Aggregator
OpenAI自研AI芯片挑战英伟达
1 month ago
安全客
AI驱动恶意软件在“s1ngularity”攻击中入侵2180个GitHub账户
1 month ago
安全客
AI安全教育与人才培养能力获认可!360携ISC.AI学苑入选IDC权威报告
1 month ago
安全客
CVE-2025-57052:cJSON存在严重JSON解析漏洞(CVSS 9.8),POC已公开
1 month ago
安全客
Progress修复OpenEdge AdminServer远程命令执行漏洞(CVE-2025-7388)
1 month ago
安全客
Nubox Falls Victim to Mydata/Alphalocker Ransomware
1 month ago
Nubox Falls Victim to Mydata/Alphalocker Ransomware
Dark Web Informer
Одна лишняя «t». Разработчики Ethereum теряют кошельки через Telegram-боты
1 month ago
Поддельные SDK отправляют мнемонические фразы в чужие руки. Каждая установка может обернуться катастрофой.
[Control systems] CISA ICS security advisories (AV25–574)
1 month ago
Canadian Centre for Cyber Security
CVE-2025-5993
1 month ago
Currently trending CVE - Hype Score: 5 - ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable parameter fileName and construct payloads that allow to download any file accessible by the the web server process.
CVE-2025-9074
1 month ago
Currently trending CVE - Hype Score: 1 - A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, ...
CVE-2016-7152 | Microsoft Edge HTTPS HEIST information disclosure (Nessus ID 261330 / BID-92769)
1 month ago
A vulnerability classified as problematic was found in Microsoft Edge. Impacted is an unknown function of the component HTTPS Handler. Executing manipulation can lead to information disclosure (HEIST).
The identification of this vulnerability is CVE-2016-7152. The attack may be launched remotely. There is no exploit available. This vulnerability is notable in history due to its background and the response it received.
You are recommended to apply the suggested workaround.
vuldb.com
CVE-2016-7152 | Mozilla Firefox HTTPS HEIST information disclosure (Nessus ID 261330 / BID-92769)
1 month ago
A vulnerability, which was classified as problematic, has been found in Mozilla Firefox. The affected element is an unknown function of the component HTTPS Handler. The manipulation leads to information disclosure (HEIST).
This vulnerability is referenced as CVE-2016-7152. Remote exploitation of the attack is possible. No exploit is available. Due to its background and reception, this vulnerability has an historic impact.
It is recommended to apply the suggested workaround.
vuldb.com
CVE-2016-7152 | Apple Safari HTTPS HEIST information disclosure (Nessus ID 261330 / BID-92769)
1 month ago
A vulnerability marked as problematic has been reported in Apple Safari. This affects an unknown part of the component HTTPS Handler. This manipulation causes information disclosure (HEIST).
This vulnerability is handled as CVE-2016-7152. The attack can be initiated remotely. There is not any exploit available. This vulnerability is considered historic because of its background and reception.
It is best practice to apply the suggested workaround.
vuldb.com
CVE-2016-7152 | Google Chrome HTTPS HEIST information disclosure (Nessus ID 261330 / BID-92769)
1 month ago
A vulnerability described as problematic has been identified in Google Chrome. This vulnerability affects unknown code of the component HTTPS Handler. Such manipulation leads to information disclosure (HEIST).
This vulnerability is uniquely identified as CVE-2016-7152. The attack can be launched remotely. No exploit exists. This vulnerability is historically impactful due to its background and the reception it garnered.
It is suggested to apply the recommended workaround.
vuldb.com
CVE-2016-7152 | Microsoft Internet Explorer HTTPS HEIST information disclosure (Nessus ID 261330 / BID-92769)
1 month ago
A vulnerability classified as problematic has been found in Microsoft Internet Explorer. This issue affects some unknown processing of the component HTTPS Handler. Performing manipulation results in information disclosure (HEIST).
This vulnerability was named CVE-2016-7152. The attack may be initiated remotely. There is no available exploit. This vulnerability is historically significant due to its background and the way it was received.
The suggested workaround should be applied.
vuldb.com
CVE-2016-2338 | Ruby Tags Array Length Psych::Emitter heap-based overflow (DLA 2158-1 / Nessus ID 261341)
1 month ago
A vulnerability, which was classified as critical, was found in Ruby. The impacted element is the function Psych::Emitter of the component Tags Array Length Handler. Executing manipulation can lead to heap-based buffer overflow.
This vulnerability is tracked as CVE-2016-2338. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2022-50030 | Linux Kernel up to 5.4.210/5.10.137/5.15.62/5.19.3 scsi buffer overflow (Nessus ID 261340 / WID-SEC-2025-1350)
1 month ago
A vulnerability identified as critical has been detected in Linux Kernel up to 5.4.210/5.10.137/5.15.62/5.19.3. This affects an unknown function of the component scsi. Performing manipulation results in buffer overflow.
This vulnerability is known as CVE-2022-50030. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2021-20282 | Moodle up to 3.5.16/3.8.7/3.9.4/3.10.1 Verification authorization (Nessus ID 261349)
1 month ago
A vulnerability was found in Moodle up to 3.5.16/3.8.7/3.9.4/3.10.1. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Verification Handler. The manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2021-20282. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-43566 | Samba up to 4.13.15 SMB1/NFS access control (Nessus ID 261345 / WID-SEC-2023-2979)
1 month ago
A vulnerability was found in Samba up to 4.13.15. It has been rated as critical. Affected by this issue is some unknown functionality of the component SMB1/NFS. This manipulation causes improper access controls.
This vulnerability is registered as CVE-2021-43566. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com