A vulnerability, which was classified as critical, was found in Rapid7 InsightConnect TR Plugin up to 2.0.2 on Linux. Affected by this issue is some unknown functionality. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-8665. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in GPAC up to 26.1.x and classified as critical. This impacts the function gf_filter_pid_get_packet of the file /filter_core/filter_pid.c of the component MP4Box. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2025-60466. The attack needs to be initiated within the local network. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
A vulnerability identified as critical has been detected in Rapid7 InsightConnect Ping Plugin up to 1.0.3 on Linux. This vulnerability affects unknown code of the component Shell Command Handler. This manipulation of the argument host causes os command injection.
This vulnerability is registered as CVE-2026-8660. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Rapid7 InsightConnect AWK Plugin up to 1.2.1 on Linux. This affects the function process_string of the component Shell Command Handler. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-8592. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in Rapid7 InsightConnect Traceroute Plugin up to 1.0.2 on Linux. This issue affects some unknown processing of the component Request Parameter Handler. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-8666. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Rapid7 InsightConnect Compression Plugin up to 2.0.2 on Linux. Impacted is the function create_archive of the component Filename Handler. Performing a manipulation results in path traversal.
This vulnerability is reported as CVE-2026-8662. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in Rapid7 InsightConnect Tcpdump Plugin up to 1.x on Linux. It has been declared as critical. This vulnerability affects unknown code of the component Shell Command Handler. The manipulation results in os command injection.
This vulnerability is identified as CVE-2026-8658. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
我们习以为常的图形 UI 中的每一个小细节,无论多么微小,都是由某个人在某个时间点想出来的。举例来说:拼写错误的单词下方的小红色波浪线。这种设计已成为每个文本编辑字段司空见惯的元素,以至于无人特意去思考它。然而它确实是由某个人发明的,微软资深程序员 Raymond Chen 说,这个人是 Tony Krueger。早期的 Word 版本中,拼写检查功能需要用户手动调用,然后等待程序查找所有可能拼写错误的单词,逐一向用户展示,由用户决定如何处理每一个错误。Word 引入了自动拼写检查功能,在用户空闲时运行拼写检查,当用户点击拼写检查按钮时,结果已准备就绪。然而自动拼写检查仍然是一个阻塞操作。很多用户选择关闭它,因为它总是会在你想做其它事情如保存并退出时突然决定“现在是检查文档拼写的好时机”,迫使你等待拼写检查完成。Tony 让拼写检查器变得更不显眼,不会干扰用户的当前工作。当它发现问题时,不会触发拼写检查,而是立即在可能拼写错误的单词下画上红色波浪线,后来在可能语法错误的单词下画上绿色波浪线。
A vulnerability labeled as critical has been found in Linux Kernel up to 7.0.10. Affected is the function batadv_frag_skb_buffer of the component batman-adv. The manipulation results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-52916. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
A vulnerability classified as critical has been found in daytonaio daytona up to 0.185. This issue affects some unknown processing. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-54319. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability identified as problematic has been detected in denoland deno up to 2.8.0. Affected by this issue is the function process.loadEnvFile of the component Node-compatible API. Performing a manipulation results in incorrect authorization.
This vulnerability is identified as CVE-2026-49983. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in Electron up to 42.3.2. It has been classified as critical. This vulnerability affects unknown code. Performing a manipulation results in buffer overflow.
This vulnerability is known as CVE-2026-54257. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
对 LG 和三星智能电视应用的扫描发现,6038 款电视应用中有 2058 款嵌入了住宅代理 SDK,也就是会出售用户的家用 IP 作为代理服务使用。智能电视是理想的代理主机,它基本上一直处于插入电源状态,同时接入了家用 WIFI,但不像 PC 没人会去检查其可疑后台活动。电视应用上的广告可能会让用户不满,但默默运行的住宅代理则能在最小化用户不满的同时给运营商带来收入。但住宅代理会有滥用的风险,Kimwolf 僵尸网络就滥用了住宅代理进行传播和扩散。
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.0-rc4. The impacted element is the function smc_tcp_syn_recv_sock. This manipulation causes null pointer dereference.
This vulnerability appears as CVE-2026-23450. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.129/6.12.77/6.18.19/6.19.9/7.0-rc4. This affects the function cdc_ncm_rx_verify_ndp16 of the component net. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is tracked as CVE-2026-23448. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.