. The attack requires local access. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-21916 | Juniper Junos OS up to 25.4R0 symlink (JSA107807 / Nessus ID 305598)
2 months ago
A vulnerability classified as critical was found in Juniper Junos OS up to 25.4R0. This issue affects some unknown processing. Executing a manipulation can lead to symlink following.
The identification of this vulnerability is CVE-2026-21916. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors
2 months ago
Anthropic’s Claude AI is facing a fresh wave of user-reported disruptions on April 13, 2026, with hundreds of users encountering intermittent HTTP 500 internal server errors across claude.ai, the API, and Claude Code, even as Anthropic’s official status page continues to show “All Systems Operational.” Reports began surfacing in community forums, including a thread on […]
The post Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors appeared first on Cyber Security News.
Guru Baran
CVE-2020-11022 | jQuery up to 3.4.x html cross site scripting (ID 162159 / EDB-49766)
2 months ago
A vulnerability described as problematic has been identified in jQuery up to 3.4.x. This vulnerability affects the function html. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2020-11022. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2020-11022 | Oracle Communications Analytics 12.1.1 Platform cross site scripting (EDB-49766 / Nessus ID 209233)
2 months ago
A vulnerability labeled as critical has been found in Oracle Communications Analytics 12.1.1. This issue affects some unknown processing of the component Platform. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2020-11022. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2020-11022 | Oracle Communications Element Manager 8.1.1/8.2.0/8.2.1 User Interface cross site scripting (EDB-49766 / Nessus ID 209233)
2 months ago
A vulnerability marked as critical has been reported in Oracle Communications Element Manager 8.1.1/8.2.0/8.2.1. Impacted is an unknown function of the component User Interface. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2020-11022. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
vuldb.com