Aggregator
CVE-2025-31703 | Dahua NVR2-4KS3/XVR4232AN-I/T/XVR1B16H-I authentication bypass (EUVD-2025-208815)
CVE-2026-22323 | Phoenix Contact FL SWITCH 2005 up to 3.52 Link Aggregation Configuration Interface cross-site request forgery (VDE-2025-104 / EUVD-2026-12794)
CVE-2026-22730 | VMware Spring AI up to 1.0.3/1.1.2 MariaDBFilterExpressionConverter sql injection (EUVD-2026-12797)
CVE-2026-22729 | VMware Spring AI up to 1.0.3/1.1.2 AbstractFilterExpressionConverter injection (EUVD-2026-12795)
CVE-2026-22320 | Phoenix Contact FL SWITCH 2005 up to 3.52 Telnet/SSH stack-based overflow (VDE-2025-104 / EUVD-2026-12789)
CVE-2026-22319 | Phoenix Contact FL SWITCH 2005 up to 3.52 POST Parameter stack-based overflow (VDE-2025-104 / EUVD-2026-12788)
CVE-2026-22318 | Phoenix Contact FL SWITCH 2005 up to 3.52 POST Parameter stack-based overflow (VDE-2025-104 / EUVD-2026-12787)
CVE-2026-3512 | alhadeff Writeprint Stylometry Plugin up to 0.1 on WordPress GET Parameter bjl_wprintstylo_comments_nav cross site scripting (EUVD-2026-12783)
CVE-2026-22321 | Phoenix Contact FL SWITCH 2005 up to 3.52 Telnet/SSH stack-based overflow (VDE-2025-104 / EUVD-2026-12790)
CVE-2026-22317 | Phoenix Contact FL SWITCH 2005 up to 3.52 HTTP command injection (VDE-2025-104 / EUVD-2026-12786)
Проверка страшнее кражи. Российский бизнес боится Роскомнадзора больше, чем хакеров
Ubuntu CVE-2026-3888 Bug Lets Attackers Gain Root via systemd Cleanup Timing Exploit
RSAC 2026创新沙盒 | Charm Security:构建面向新型诈骗的AI反欺诈平台
智能体时代 漏洞管理要跃迁到10.0版本
Researchers Reveal ‘RegPwn,’ a Windows Registry Vulnerability That Granted SYSTEM Privileges
A high-severity Windows vulnerability dubbed “RegPwn” (CVE-2026-24291) is an elevation-of-privilege flaw that allows low-privileged users to gain full SYSTEM access. The MDSec red team discovered the vulnerability and successfully used it in internal engagements since January 2025, before it was addressed in a recent Microsoft Patch Tuesday update. The attack targets the way Windows manages […]
The post Researchers Reveal ‘RegPwn,’ a Windows Registry Vulnerability That Granted SYSTEM Privileges appeared first on Cyber Security News.
Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access
A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS). Tracked as CVE-2026-21643, this severe flaw carries a CVSS score of 9.1. It allows unauthenticated attackers to execute arbitrary SQL commands and access sensitive database information. The issue specifically affects FortiClient EMS version 7.4.4 when multi-tenant mode is active. The root cause stems […]
The post Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access appeared first on Cyber Security News.