Aggregator
CVE-2026-32942 | pjsip pjproject up to 2.16 use after free (ID 1451 / Nessus ID 304066)
1 day 18 hours ago
A vulnerability, which was classified as critical, was found in pjsip pjproject up to 2.16. This issue affects some unknown processing. Executing a manipulation can lead to use after free.
This vulnerability is registered as CVE-2026-32942. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-23322 | Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 ipmi smi_work null pointer dereference (Nessus ID 304068 / WID-SEC-2026-0861)
1 day 18 hours ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1. The impacted element is the function smi_work of the component ipmi. Executing a manipulation can lead to null pointer dereference.
The identification of this vulnerability is CVE-2026-23322. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-23349 | Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 HID null pointer dereference (Nessus ID 304067)
1 day 18 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc2. The affected element is an unknown function of the component HID. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-23349. Access to the local network is required for this attack. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-23283 | Linux Kernel up to 6.19.6/7.0-rc1 regulator fp9931_hwmon_read memory leak (Nessus ID 304069 / WID-SEC-2026-0861)
1 day 18 hours ago
A vulnerability was found in Linux Kernel up to 6.19.6/7.0-rc1 and classified as critical. Affected is the function fp9931_hwmon_read of the component regulator. Such manipulation leads to memory leak.
This vulnerability is referenced as CVE-2026-23283. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-33896 | digitalbazaar forge 1.3.2 Certificate Chain certificate validation (Nessus ID 304071)
1 day 18 hours ago
A vulnerability was found in digitalbazaar forge 1.3.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Certificate Chain Handler. The manipulation results in improper certificate validation.
This vulnerability is identified as CVE-2026-33896. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-23341 | Linux Kernel up to 6.19.6/7.0-rc1 amdxdna aie2_destroy_context denial of service (Nessus ID 304070)
1 day 18 hours ago
A vulnerability has been found in Linux Kernel up to 6.19.6/7.0-rc1 and classified as critical. Impacted is the function aie2_destroy_context of the component amdxdna. This manipulation causes denial of service.
This vulnerability appears as CVE-2026-23341. The attacker needs to be present on the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
HPE security advisory (AV26-305)
1 day 19 hours ago
Canadian Centre for Cyber Security
Даже организатор - инкогнито. Proton Meet довел идею конфиденциальности до абсолюта
1 day 19 hours ago
Новый Proton Meet обещает анонимные звонки без логов и вход в конференцию даже без аккаунта.
Attackers hijack Axios npm account to spread RAT malware
1 day 19 hours ago
Threat actors hijacked the npm account of Axios to distribute RAT malware via malicious package updates. Threat actors compromised the npm account of Axios, a widely used library with over 100M weekly downloads, and published malicious versions to spread remote access trojans across Linux, Windows, and macOS. The supply chain attack was identified by multiple […]
Pierluigi Paganini
CVE-2021-27923 | Pillow up to 8.1.0 ICO Container memory allocation (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability was found in Pillow up to 8.1.0. It has been classified as problematic. Affected is an unknown function of the component ICO Container Handler. The manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2021-27923. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2021-28675 | Pillow up to 8.1.x Data Block PSDImagePlugin.PsdImageFile denial of service (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability, which was classified as problematic, was found in Pillow up to 8.1.x. This vulnerability affects the function PSDImagePlugin.PsdImageFile of the component Data Block Handler. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2021-28675. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2021-27921 | Pillow up to 8.1.0 BLP Container memory allocation (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability has been found in Pillow up to 8.1.0 and classified as problematic. This affects an unknown function of the component BLP Container. Performing a manipulation results in uncontrolled memory allocation.
This vulnerability is reported as CVE-2021-27921. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2021-27922 | Pillow up to 8.1.0 Image memory allocation (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability was found in Pillow up to 8.1.0 and classified as problematic. This impacts an unknown function of the component Image Handler. Executing a manipulation can lead to uncontrolled memory allocation.
This vulnerability appears as CVE-2021-27922. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2021-25292 | Pillow up to 8.1.0 PDF Parser incorrect regex (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability, which was classified as critical, was found in Pillow up to 8.1.0. The affected element is an unknown function of the component PDF Parser. The manipulation results in incorrect regular expression.
This vulnerability is cataloged as CVE-2021-25292. The attack must originate from the local network. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2021-25293 | Pillow up to 8.1.0 SGIRleDecode.c out-of-bounds (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability has been found in Pillow up to 8.1.0 and classified as problematic. The impacted element is an unknown function of the file SGIRleDecode.c. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2021-25293. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2021-25290 | Pillow up to 8.1.0 Offset TiffDecode.c memcpy out-of-bounds write (Nessus ID 236661 / WID-SEC-2022-1835)
1 day 19 hours ago
A vulnerability classified as problematic was found in Pillow up to 8.1.0. This issue affects the function memcpy of the file TiffDecode.c of the component Offset Handler. Executing a manipulation can lead to out-of-bounds write.
This vulnerability is tracked as CVE-2021-25290. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
Security and privacy controls and assurance activities catalogue (ITSP.10.033)
1 day 19 hours ago
Canadian Centre for Cyber Security
Android Developer Verification Rollout Begins Ahead of September Enforcement
1 day 19 hours ago
Google on Monday said it's officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while "hiding behind anonymity."
The development comes ahead of a planned verification mandate that goes into effect in Brazil, Indonesia, Singapore, and Thailand this September, before it expands globally next year.
As part of this
The Hacker News
Defense Evasion Split: A Tale of Two Tactics
1 day 19 hours ago
Lauren Lusty