Aggregator
CVE-2026-43824 | argoproj Argo CD up to 3.2.10/3.3.8 ServerSideDiff improper removal of sensitive information before storage or transfer (Duplicate CVE-2026-42880 / GHSA-3v3m-wc6v-x4x3)
1 month 2 weeks ago
A vulnerability, which was classified as problematic, has been found in argoproj Argo CD up to 3.2.10/3.3.8. The affected element is an unknown function of the component ServerSideDiff. Performing a manipulation results in improper removal of sensitive information before storage or transfer.
This vulnerability is known as CVE-2026-43824. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
This entry has a duplicate CVE-2026-42880 assigned.
vuldb.com
CVE-2026-8125 | code-projects Simple Chat System 1.0 sendMessage.php type/length/business parameter validity sql injection
1 month 2 weeks ago
A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipulation of the argument type/length/business parameter validity results in sql injection.
This vulnerability is cataloged as CVE-2026-8125. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
DirtyFrag漏洞细节及PoC已公开
1 month 2 weeks ago
一、 漏洞概述微步情报局监测到,Linux Kernel被披露存在本地权限提升漏洞,代号 “DirtyFrag
DirtyFrag漏洞细节及PoC已公开
1 month 2 weeks ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
nivel basico e ia
1 month 2 weeks ago
CVE-2022-25736 | Qualcomm Snapdragon Auto WLAN denial of service (EUVD-2022-30391)
1 month 2 weeks ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking. It has been declared as problematic. This impacts an unknown function of the component WLAN. The manipulation results in denial of service.
This vulnerability is known as CVE-2022-25736. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-25724 | Qualcomm Snapdragon Auto Graphics buffer overflow (EUVD-2022-30379)
1 month 2 weeks ago
A vulnerability has been found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music and Snapdragon Wearables and classified as critical. Affected is an unknown function of the component Graphics. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2022-25724. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2022-25727 | Qualcomm Snapdragon Consumer IOT memory corruption (EUVD-2022-30382)
1 month 2 weeks ago
A vulnerability classified as critical has been found in Qualcomm Snapdragon Consumer IOT, Snapdragon Industrial IOT and Snapdragon Voice & Music. This impacts an unknown function. The manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2022-25727. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
威胁猎人黑话词典2.0|打击欺诈行为,快速了解黑灰产黑话(信贷欺诈篇)
1 month 2 weeks ago
随着金融黑灰产持续升级,越来越多黑产开始通过“黑话”规避平台审查、组织协作与包装骗贷流程。威胁猎人结合长期黑灰产攻防经验,系统揭秘信贷欺诈场景中的高频黑话、隐藏角色与典型作恶链路,帮助金融机构更早识别潜在风险与异常作恶行为。
威胁猎人黑话词典2.0|打击欺诈行为,快速了解黑灰产黑话(信贷欺诈篇)
1 month 2 weeks ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
OpenAI推出新的“可信联系人”保障措施
1 month 2 weeks ago
周四,OpenAI宣布了一项名为 “可信联系人” 的新功能,旨在如果对话中表达了自残的提及,则提醒可信的第三方。该功能允许成年ChatGPT用户在其账户内将另一个人指定为可信联系人,例如朋友或家庭成员
万字复盘我家的装修过程,希望可以帮你避避坑
1 month 2 weeks ago
从 23 年 5 月到 26 年 5 月,历经 3 年时光,虽然软装还没有买,但也算是大致完成了新房的装修,回想期间种种,感慨万分。装修这 3 年,并非一直是高强度推进,而是断断续续,如同钝刀子割肉般
《中国信息安全》杂志2026年第4期目录
1 month 2 weeks ago
欢迎订阅《中国信息安全》杂志!
中国信息安全测评中心主任彭涛:智能向善守底线 信息安全护民生
1 month 2 weeks ago
当前,个人信息是数智时代新型生产要素的重要基石。海量个人信息的有序流动与高效运用,正持续释放澎湃数字动能,深刻重塑社会运行肌理和时代发展格局。但过度采集、非法滥用、信息倒卖、精准诈骗等风险隐患亦相伴而生,个人信息保护面临前所未有的严峻考验。
CVE-2026-41417 | Netty up to 4.1.132.Final/4.2.12.Final HTTP Request setUri crlf injection (GHSA-v8h7-rr48-vmmv / Nessus ID 313062)
1 month 2 weeks ago
A vulnerability was found in Netty up to 4.1.132.Final/4.2.12.Final. It has been classified as problematic. This affects the function setUri of the component HTTP Request Handler. Performing a manipulation results in crlf injection.
This vulnerability is reported as CVE-2026-41417. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41142 | AcademySoftwareFoundation OpenEXR up to 3.2.8/3.3.10/3.4.10 EXR File ImageChannel::resize integer overflow (GHSA-m25w-72cj-q6mg / EUVD-2026-28251)
1 month 2 weeks ago
A vulnerability classified as critical has been found in AcademySoftwareFoundation OpenEXR up to 3.2.8/3.3.10/3.4.10. Impacted is the function ImageChannel::resize of the component EXR File Handler. Performing a manipulation results in integer overflow.
This vulnerability was named CVE-2026-41142. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-44599 | Tor up to 0.4.9.7 resource transfer (Nessus ID 313060)
1 month 2 weeks ago
A vulnerability marked as problematic has been reported in Tor up to 0.4.9.7. The affected element is an unknown function. Performing a manipulation results in incorrect resource transfer.
This vulnerability is known as CVE-2026-44599. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-44602 | Tor up to 0.4.9.7 null pointer dereference (EUVD-2026-28304 / Nessus ID 313061)
1 month 2 weeks ago
A vulnerability was found in Tor up to 0.4.9.7 and classified as problematic. Impacted is an unknown function. The manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2026-44602. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41675 | xmldom prior 0.8.13/0.9.10 DOMParser/XMLSerializer xml injection (GHSA-x6wf-f3px-wcqx / Nessus ID 313065)
1 month 2 weeks ago
A vulnerability has been found in xmldom and classified as critical. This impacts an unknown function of the component DOMParser/XMLSerializer. This manipulation causes xml injection.
This vulnerability is tracked as CVE-2026-41675. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com