Aggregator
CVE-2026-0067 | Google Android 14/15/16/16-qpr2 ubsan_throwing_runtime.cpp denial of service (WID-SEC-2026-1772)
CVE-2026-0056 | Google Android 14/15/16/16-qpr2 ResourceTypes.cpp setTo out-of-bounds (WID-SEC-2026-1772)
CVE-2026-0055 | Google Android 14/15/16/16-qpr2 PackageInstallerService.java createSessionInternal path traversal (WID-SEC-2026-1772)
CVE-2026-0059 | Google Android 14/15/16/16-qpr2 sdp_discovery.cc heap-based overflow (WID-SEC-2026-1772)
CVE-2026-0051 | Google Android 14/15/16/16-qpr2 ubsan_throwing_runtime.cpp denial of service (WID-SEC-2026-1772)
CVE-2026-0052 | Google Android 14/15/16/16-qpr2 ubsan_throwing_runtime.cpp integer overflow (WID-SEC-2026-1772)
Мир станет чуточку безопаснее. Anthropic предоставит доступ к Mythos сразу 15 странам
Known vulnerabilities behind most application security incidents
Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to a structural condition across the industry, where the window between identifying a flaw and closing it in production stays open long enough for attackers to act. Which of the following best describes your … More →
The post Known vulnerabilities behind most application security incidents appeared first on Help Net Security.
哈哈,英国 KSL 真是家有趣的公司[666]
CVE-2026-31942 | danny-avila LibreChat up to 0.7.6/0.8.2 API Keys Management Endpoint /api/keys userId authorization (GHSA-5jcj-rh68-cgj7 / EUVD-2026-34044)
CVE-2026-32625 | danny-avila LibreChat up to 0.8.3 information disclosure (GHSA-4pcc-j6m6-wcwx / EUVD-2026-34046)
CVE-2026-44653 | danny-avila LibreChat up to 0.8.3 API Response /api/mcp/servers insertion of sensitive information into sent data (GHSA-6vqg-rgpm-qvf9 / EUVD-2026-34047)
CVE-2026-10197 | Assimp up to 6.0.4 TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference (Issue 6608 / Nessus ID 318233)
CVE-2026-10199 | Assimp up to 6.0.4 glTF2Asset.h glTF2::LazyDict operator[] null pointer dereference (Issue 6611 / Nessus ID 318231)
CVE-2025-60485 | GPAC up to 26.1.x MP4Box /isomedia/isom_write.c gf_isom_apple_set_tag_ex denial of service (Nessus ID 318232)
CVE-2026-10231 | Assimp up to 6.0.4 Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value num.total heap-based overflow (Issue 6616 / Nessus ID 318234)
Welcoming the Philippine Government to Have I Been Pwned
Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines.
The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor official government domains against the data in HIBP. This gives their Cyber