Aggregator
CVE-2026-12458 | Google Chrome up to 149.0.7827.115 Passwords cross-domain policy (Nessus ID 321425)
3 days 3 hours ago
A vulnerability was found in Google Chrome. It has been declared as problematic. This affects an unknown part of the component Passwords. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability was named CVE-2026-12458. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-48853 | elixir-grpc 0.x erlpack.ex deserialization (GHSA-grp7-v8xh-rj7h / Nessus ID 321429)
3 days 3 hours ago
A vulnerability was found in elixir-grpc grpc 0.x. It has been rated as critical. This issue affects some unknown processing of the file lib/grpc/codec/erlpack.ex. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2026-48853. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-12457 | Google Chrome up to 149.0.7827.115 Extensions improper isolation or compartmentalization (Nessus ID 321426)
3 days 3 hours ago
A vulnerability categorized as critical has been discovered in Google Chrome. Affected by this issue is some unknown functionality of the component Extensions. The manipulation results in improper isolation or compartmentalization.
This vulnerability is identified as CVE-2026-12457. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-23394 | SUSE openSUSE Tumbleweed 2.5.0-1.1 cyrus-imapd symlink (Nessus ID 321430)
3 days 3 hours ago
A vulnerability labeled as critical has been found in SUSE openSUSE Tumbleweed 2.5.0-1.1. Affected is an unknown function of the component cyrus-imapd. The manipulation results in symlink following.
This vulnerability is known as CVE-2025-23394. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.
vuldb.com
摩根大通高盛禁止香港员工使用 Anthropic 模型
3 days 3 hours ago
美国投行摩根大通已禁止香港员工访问 Anthropic 的模型,显示这一技术在美国境外的应用正面临极其严格的审查。由于 Anthropic 与摩根大通的许可协议中有关“使用条款”的特定措辞,摩根大通已将 Claude 模型从其驻港员工获批使用的大型语言模型(LLM)内部名单中移除。在此之前,高盛也做出了类似决定,于 4 月将 Claude 从其香港员工的获准使用工具名单中剔除。今年 4 月 Anthropic 首次向少数企业和机构开放 Mythos 模型测试,并警告该模型具备发现网络安全漏洞的能力,不宜广泛推广。6 月初 Anthropic 发布了 Mythos 级模型的首个公开版本 Fable 5,但为管控其突破网络漏洞的能力,同步设置了许多限制措施。然而华盛顿仍以国家安全为由下达紧急出口管制令,迫使 Anthropic 在全球范围内关停 Mythos 5 和 Fable 5 模型。
Oracle, Samsung, Siemens и госструктуры. Хакеры взломали почти 74000 устройств Fortinet в 194 странах
3 days 3 hours ago
Ключ под ковриком – вкратце, как тысячи компаний из списка Fortune 500 «защищали» свои корпоративные сети.
CVE-2026-0071 | Google Android 17 SettingsLib permission (WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability described as critical has been identified in Google Android 17. This affects an unknown function of the component SettingsLib. Such manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2026-0071. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-0064 | Google Android 17 denial of service (WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability was found in Google Android 17 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-0064. The attack must be initiated from a local position. There is no exploit available.
vuldb.com
CVE-2026-0068 | Google Android 17 PackageInstallerService.java createSessionInternal improper synchronization (WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability was found in Google Android 17 and classified as critical. This vulnerability affects the function createSessionInternal of the file PackageInstallerService.java. Such manipulation leads to improper synchronization.
This vulnerability is listed as CVE-2026-0068. The attack must be carried out locally. There is no available exploit.
vuldb.com
CVE-2026-0063 | Google Android 17 PhoneInterfaceManager.java setAllowedCarriers Local Privilege Escalation (EUVD-2026-37575 / WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability marked as critical has been reported in Google Android 17. The impacted element is the function setAllowedCarriers of the file PhoneInterfaceManager.java. This manipulation causes Local Privilege Escalation.
This vulnerability is handled as CVE-2026-0063. It is possible to launch the attack on the local host. There is not any exploit available.
vuldb.com
CVE-2026-0057 | Google Android 17 permission (EUVD-2026-37555 / WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability has been found in Google Android 17 and classified as critical. Affected is an unknown function. The manipulation leads to permission issues.
This vulnerability is listed as CVE-2026-0057. The attack must be carried out locally. There is no available exploit.
vuldb.com
CVE-2025-48643 | Google Android 17 input validation (EUVD-2025-210216 / WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability was found in Google Android 17. It has been rated as critical. This vulnerability affects unknown code. Performing a manipulation results in improper input validation.
This vulnerability is reported as CVE-2025-48643. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2026-0019 | Google Android 17 Setting Local Privilege Escalation (EUVD-2026-37554 / WID-SEC-2026-1993)
3 days 3 hours ago
A vulnerability labeled as critical has been found in Google Android 17. The affected element is an unknown function of the component Setting Handler. The manipulation results in Local Privilege Escalation.
This vulnerability is known as CVE-2026-0019. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2026-50107 | F5 NGINX Gateway Fabric up to 2.6.3 NGINX Configuration Generator injection (K000161785 / WID-SEC-2026-1995)
3 days 3 hours ago
A vulnerability described as critical has been identified in F5 NGINX Gateway Fabric up to 2.6.3. This affects an unknown part of the component NGINX Configuration Generator. The manipulation results in injection.
This vulnerability is reported as CVE-2026-50107. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
Microsoft fixes Windows Server 2016 security update failures
3 days 3 hours ago
Microsoft has fixed a known issue causing the June 2026 security updates to fail on Windows Server 2016 systems that weren't up to date. [...]
Sergiu Gatlan
CVE-2026-48142 | F5 NGINX Open Source/NGINX Plus up to 1.30.2/1.31.1 out-of-bounds (K000161585 / WID-SEC-2026-1995)
3 days 3 hours ago
A vulnerability identified as critical has been detected in F5 NGINX Open Source and NGINX Plus up to 1.30.2/1.31.1. This affects an unknown function. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-48142. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-42055 | F5 NGINX Open Source/NGINX Plus up to 1.30.2/1.31.1 heap-based overflow (K000161584 / WID-SEC-2026-1995)
3 days 3 hours ago
A vulnerability, which was classified as critical, was found in F5 NGINX Open Source and NGINX Plus up to 1.30.2/1.31.1. This issue affects some unknown processing. The manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-42055. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-42530 | F5 NGINX Open Source up to 1.31.1 QUIC use after free (K000161616 / WID-SEC-2026-1995)
3 days 3 hours ago
A vulnerability has been found in F5 NGINX Open Source up to 1.31.1 and classified as critical. Impacted is an unknown function of the component QUIC Module. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-42530. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-32682 | F5 NGINX Gateway Fabric up to 2.6.3 Configuration array index (K000161786 / WID-SEC-2026-1995)
3 days 3 hours ago
A vulnerability has been found in F5 NGINX Gateway Fabric up to 2.6.3 and classified as problematic. This issue affects some unknown processing of the component Configuration Handler. Performing a manipulation results in improper validation of array index.
This vulnerability was named CVE-2026-32682. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com