Aggregator
[Virtual Event] Building a Secure AI Strategy for the Enterprise
1 month hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
20 minutes 23 seconds ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
Лазер сквозь Землю остался мечтой. Помешала квантовая физика и запрет Паули
6 hours 27 minutes ago
Физики доказали невозможность технологии, которую ещё недавно считали перспективной.
7 российских компаний под ударом. Новый шифровальщик VantaCore требует от жертв миллионы
7 hours 13 minutes ago
Спасти данные не помогут даже изолированные резервные копии.
CVE-2026-86228 | JeecgBoot up to 3.9.3 AiragModelController.java exportXls credential access control (Issue 9600)
8 hours 10 minutes ago
A vulnerability, which was classified as problematic, was found in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls.
This vulnerability is referenced as CVE-2026-86228. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-52924
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
sctp: purge outqueue on stale COOKIE-ECHO handling
sctp_stream_update() is only invoked when the association is moved into
COOKIE_WAIT during association setup/reconfiguration. In this path, the
outbound ...
CVE-2026-73749
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 5 - Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could ...
CVE-2026-20354
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
CVE-2026-43502
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 9 - In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently ...
CVE-2026-85046
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 9 - Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-20355
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
CVE-2026-20279
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 2 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
CVE-2026-20274
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 2 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
CVE-2026-32475
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 6 - Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
This issue affects Elementor Pro: from n/a through 4.2.1.
CVE-2025-36911
8 hours 12 minutes ago
Currently trending CVE - Hype Score: 5 - In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for ...
CVE-2026-86227 | valkey-io valkey up to 9.0.5/9.1.1 src/kvstore.c kvstoreGetHashtable didx out-of-bounds (Issue 4222)
8 hours 16 minutes ago
A vulnerability, which was classified as problematic, has been found in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-86227. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
To fix this issue, it is recommended to deploy a patch.
Exploitation requires cluster mode plus attacker-controlled dump.rdb at startup (data-dir write access, replication feed, or a stored crafted RDB) - an attacker-position DoS at boot, not network pre-auth. The issue report was closed stating it "is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure."
vuldb.com
CVE-2026-86226 | Projectwolds Online Attendance System 1.0 profile.php email cross site scripting
8 hours 19 minutes ago
A vulnerability classified as problematic was found in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting.
This vulnerability was named CVE-2026-86226. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
9,8 из 10. Критическая дыра в Super Forms отдаёт сервер хакерам за два клика
8 hours 21 minutes ago
Реальные масштабы вторжения оказались значительно шире официальных отчётов.
造物100#05|给 AI 发外设,戴森派摄像头进嘴、绿联给充电宝开了扇窗
8 hours 23 minutes ago
AI 正在把所有硬件重新做一遍,这周轮到了一把牙刷。