Aggregator
苹果将AppleCare+年度订阅上调5美元
1 week 1 day ago
苹果公司小幅上调了AppleCare+服务订阅的价格,这是该公司在全球存储芯片短缺及其他行业压力下推出的又一轮涨价举措。Mac和iPad的 AppleCare+ 月度订阅套餐价格上涨了50美分,而年度
2026京麒CTF决赛 倒计时三天!
1 week 1 day ago
CVE-2022-3492 | SourceCodester Human Resource Management System 1.0 Profile Photo parameter os command injection (EUVD-2022-42864)
1 week 1 day ago
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Profile Photo Handler. Performing a manipulation of the argument parameter results in os command injection.
This vulnerability is identified as CVE-2022-3492. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2022-3493 | SourceCodester Human Resource Management System 1.0 Add Employee First Name/Middle Name/Last Name cross site scripting (EUVD-2022-42865)
1 week 1 day ago
A vulnerability, which was classified as problematic, was found in SourceCodester Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the component Add Employee Handler. Executing a manipulation of the argument First Name/Middle Name/Last Name can lead to cross site scripting.
This vulnerability is tracked as CVE-2022-3493. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2022-3491 | vim up to 9.0.741 heap-based overflow (EUVD-2022-42863 / WID-SEC-2022-2222)
1 week 1 day ago
A vulnerability described as critical has been identified in vim up to 9.0.741. This affects an unknown function. Such manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2022-3491. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
1 week 1 day ago
On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromis
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
1 week 1 day ago
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses.
The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog.
Microsoft Security Research, Ravikant Tiwari, Sagar Patil, Suriyaraj Natarajan and Arvind Gowda
CVE-2026-22213 | RIOT OS up to 2026.01-devel-317 /dev/ devopen stack-based overflow (EUVD-2026-2394)
1 week 1 day ago
A vulnerability classified as critical has been found in RIOT OS up to 2026.01-devel-317. This affects the function devopen of the file /dev/. The manipulation leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2026-22213. The attack can only be performed from a local environment. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-22214 | RIOT OS up to 2026.01-devel-317 _handle_char stack-based overflow (EUVD-2026-2395)
1 week 1 day ago
A vulnerability, which was classified as critical, has been found in RIOT OS up to 2026.01-devel-317. Affected is the function _handle_char. This manipulation causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-22214. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-68798 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 NMI x86_pmu_stop null pointer dereference (Nessus ID 298659 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. The affected element is the function x86_pmu_stop of the component NMI Handler. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2025-68798. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-68814 | Linux Kernel up to 6.19-rc2 __io_openat_prep memory leak (Nessus ID 298659 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc2. This affects the function __io_openat_prep. The manipulation results in memory leak.
This vulnerability is known as CVE-2025-68814. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2025-68816 | Linux Kernel up to 6.19-rc1 mlx5_tracer_validate_params format string (Nessus ID 298659 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. It has been rated as critical. The impacted element is the function mlx5_tracer_validate_params. The manipulation leads to format string.
This vulnerability is referenced as CVE-2025-68816. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-68788 | Linux Kernel up to 6.19-rc1 fsnotify utimensat information disclosure (Nessus ID 298404 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. This vulnerability affects the function utimensat of the component fsnotify. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2025-68788. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-68787 | Linux Kernel up to 6.19-rc1 netrom include/linux/kmemleak.h nr_sendmsg memory leak (Nessus ID 283665 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. Impacted is the function nr_sendmsg in the library include/linux/kmemleak.h of the component netrom. This manipulation causes memory leak.
This vulnerability is registered as CVE-2025-68787. The attack requires access to the local network. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-68803 | Linux Kernel up to 6.1.159/6.12.63/6.18.2/6.19-rc2 NFSv4 nfsd_create_setattr privilege escalation (EUVD-2026-2303 / Nessus ID 298659)
1 week 1 day ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.159/6.12.63/6.18.2/6.19-rc2. The impacted element is the function nfsd_create_setattr of the component NFSv4. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2025-68803. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-68776 | Linux Kernel up to 6.19-rc1 prp_get_untagged_frame null pointer dereference (Nessus ID 298404 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. Impacted is the function prp_get_untagged_frame. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2025-68776. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-68782 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 scsi t_task_cdb null pointer dereference (Nessus ID 298404 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. It has been classified as critical. This affects an unknown function of the component scsi. The manipulation of the argument t_task_cdb leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-68782. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-68773 | Linux Kernel up to 6.19-rc1 spi buffer overflow (Nessus ID 298404 / WID-SEC-2026-0086)
1 week 1 day ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc1. This issue affects some unknown processing of the component spi. The manipulation results in buffer overflow.
This vulnerability was named CVE-2025-68773. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
马斯克开源 Grok Build 编程AI智能体工具
1 week 1 day ago
马斯克旗下的 SpaceXAI 公司本周三宣布开源 Grok Build,并将源代码发布至 GitHub 平台。SpaceXAI公司表示:“开源发布源代码是构建强大、可靠框架的最直接方法。用户可以阅读