Aggregator
Cracks in the Bedrock: Bypassing SCP Enforcement with Long-Lived API Keys
4 months ago
Introduction Following the release of Amazon Bedrock Powered by AWS Mantle, I discovered a mechanism to bypass Service Control Policy (SCP) statements limiting the use of bedrock-mantle IAM permissions. By leveraging long-lived API keys backed by Service Specific Credentials, I was able to successfully leverage bedrock-mantle:CreateInference despite an SCP statement denying that action. SCPs are […]
The post Cracks in the Bedrock: Bypassing SCP Enforcement with Long-Lived API Keys appeared first on Security Boulevard.
Adeel Nazar
CVE-2026-2227 | D-Link DCS-931L up to 1.13.0 /setSystemAdmin doSystem AdminID command injection
4 months ago
A vulnerability marked as critical has been reported in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2026-2227. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2025-70829 | Datart 1.0.0-rc.3 H2 JDBC Connection information disclosure
4 months ago
A vulnerability was found in Datart 1.0.0-rc.3. It has been classified as problematic. This issue affects some unknown processing of the component H2 JDBC Connection Handler. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2025-70829. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2023-38265 | IBM Cloud Pak System up to 2.1.0/2.3.3.7/2.3.4.0/2.3.4.1/2.3.5.0 exposure of information through directory listing
4 months ago
A vulnerability, which was classified as problematic, has been found in IBM Cloud Pak System up to 2.1.0/2.3.3.7/2.3.4.0/2.3.4.1/2.3.5.0. This issue affects some unknown processing. The manipulation leads to exposure of information through directory listing.
This vulnerability is documented as CVE-2023-38265. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-55853 | SoftVision webPDF up to 10.0.1 server-side request forgery
4 months ago
A vulnerability classified as critical has been found in SoftVision webPDF up to 10.0.1. This impacts an unknown function. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2025-55853. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-69674 | CData FD614GS3-R850 3.2.7_P161006 mesh_node_config/domiainblk_config domainblk buffer overflow
4 months ago
A vulnerability, which was classified as critical, was found in CData FD614GS3-R850 3.2.7_P161006. The impacted element is the function mesh_node_config/domiainblk_config. Executing a manipulation of the argument domainblk can lead to buffer overflow.
This vulnerability is handled as CVE-2025-69674. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-20144 | Splunk Enterprise/Cloud Platform prior 9.2.11/9.3.8/9.4.7/10.0.2 Search Head Cluster log file (SVD-2026-0209 / Nessus ID 299408)
4 months ago
A vulnerability, which was classified as problematic, has been found in Splunk Enterprise and Cloud Platform. This affects an unknown function of the component Search Head Cluster. This manipulation causes sensitive information in log files.
This vulnerability is registered as CVE-2026-20144. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-2441 | Google Chrome up to 145.0.7632.45 CSS use after free (ID 483569 / Nessus ID 299033)
4 months ago
A vulnerability has been found in Google Chrome and classified as critical. Affected by this issue is some unknown functionality of the component CSS. The manipulation leads to use after free.
This vulnerability is traded as CVE-2026-2441. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-41117 | Grafana/Grafana Enterprise up to 12.2.4/12.3.2 Jaeger HTTP API injection (Nessus ID 298909 / WID-SEC-2026-0405)
4 months ago
A vulnerability has been found in Grafana and Grafana Enterprise up to 12.2.4/12.3.2 and classified as problematic. This impacts an unknown function of the component Jaeger HTTP API. The manipulation leads to injection.
This vulnerability is documented as CVE-2025-41117. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-2327 | markdown-it up to 14.1.0 linkify redos (SNYK-JS-MARKDOWNIT-10666750 / Nessus ID 299039)
4 months ago
A vulnerability described as problematic has been identified in markdown-it up to 14.1.0. This impacts the function linkify. Such manipulation leads to inefficient regular expression complexity.
This vulnerability is listed as CVE-2026-2327. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-15577 | Valmet DNA Web Tools up to C2022 URL path traversal (EUVD-2025-206978)
4 months ago
A vulnerability, which was classified as critical, has been found in Valmet DNA Web Tools up to C2022. The impacted element is an unknown function of the component URL Handler. Performing a manipulation results in path traversal.
This vulnerability is cataloged as CVE-2025-15577. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-2225 | itsourcecode News Portal Project 1.0 Administrator Login /admin/index.php email sql injection
4 months ago
A vulnerability identified as critical has been detected in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection.
This vulnerability is handled as CVE-2026-2225. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2026-2171 | code-projects Online Student Management System 1.0 Login accounts.php username/password sql injection (EUVD-2026-5779)
4 months ago
A vulnerability identified as critical has been detected in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql injection.
This vulnerability is identified as CVE-2026-2171. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-25249 | Fortinet FortiSwitchManager/FortiSASE/FortiOS heap-based overflow (FG-IR-25-084 / EUVD-2026-2223)
4 months ago
A vulnerability, which was classified as critical, has been found in Fortinet FortiSwitchManager, FortiSASE and FortiOS. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2025-25249. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
Linux 7.0-rc1 释出
4 months ago
Linus Torvalds 在内核邮件列表上宣布释出 Linux 7.0-rc1。主要变化包括:支持英特尔即将推出的新 CPU Nova Lake 和 Diamond Rapids,以及 AMD Zen 6 CPU 及其下一代 GPU,高通 Snapdragon X2;增强文件系统,改进 exFAT 的顺序读取性能,EXT4 并发直接 I/O 写入性能;对 Rust 语言的支持不再是实验性质;等等。
Romanian hacker pleads guilty to selling access to Oregon state networks
4 months ago
A Romanian man pleaded guilty to selling admin access to Oregon’s state network for $3,000 in Bitcoin and repeatedly accessing it to prove control. Catalin Dragomir (45) from Romania, pleaded guilty in the U.S. for selling unauthorized admin access to an Oregon state emergency management network. He gained access in June 2021, advertised it, and […]
Pierluigi Paganini
Идеальный сотрудник: не просит страховку и спонсирует армию КНДР. В США вынесли приговор организатору схемы
4 months ago
Фигурант дела помогал гражданам КНДР работать на американском рынке удаленки.
雏鸡也存在 Bouba/Kiki 效应
4 months ago
人类会将无意义的单词与形状联系起来,比如 bouba 会与圆滑形状联系起来,而 kiki 会与尖角形状联系起来,这种语言学现象被称为 Bouba/Kiki 效应。根据发表在《科学》期刊上的一项研究,对刚出生雏鸡的测试显示,小鸡也存在 Bouba/Kiki 效应:刚出生 3 日的小鸡和刚出生 1 日的小鸡在听到 kiki 声音之后会自发选择尖角形状,听到 bouba 声音之后会选择圆滑形状。这一发现表明可能存在某种匹配形状和声音的先天机制,并且普遍存在于不同物种中,其历史渊源可能比我们以为的古老得多。
CVE-2026-3028 | erzhongxmu JEEWMS up to 3.7 JeecgListDemoController.java doAdd Name cross site scripting
4 months ago
A vulnerability, which was classified as problematic, has been found in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This manipulation of the argument Name causes cross site scripting.
This vulnerability appears as CVE-2026-3028. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com