Aggregator
Secure Your Spot at RSAC 2026 Conference
2 weeks 3 days hence
[Virtual Event] Shields Up: Key Technologies Reshaping Cybersecurity Defenses
1 week 6 days hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
42 minutes 18 seconds ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CVE-2026-3606 | Ettercap 0.8.4-Garofalo etterfilter ef_output.c add_data_segment out-of-bounds (Issue 1297)
2 hours 43 minutes ago
A vulnerability, which was classified as problematic, has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-3606. Local access is required to approach this attack. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
SmarterMain未授权RCE(CVE-2026-24423)漏洞代码分析
2 hours 44 minutes ago
漏洞描述这是SmarterMain的一个未授权RCE漏洞,出现RCE的位置为ConnectToHub API method,具体的漏洞描述如下图所示:环境搭建这里我直接用的docker搭建的环境,命令如下:然后是.net的反编译工具,我使用的是Rider以及dotPeet,这个就凭个人喜好下载了。漏洞代码分析因为.Net的路由大部分都在MailService.dll,所以可以直接看到这个dll中
CVE-2026-3009 | Keycloak IdentityBrokerService improper authentication
2 hours 47 minutes ago
A vulnerability classified as critical was found in Keycloak. Affected is an unknown function of the component IdentityBrokerService. Executing a manipulation can lead to improper authentication.
This vulnerability is handled as CVE-2026-3009. The attack can only be done within the local network. There is not any exploit available.
vuldb.com
CVE-2026-2603 | Keycloak SAML Identity Provider improper authentication
2 hours 47 minutes ago
A vulnerability classified as critical has been found in Keycloak. This impacts an unknown function of the component SAML Identity Provider Handler. Performing a manipulation results in improper authentication.
This vulnerability is known as CVE-2026-2603. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2026-2092 | Keycloak Encrypted SAML Assertion improper authorization
2 hours 47 minutes ago
A vulnerability described as critical has been identified in Keycloak. This affects an unknown function of the component Encrypted SAML Assertion. Such manipulation leads to improper authorization.
This vulnerability is traded as CVE-2026-2092. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-26377 | Koha up to 25.11 News cross site scripting
2 hours 49 minutes ago
A vulnerability marked as problematic has been reported in Koha up to 25.11. The impacted element is an unknown function of the component News. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-26377. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-64166 | mercurius-js mercurius up to 16.3.x Content-Type Header fetch cross-site request forgery (GHSA-v66j-6wwf-jc57)
2 hours 50 minutes ago
A vulnerability labeled as problematic has been found in mercurius-js mercurius up to 16.3.x. The affected element is the function fetch of the component Content-Type Header Handler. The manipulation of the argument Content-Type results in cross-site request forgery.
This vulnerability is reported as CVE-2025-64166. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-30793 | rustdesk-client RustDesk Client up to 1.4.5 URI flutter/lib/common.Dart MainSetPermanentPassword improper authorization
2 hours 50 minutes ago
A vulnerability identified as critical has been detected in rustdesk-client RustDesk Client up to 1.4.5. Impacted is the function MainSetPermanentPassword in the library flutter/lib/common.Dart of the component URI Handler. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-30793. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-30784 | rustdesk-server RustDesk Server up to 1.1.15/1.7.5 RegisterPeer handle_punch_hole_request authorization
2 hours 50 minutes ago
A vulnerability categorized as critical has been discovered in rustdesk-server RustDesk Server up to 1.1.15/1.7.5. This issue affects the function handle_punch_hole_request of the component RegisterPeer Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2026-30784. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-30785 | rustdesk-client RustDesk Client up to 1.4.5 UID Module password_security.Rs password recoverable
2 hours 50 minutes ago
A vulnerability was found in rustdesk-client RustDesk Client up to 1.4.5. It has been rated as problematic. This vulnerability affects the function symmetric_crypt/encrypt_str_or_original/decrypt_str_or_original/get_uuid/get_machine_id in the library hbb_common/src/lib.Rs of the file hbb_common/src/password_security.Rs of the component UID Module. Performing a manipulation results in storing passwords in a recoverable format.
This vulnerability is cataloged as CVE-2026-30785. The attack must be initiated from a local position. There is no exploit available.
vuldb.com
CVE-2026-30783 | rustdesk-client RustDesk Client up to 1.4.5 rendezvous_mediator.Rs client-side enforcement of server-side security
2 hours 51 minutes ago
A vulnerability was found in rustdesk-client RustDesk Client up to 1.4.5. It has been declared as critical. This affects an unknown part of the file src/rendezvous_mediator.Rs. Such manipulation leads to client-side enforcement of server-side security.
This vulnerability is listed as CVE-2026-30783. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-30798 | rustdesk-client RustDesk Client up to 1.4.5 src/hbbs_http/sync.Rs data authenticity
2 hours 52 minutes ago
A vulnerability was found in rustdesk-client RustDesk Client up to 1.4.5. It has been classified as problematic. Affected by this issue is some unknown functionality of the file src/hbbs_http/sync.Rs. This manipulation causes insufficient verification of data authenticity.
This vulnerability is tracked as CVE-2026-30798. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-30797 | rustdesk-client RustDesk Client up to 1.4.5 URI flutter/lib/common.Dart importConfig authorization
2 hours 53 minutes ago
A vulnerability was found in rustdesk-client RustDesk Client up to 1.4.5 and classified as critical. Affected by this vulnerability is the function importConfig in the library flutter/lib/common.Dart of the component URI Handler. The manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-30797. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-30790 | RustDesk Server Pro/RustDesk Server up to 1.7.5 src/server/connection.Rs excessive authentication
2 hours 53 minutes ago
A vulnerability has been found in RustDesk Server Pro and RustDesk Server up to 1.7.5 and classified as problematic. Affected is an unknown function of the file src/server/connection.Rs. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is referenced as CVE-2026-30790. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-30789 | rustdesk-client RustDesk Client up to 1.4.5 src/client.Rs hash_password authentication replay
2 hours 53 minutes ago
A vulnerability, which was classified as critical, was found in rustdesk-client RustDesk Client up to 1.4.5. This impacts the function hash_password of the file src/client.Rs. Executing a manipulation can lead to authentication bypass by capture-replay.
The identification of this vulnerability is CVE-2026-30789. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-25048 | mlc-ai xgrammar up to 0.1.31 recursion (GHSA-7rgv-gqhr-fxg3)
2 hours 54 minutes ago
A vulnerability, which was classified as problematic, has been found in mlc-ai xgrammar up to 0.1.31. This affects an unknown function. Performing a manipulation results in uncontrolled recursion.
This vulnerability was named CVE-2026-25048. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com