Aggregator
CVE-2026-44502 | Bugsink up to 2.1.2 URL Parser urllib.parse.urlparse server-side request forgery (GHSA-fp53-qcf8-2xx2)
CVE-2026-44723 | VowpalWabbit vowpal_wabbit python_checks.yml os command injection (GHSA-cg2g-xgg7-3xxq)
CVE-2026-48697 | FastNetMon Community Edition up to 1.2.9 src/fast_library.cpp execute_web_request_secure improper following of a certificate's chain of trust (EUVD-2026-31900)
CVE-2026-45836 | Linux Kernel up to 7.1-rc2 Bluetooth l2cap_sock_get_sndtimeo_cb null pointer dereference
CVE-2026-45835 | Linux Kernel up to 7.1-rc2 Bluetooth l2cap_sock_new_connection_cb null pointer dereference
CVE-2026-45834 | Linux Kernel up to 7.1-rc2 Bluetooth l2cap_sock_state_change_cb null pointer dereference
CVE-2026-24162 | NVIDIA Merlin Transformers4Rec on Linux deserialization
CVE-2025-14290 | IBM webMethods Integration Server server-side request forgery
CVE-2026-24212 | NVIDIA Isaac Launchable on Linux cleartext transmission
CVE-2025-36148 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms Web UI cross site scripting
CVE-2025-36221 | IBM Cloud Pak for Data System up to 11.3.0.2 IF002 default credentials
CVE-2025-36145 | IBM watsonx.data up to 2.3.1 communication channel to intended endpoints
CVE-2025-36220 | IBM Cloud Pak for Data System up to 11.3.0.2 IF002 sql injection
CVE-2025-13755 | IBM DB2/DB2 Connect Server up to 11.5.9/12.1.4 log file
CVE-2026-9628 | UTT HiPER 1200GW up to 2.5.3-170306 Web Management Interface formPptpClientConfig PPTP server address/username/password/tunnel name stack-based overflow
CVE-2026-9627 | UTT HiPER 1200GW up to 2.5.3-170306 Web Management Interface /goform/setSysAdm strcpy sysAdmUser/sysAdmPass buffer overflow
Multiple Angular Language Service Extension Vulnerabilities Enable RCE Attacks
A set of high-severity vulnerabilities has been identified in the Angular Language Service Visual Studio Code extension (Angular.ng-template), potentially exposing developers to remote code execution (RCE) attacks through multiple exploitation paths. The vulnerabilities arise from insecure handling of user-controlled input and unsafe configuration loading within the extension. Researchers found that attackers can exploit trusted development […]
The post Multiple Angular Language Service Extension Vulnerabilities Enable RCE Attacks appeared first on Cyber Security News.
Windows Update решил обновить BIOS. Владельцы HP получили шум, зависания и синие экраны
How Tier 1 Can Process Alerts 3x Faster with Threat Intelligence
You already know the feeling.The shift starts, and the queue is already full. Somewhere in that pile of hundreds of alerts is the one that actually matters — the lateral movement no one caught, the C2 beacon hiding behind a legitimate-looking domain, the first whisper of a ransomware chain. Your job is to find it before the window closes. That’s the weight Tier 1 carries […]
The post How Tier 1 Can Process Alerts 3x Faster with Threat Intelligence appeared first on Cyber Security News.