Posts of last few hours
Физики доказали невозможность технологии, которую ещё недавно считали перспективной.
https://www.securitylab.ru/news/576986.php
Спасти данные не помогут даже изолированные резервные копии.
https://www.securitylab.ru/news/576956.php
A vulnerability, which was classified as problematic, was found in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls.
This vulnerability is referenced as CVE-2026-86228. It is possible to launch the attack remotely. Furthermore, an exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/399381
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
sctp: purge outqueue on stale COOKIE-ECHO handling
sctp_stream_update() is only invoked when the association is moved into
COOKIE_WAIT during association setup/reconfiguration. In this path, the
outbound ...
https://cvemon.intruder.io/cves/CVE-2026-52924
Currently trending CVE - Hype Score: 5 - Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could ...
https://cvemon.intruder.io/cves/CVE-2026-73749
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
https://cvemon.intruder.io/cves/CVE-2026-20354
Currently trending CVE - Hype Score: 9 - In the Linux kernel, the following vulnerability has been resolved:
net/rds: handle zerocopy send cleanup before the message is queued
A zerocopy send can fail after user pages have been pinned but before
the message is attached to the sending socket.
The purge path currently ...
https://cvemon.intruder.io/cves/CVE-2026-43502
Currently trending CVE - Hype Score: 9 - Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
https://cvemon.intruder.io/cves/CVE-2026-85046
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
https://cvemon.intruder.io/cves/CVE-2026-20355
Currently trending CVE - Hype Score: 2 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
https://cvemon.intruder.io/cves/CVE-2026-20279
Currently trending CVE - Hype Score: 2 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
https://cvemon.intruder.io/cves/CVE-2026-20274
Currently trending CVE - Hype Score: 6 - Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
This issue affects Elementor Pro: from n/a through 4.2.1.
https://cvemon.intruder.io/cves/CVE-2026-32475
Currently trending CVE - Hype Score: 5 - In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for ...
https://cvemon.intruder.io/cves/CVE-2025-36911
A vulnerability, which was classified as problematic, has been found in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-86227. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
To fix this issue, it is recommended to deploy a patch.
Exploitation requires cluster mode plus attacker-controlled dump.rdb at startup (data-dir write access, replication feed, or a stored crafted RDB) - an attacker-position DoS at boot, not network pre-auth. The issue report was closed stating it "is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure."
https://vuldb.com/vuln/399380
A vulnerability classified as problematic was found in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting.
This vulnerability was named CVE-2026-86226. The attack may be performed from remote. In addition, an exploit is available.
https://vuldb.com/vuln/399379
Реальные масштабы вторжения оказались значительно шире официальных отчётов.
https://www.securitylab.ru/news/576955.php
A vulnerability classified as critical has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-86225. The attack is possible to be carried out remotely. Moreover, an exploit is present.
https://vuldb.com/vuln/399378
A vulnerability described as critical has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection.
This vulnerability is handled as CVE-2026-86224. The attack can be executed remotely. Additionally, an exploit exists.
https://vuldb.com/vuln/399377
A vulnerability marked as critical has been reported in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection.
This vulnerability is known as CVE-2026-86223. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
https://vuldb.com/vuln/399376
A vulnerability labeled as critical has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection.
This vulnerability is traded as CVE-2026-86222. The attack may be launched remotely. Furthermore, there is an exploit available.
https://vuldb.com/vuln/399375
Latest Blog Posts
- 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago