Aggregator
CVE-2026-45345 | open-webui Open WebUI up to 0.5.6 improper authorization (GHSA-gm54-m39w-grjp)
CVE-2026-45666 | open-webui Open WebUI up to 0.8.10 /api/v1/notes/ authorization (GHSA-x3qm-p8hr-3c3h)
CVE-2026-8700 | TIMLEGGE Crypt::DSA up to 1.19 on Perl rand entropy (EUVD-2026-30666 / Nessus ID 315076)
CVE-2026-8704 | TIMLEGGE Crypt::DSA up to 1.19 on Perl file access (EUVD-2026-30668 / Nessus ID 315077)
CVE-2026-45303 | open-webui Open WebUI up to 0.6.4 cross site scripting (GHSA-4vrc-m9ch-6m3r)
CVE-2026-45301 | open-webui Open WebUI up to 0.3.15 API Endpoint access control (GHSA-r8wh-8m7r-fh33)
CVE-2026-44571 | open-webui Open WebUI up to 0.8.5 Message update authorization (GHSA-jgj3-r8hr-9pjw)
CVE-2026-44570 | open-webui Open WebUI up to 0.6.18 Memories API /api/v1/memories/query authorization (GHSA-hmjq-crxp-7rjw)
CVE-2026-44569 | open-webui Open WebUI up to 0.6.18 Channels Message authorization (GHSA-jxwr-g6r6-j3fx)
CVE-2026-44567 | open-webui Open WebUI up to 0.1.123 User Registration authorization (GHSA-4vg5-rp28-gvjf)
ChatGPT 能替你管钱了,你敢把银行账户交给它吗?
Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices
A newly disclosed zero-click exploit chain targeting Google Pixel 10 devices has raised fresh concerns about Android’s low-level security. Google Project Zero researchers demonstrated how attackers could silently compromise a device and escalate privileges to root without any user interaction by chaining just two vulnerabilities. The attack builds on earlier research targeting Pixel 9 devices, […]
The post Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices appeared first on Cyber Security News.
ИИ в ухе, ИИ на пальце, ИИ в кармане. Гаджеты скоро станут умнее своих хозяев. И это произойдёт куда быстрее, чем вы думаете
Bad News for the Average Pentester
ArXiv将封禁上传充满AI泔水论文的研究人员
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address
A newly disclosed flaw in Android 16 is raising serious privacy concerns after researchers revealed that malicious apps can bypass VPN protections and expose a user’s real IP address even when strict security settings are enabled. The vulnerability, dubbed the “Tiny UDP Cannon,” allows any regular Android app with basic permissions to leak network traffic […]
The post Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address appeared first on Cyber Security News.