Aggregator
Please support the site operations by clicking ads.
【安全圈】洗衣机19小时传400MB流量!
1 day 13 hours ago
关键词美的一、60秒看完全部要点🔴 用户爆料:美的洗衣机联网19小时40分,产生411.52MB流量😰 网
【安全圈】GitHub又崩了!PR重大中断全球研发停摆
1 day 13 hours ago
Submit #919190: marcobambini gravity v0.9.7 Out-of-Bounds Read [Accepted]
1 day 13 hours ago
Submit #919190 / VDB-403270
lrrh
Submit #919189: marcobambini gravity v0.9.7 Heap-based Buffer Overflow [Accepted]
1 day 13 hours ago
Submit #919189 / VDB-403269
lrrh
Submit #919185: marcobambini gravity v0.9.7 Out-of-bounds Pointer Arithmetic [Accepted]
1 day 13 hours ago
Submit #919185 / VDB-403268
lrrh
CVE-2026-90713 | vllm-project vLLM up to 0.29.0 tiktoken vocab File mod.rs TiktokenTokenizer::new denial of service (Issue 50954)
1 day 13 hours ago
A vulnerability labeled as problematic has been found in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service.
This vulnerability is identified as CVE-2026-90713. The attack is only possible with local access. Additionally, an exploit exists.
The pull request to fix this issue awaits acceptance.
vuldb.com
CVE-2026-90712 | Gitlawb openclaude up to 0.30.0 xAI OAuth Callback xaiOAuthCallback.ts waitForCallback Error denial of service (Issue 2101)
1 day 13 hours ago
A vulnerability identified as problematic has been detected in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service.
This vulnerability is referenced as CVE-2026-90712. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
Submit #918762: vLLM Project (vllm-project) vLLM v0.26.0 Denial of Service [Accepted]
1 day 13 hours ago
Submit #918762 / VDB-403267
Zyz3366
Submit #918715: Gitlawb openclaude 0.27.0 Denial of Service [Accepted]
1 day 14 hours ago
Submit #918715 / VDB-403266
nedlir
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
1 day 14 hours ago
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]
Pierluigi Paganini
Пароль удалили из Git, но он всё ещё там. Главные ошибки безопасности CI/CD
1 day 14 hours ago
Как забытые токены в истории коммитов, слепые слои контейнеров и избыточные роли ломают периметр еще до первого запуска.
CVE-2026-90710 | taisan tarzan-cms 1.0.0 Theme Download Function ThemeService.java openConnection httpUrl server-side request forgery (IK768M)
1 day 14 hours ago
A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-90710. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
CVE-2026-85103
1 day 14 hours ago
Currently trending CVE - Hype Score: 2 - A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
CVE-2026-85102
1 day 14 hours ago
Currently trending CVE - Hype Score: 2 - Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
CVE-2026-67277
1 day 14 hours ago
Currently trending CVE - Hype Score: 1 - RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet ...
CVE-2025-25249
1 day 14 hours ago
Currently trending CVE - Hype Score: 1 - A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 ...
CVE-2026-86060
1 day 14 hours ago
Currently trending CVE - Hype Score: 1 - RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to ...
Submit #918522: taisan Tarzan CMS 1.0.0 and earlier Server-Side Request Forgery (SSRF) [Accepted]
1 day 14 hours ago
Submit #918522 / VDB-403265
mjh_123
Биороботы получили мышцы с диапазоном движения в 11 раз больше
1 day 14 hours ago
Алгоритм одновременно выращивает мышцу и проектирует скелет.