Aggregator
Обнаружен новый вид зависимости — люди сходят с ума от общения с ИИ
4 months ago
ChatGPT - это настоящий психологический вампир: высасывает разум и подкармливает паранойю.
Canada Goose investigating as hackers leak 600K customer records
4 months ago
ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data. Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and that it has not found evidence of a breach of its own systems. [...]
Ax Sharma
Firewall Penetration Testing: Definition, Process and Tools
4 months ago
Firewall penetration testing examines the firewall as a security control and identifies the weaknesses that allow unwanted traffic to reach internal systems. It helps to make the network secure by checking that inbound and outbound filtering rules block unwanted traffic correctly. It also protects the perimeter by keeping internal-to-external boundaries intact and preventing external probes […]
The post Firewall Penetration Testing: Definition, Process and Tools appeared first on Security Boulevard.
Harman Singh
CVE-2026-2361 | DALIBO PostgreSQL Anonymizer up to 3.0.0 anon.get_tablesample_ratio uncontrolled search path (News 617 / Nessus ID 298761)
4 months ago
A vulnerability, which was classified as problematic, was found in DALIBO PostgreSQL Anonymizer up to 3.0.0. This affects the function anon.get_tablesample_ratio. Such manipulation leads to uncontrolled search path.
This vulnerability is listed as CVE-2026-2361. The attack must be carried out locally. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-26079 | Roundcube Webmail up to 1.5.12/1.6.12 Cascading Style Sheet inclusion of functionality from untrusted control sphere (Nessus ID 298770 / CNNVD-202602-2040)
4 months ago
A vulnerability identified as problematic has been detected in Roundcube Webmail up to 1.5.12/1.6.12. Affected by this issue is some unknown functionality of the component Cascading Style Sheet Handler. This manipulation causes inclusion of functionality from untrusted control sphere.
This vulnerability is registered as CVE-2026-26079. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-2530 | Wavlink WL-WN579A3 up to 20210219 /cgi-bin/wireless.cgi AddMac macAddr command injection
4 months ago
A vulnerability identified as critical has been detected in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injection.
This vulnerability is tracked as CVE-2026-2530. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-2531 | MindsDB up to 25.14.1 File Upload security.py clear_filename server-side request forgery (Issue 12163)
4 months ago
A vulnerability labeled as critical has been found in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-2531. The attack may be performed from remote. In addition, an exploit is available.
It is best practice to apply a patch to resolve this issue.
vuldb.com
CVE-2026-2533 | Tosei Self-service Washing Machine 4.02 tosei_datasend.php adr_txt_1 command injection
4 months ago
A vulnerability described as critical has been identified in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing a manipulation of the argument adr_txt_1 can lead to command injection.
This vulnerability is registered as CVE-2026-2533. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-2534 | Comfast CF-N1 V2 2.6.0.2 mbox-config?method=SET§ion=ptest_bandwidth sub_44AC4C command injection
4 months ago
A vulnerability classified as critical has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_bandwidth. The manipulation of the argument bandwidth leads to command injection.
This vulnerability is documented as CVE-2026-2534. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-15569 | Artifex MuPDF up to 1.26.1 on Windows platform/x11/win_main.c get_system_dpi uncontrolled search path (ID 708617 / Nessus ID 298772)
4 months ago
A vulnerability was found in Artifex MuPDF up to 1.26.1 on Windows. It has been classified as problematic. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path.
This vulnerability appears as CVE-2025-15569. The attack requires local access. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-1849 | MongoDB Server up to 7.0.28/8.0.17/8.2.1 recursion (Nessus ID 298773 / WID-SEC-2026-0386)
4 months ago
A vulnerability classified as problematic has been found in MongoDB Server up to 7.0.28/8.0.17/8.2.1. This impacts an unknown function. The manipulation leads to uncontrolled recursion.
This vulnerability is referenced as CVE-2026-1849. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-1847 | MongoDB Server up to 7.0.28/8.0.17 Large Document Insert allocation of resources (Nessus ID 298783 / WID-SEC-2026-0386)
4 months ago
A vulnerability was found in MongoDB Server up to 7.0.28/8.0.17. It has been classified as problematic. This impacts an unknown function of the component Large Document Insert. This manipulation causes allocation of resources.
This vulnerability appears as CVE-2026-1847. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-25611 | MongoDB Server up to 7.0.28/8.0.17/8.2.3 Message amplification (Nessus ID 298779 / WID-SEC-2026-0386)
4 months ago
A vulnerability labeled as problematic has been found in MongoDB Server up to 7.0.28/8.0.17/8.2.3. The affected element is an unknown function of the component Message Handler. Such manipulation leads to asymmetric resource consumption.
This vulnerability is uniquely identified as CVE-2026-25611. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-2302 | MongoDB Ruby Driver up to 7.6.1/8.0.12/8.1.12/9.0.10 Mongoid::Criteria privilege escalation (Nessus ID 298776)
4 months ago
A vulnerability classified as critical was found in MongoDB Ruby Driver up to 7.6.1/8.0.12/8.1.12/9.0.10. Affected is the function Mongoid::Criteria. The manipulation results in privilege escalation.
This vulnerability is identified as CVE-2026-2302. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-1850 | MongoDB Server up to 8.0.17/8.2.3 allocation of resources (Nessus ID 298778 / WID-SEC-2026-0386)
4 months ago
A vulnerability has been found in MongoDB Server up to 8.0.17/8.2.3 and classified as problematic. This affects an unknown part. Performing a manipulation results in allocation of resources.
This vulnerability is cataloged as CVE-2026-1850. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-21218 | Microsoft .NET missing special element (Nessus ID 298781)
4 months ago
A vulnerability classified as problematic has been found in Microsoft .NET. The impacted element is an unknown function. This manipulation causes improper handling of missing special element.
This vulnerability appears as CVE-2026-21218. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2026-25612 | MongoDB Server up to 7.0.28/8.0.17/8.2.3 Internal Locking unrestricted externally accessible lock (Nessus ID 298784 / WID-SEC-2026-0386)
4 months ago
A vulnerability described as problematic has been identified in MongoDB Server up to 7.0.28/8.0.17/8.2.3. This affects an unknown part of the component Internal Locking. The manipulation results in unrestricted externally accessible lock.
This vulnerability is identified as CVE-2026-25612. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2022-49401 | Linux Kernel up to 5.18.2 page_owner lib/string_helpers.c strscpy buffer overflow (WID-SEC-2025-2107)
4 months ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 5.18.2. This vulnerability affects the function strscpy in the library lib/string_helpers.c of the component page_owner. Such manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2022-49401. The attack must be carried out from within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2022-49407 | Linux Kernel up to 5.18.2 send_op out-of-bounds (Nessus ID 235744 / WID-SEC-2025-2107)
4 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.18.2. This impacts the function send_op. Such manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2022-49407. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com