Aggregator
议题分享: When ASUS IoT Devices Play Hide-and-Seek with Security
4 months 1 week ago
Swing
CVE-2025-32023 Redis 漏洞分析
4 months 1 week ago
Swing
TP-Link WR841N router CVE-2023-50224 and CVE-2025-9377
4 months 1 week ago
Swing
CVE-2026-25581 | samclarke SCEditor up to 3.2.0 Configuration sceditor.create cross site scripting (GHSA-25fq-6qgg-qpj8 / EUVD-2026-5575)
4 months 1 week ago
A vulnerability categorized as problematic has been discovered in samclarke SCEditor up to 3.2.0. This affects the function sceditor.create of the component Configuration Handler. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-25581. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-2067 | UTT 进取 520W 1.7.7-180627 formTimeGroupConfig strcpy year1 buffer overflow (EUVD-2026-5572)
4 months 1 week ago
A vulnerability identified as critical has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 leads to buffer overflow.
This vulnerability is listed as CVE-2026-2067. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-25580 | pydantic pydantic-ai up to 1.55.x server-side request forgery (GHSA-2jrp-274c-jhv3 / EUVD-2026-5574)
4 months 1 week ago
A vulnerability, which was classified as critical, was found in pydantic pydantic-ai up to 1.55.x. The impacted element is an unknown function. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-25580. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-25574 | payloadcms payload up to 3.73.x authorization (EUVD-2026-5571)
4 months 1 week ago
A vulnerability has been found in payloadcms payload up to 3.73.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to authorization bypass.
This vulnerability is referenced as CVE-2026-25574. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-25544 | payloadcms payload up to 3.72.x sql injection (EUVD-2026-5570)
4 months 1 week ago
A vulnerability was found in payloadcms payload up to 3.72.x and classified as critical. Affected by this issue is some unknown functionality. The manipulation results in sql injection.
This vulnerability is identified as CVE-2026-25544. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-25628 | Qdrant up to 1.15.x /logger on_disk.log_file file inclusion (GHSA-f632-vm87-2m2f / EUVD-2026-5567)
4 months 1 week ago
A vulnerability was found in Qdrant up to 1.15.x. It has been classified as problematic. Affected is an unknown function of the file /logger. The manipulation of the argument on_disk.log_file leads to file inclusion.
This vulnerability is listed as CVE-2026-25628. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-25732 | zauberzeug NiceGUI up to 3.6.x path traversal (EUVD-2026-5568)
4 months 1 week ago
A vulnerability, which was classified as critical, has been found in zauberzeug NiceGUI up to 3.6.x. This impacts an unknown function. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-25732. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-22226 | TP-Link Archer BE230 1.2.4 VPN Server Configuration os command injection (EUVD-2026-5089)
4 months 1 week ago
A vulnerability classified as critical was found in TP-Link Archer BE230 1.2.4. The affected element is an unknown function of the component VPN Server Configuration Module. Executing a manipulation can lead to os command injection.
This vulnerability is handled as CVE-2026-22226. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-22222 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5097)
4 months 1 week ago
A vulnerability was found in TP-Link Archer BE230 1.2.4. It has been rated as critical. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is listed as CVE-2026-22222. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-0631 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5098)
4 months 1 week ago
A vulnerability was found in TP-Link Archer BE230 1.2.4. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-0631. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-22221 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5100)
4 months 1 week ago
A vulnerability was found in TP-Link Archer BE230 1.2.4. It has been declared as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to os command injection.
This vulnerability is tracked as CVE-2026-22221. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-22227 | TP-Link Archer BE230 1.2.4 Configuration Backup os command injection (EUVD-2026-5084)
4 months 1 week ago
A vulnerability, which was classified as critical, has been found in TP-Link Archer BE230 1.2.4. The impacted element is an unknown function of the component Configuration Backup Handler. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-22227. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-22223 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5086)
4 months 1 week ago
A vulnerability categorized as critical has been discovered in TP-Link Archer BE230 1.2.4. This vulnerability affects unknown code. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-22223. The attack must originate from the local network. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
Ваш роутер за вами шпионит. И он делает это (как минимум) последние пять лет
4 months 1 week ago
Специалисты обнаружили платформу DKnife, предназначенную для перехвата трафика на уровне сетевого оборудования.
观点 | 人工智能会犯错吗?
4 months 1 week ago
在技术革命与产业变革的双重驱动下,人工智能正以前所未有的广度与深度渗透至工作、学习、医疗、交通等社会生活的各个领域,成为重塑人类文明形态与推动社会转型的重要力量。
前沿 | 人工智能百花齐放背后的中国创新密码
4 months 1 week ago
世界主要经济体也在以国家战略进行系统布局,支持人工智能发展,推动“无形的手”和“有形的手”协同配合已成为全球各国的通行做法。因此,我们必须更好把握政府和市场的关系,让这“两只手”紧密协同、高效配合,在人工智能这场关乎未来的竞赛中赢得主动。