Aggregator
Qilin
1 day 2 hours ago
You must login to view this content
cohenido
US indicts Maryland man for 2021 theft of $54 million from Uranium Finance
1 day 2 hours ago
U.S. Attorney Jay Clayton said Spalletta “repeatedly hacked smart contracts to steal millions of dollars’ worth of other people’s money for himself, and destroyed a cryptocurrency exchange in the process.”
Cisco source code stolen in Trivy-linked dev environment breach
1 day 2 hours ago
Cisco has suffered a cyberattack after threat actors used stolen credentials from the recent Trivy supply chain attack to breach its internal development environment and steal source code belonging to the company and its customers. [...]
Lawrence Abrams
Alleged Dataset Leak of Canva Exposes 900,000 User Records With Bcrypt Passwords, OAuth Providers, and Design Platform Usage Data
1 day 2 hours ago
Alleged Dataset Leak of Canva Exposes 900,000 User Records With Bcrypt Passwords, OAuth Providers, and Design Platform Usage Data
Dark Web Informer
CVE-2025-71101 | Linux Kernel up to 6.6.119/6.12.63/6.18.3/6.19-rc3 _elements_from_package out-of-bounds (Nessus ID 299777)
1 day 2 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.119/6.12.63/6.18.3/6.19-rc3. This impacts the function _elements_from_package. Performing a manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2025-71101. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-71107 | Linux Kernel up to 6.6.119/6.12.63/6.18.2 f2fs_put_super reference count (WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.119/6.12.63/6.18.2. This affects the function f2fs_put_super. The manipulation leads to improper update of reference count.
This vulnerability is listed as CVE-2025-71107. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2025-71111 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 hwmon race condition (Nessus ID 298680 / WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. Affected by this vulnerability is an unknown functionality of the component hwmon. Such manipulation leads to race condition.
This vulnerability is documented as CVE-2025-71111. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-71106 | Linux Kernel up to 6.18.2 fs filesystems_freeze_callback denial of service (WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability classified as critical was found in Linux Kernel up to 6.18.2. This affects the function filesystems_freeze_callback of the component fs. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2025-71106. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-71109 | Linux Kernel up to 6.12.63/6.18.2 MIPS UASM_i_LA_mostly memory corruption (WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability has been found in Linux Kernel up to 6.12.63/6.18.2 and classified as critical. Impacted is the function UASM_i_LA_mostly of the component MIPS. This manipulation causes memory corruption.
This vulnerability is handled as CVE-2025-71109. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-71102 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 __scs_magic denial of service (Nessus ID 298680 / WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. It has been classified as critical. The impacted element is the function __scs_magic. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2025-71102. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-71103 | Linux Kernel up to 6.18.2/6.19-rc2 a7xx_patch_pwrup_reglist null pointer dereference (WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.2/6.19-rc2. This affects the function a7xx_patch_pwrup_reglist. Performing a manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-71103. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-71108 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 usb num_connectors state issue (Nessus ID 298924 / WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. This vulnerability affects unknown code of the component usb. Executing a manipulation of the argument num_connectors can lead to state issue.
This vulnerability is registered as CVE-2025-71108. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-71105 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 f2fs mm/slab_common.c inline_xattr_slab reference count (Nessus ID 284714 / WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. The affected element is the function inline_xattr_slab of the file mm/slab_common.c of the component f2fs. This manipulation causes improper update of reference count.
This vulnerability appears as CVE-2025-71105. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-71110 | Linux Kernel up to 6.18.2/6.19-rc1 defer_free use after free (WID-SEC-2026-0119)
1 day 2 hours ago
A vulnerability has been found in Linux Kernel up to 6.18.2/6.19-rc1 and classified as critical. This affects the function defer_free. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2025-71110. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
vuldb.com
Хищная птица вышла на охоту: дрон Airbus сбивает дронов в воздухе. Без человека. С ракетами
1 day 2 hours ago
Обнаружил. Сопроводил. Атаковал. Уничтожил.
Threat Actor Auctioning WordPress Admin Access to Spanish E-Commerce Site With REDSYS Payment Gateway and ~1,200 Monthly Card Orders
1 day 3 hours ago
Threat Actor Auctioning WordPress Admin Access to Spanish E-Commerce Site With REDSYS Payment Gateway and ~1,200 Monthly Card Orders
Dark Web Informer
CVE-2026-5104 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setStaticRoute ip command injection (EUVD-2026-17054 / CNNVD-202603-6020)
1 day 3 hours ago
A vulnerability described as critical has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ip leads to command injection.
This vulnerability is listed as CVE-2026-5104. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2026-5103 | Totolink A3300R 17.0.0cu.557_b20221024 /cgi-bin/cstecgi.cgi setUPnPCfg enable command injection (EUVD-2026-17053 / CNNVD-202603-6021)
1 day 3 hours ago
A vulnerability marked as critical has been reported in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection.
This vulnerability is tracked as CVE-2026-5103. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2026-3124 | wpchill Download Monitor Plugin up to 5.1.7 on WordPress executePayment authorization (EUVD-2026-17052 / CNNVD-202603-6022)
1 day 3 hours ago
A vulnerability identified as critical has been detected in wpchill Download Monitor Plugin up to 5.1.7 on WordPress. Impacted is the function executePayment. This manipulation causes authorization bypass.
The identification of this vulnerability is CVE-2026-3124. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com