Posts of last few hours
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
A vulnerability classified as problematic was found in Samsung TizenFX. Affected by this issue is some unknown functionality. Such manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2026-85084. The attack can only be performed from a local environment. No exploit is available.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/398301
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
https://www.darkreading.com/application-security/ai-vulnerability-surge-manageable-than-first-feared
A vulnerability classified as problematic has been found in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the component Custom Scheduled Task Feature. This manipulation of the argument customCode causes os command injection.
The identification of this vulnerability is CVE-2026-85040. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Vendor documents this as deliberate debug-only behavior. But isSafePhpCode blacklist offers no real RCE containment.
https://vuldb.com/vuln/398300
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
https://www.darkreading.com/vulnerabilities-threats/sonicwall-sma-1000-zero-days-unauthenticated-rce
A vulnerability described as critical has been identified in fast-uri up to 2.4.5/3.1.6/4.1.3. Affected is the function parse. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-84394. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/398299
A vulnerability marked as problematic has been reported in Amazon Ion-C up to 1.1.5. This impacts an unknown function. The manipulation leads to uncontrolled recursion.
This vulnerability is uniquely identified as CVE-2026-84851. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/398298
A vulnerability labeled as problematic has been found in fastify fast-uri up to 2.4.5/3.1.6/4.1.3. This affects the function serialize/normalize/equal of the component recomposeAuthority. Executing a manipulation of the argument port can lead to improper input validation.
This vulnerability is handled as CVE-2026-84292. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/398297
A vulnerability identified as very critical has been detected in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow.
This vulnerability is known as CVE-2026-85031. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
https://vuldb.com/vuln/398296
A vulnerability categorized as problematic has been discovered in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/routes_agent.py of the component selfRegister API Endpoint. Such manipulation of the argument initial_balance leads to business logic errors.
This vulnerability is traded as CVE-2026-85030. The attack may be launched remotely. Furthermore, there is an exploit available.
This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
profit_percent_for_display() divides by INITIAL_CAPITAL + deposited, and challenge scoring's return_pct also normalises against the attacker-inflated starting_cash. So an inflated initial_balance does not yield artificial percent returns - it inflates the absolute cash/equity column only, which is a cosmetic/leaderboard-gaming concern in a simulated game.
https://vuldb.com/vuln/398295
A vulnerability was found in AMD EPYC Processors, Instinct MI300A Processors, Ryzen Processors and Athlon Processors. It has been rated as very critical. Impacted is an unknown function of the component SMM Module. This manipulation causes heap-based buffer overflow.
This vulnerability appears as CVE-2023-20577. The attack requires local access. There is no available exploit.
https://vuldb.com/vuln/398294
A vulnerability was found in AMD Ryzen 3000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processors with Radeon Graphics, Ryzen 7000 Processors, Ryzen 4000 Desktop Processors with Radeon Graphics, Ryzen Threadripper PRO 5000WX Processors, Ryzen 7020 Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Ryzen 7040 Processors with Radeon Graphics, Ryzen 7045 Mobile Processors, Ryzen Embedded 5000 and Ryzen Embedded V3000. It has been declared as problematic. This issue affects some unknown processing of the component AGESA. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2023-20576. The attack requires a local approach. No exploit exists.
https://vuldb.com/vuln/398293
A vulnerability was found in Go x-crypto-ssh up to 0.55.x. It has been classified as problematic. This vulnerability affects the function handlePacket of the component Channel. The manipulation leads to allocation of resources.
This vulnerability is documented as CVE-2026-78662. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/398292
A vulnerability was found in Go x-crypto-ssh up to 0.55.x and classified as problematic. This affects an unknown part. Executing a manipulation can lead to allocation of resources.
This vulnerability is registered as CVE-2026-56855. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/398291
A vulnerability has been found in UnoPim up to 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component TinyMCE Image Upload Endpoint. Performing a manipulation results in unrestricted upload.
This vulnerability is cataloged as CVE-2026-82524. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/398290
A vulnerability, which was classified as problematic, was found in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the component WebApp Sign-In. Such manipulation of the argument redirect_url leads to cross site scripting.
This vulnerability is listed as CVE-2026-85022. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
https://vuldb.com/vuln/398289
A vulnerability, which was classified as problematic, has been found in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site scripting.
This vulnerability is tracked as CVE-2026-85021. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
https://vuldb.com/vuln/398288
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
https://www.darkreading.com/threat-intelligence/ai-gives-cybercriminals-dangerous-time-advantage
A vulnerability classified as problematic was found in Microsoft winml-cli up to 0.3.x. This impacts the function AutoConfig.from_pretrained of the file src/winml/modelkit/loader/_autoconfig.py of the component CLI API. The manipulation of the argument trust_remote_code results in permissive cross-domain policy with untrusted domains.
This vulnerability is identified as CVE-2026-84452. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/398287
A vulnerability classified as problematic has been found in Septeo IT Solutions UpSignOn up to 7.18.x. This affects an unknown function of the file UpSignOn.exe. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-75137. The attack can only be performed from a local environment. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/398286
Latest Blog Posts
- 1 week 3 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 7 months ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago