Aggregator
GISEC GLOBAL 2026 – The Middle East & Africa’s Largest Cybersecurity Event
3 weeks 5 days hence
Weekly Threat Bulletin – April 8th, 2026
6 hours 52 minutes hence
These are the top threats you should know about this week.
CVE-2026-0049
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 2 - In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-30845
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 6 - ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can craft a malicious `X-HTTP-Method-Override` header value to bypass JWT ...
CVE-2025-48651
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 2 - StrongBox in Android before security patch level 2026-04-05 has a vulnerability of High Severity, aka A-434039170, A-467765081, A-467765894, and A-467762899.
CVE-2023-50428
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 2 - In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this is a vulnerability from the ...
CVE-2025-59528
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 22 - Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses ...
CVE-2025-53521
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 4 - When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-55182
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 5 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
CVE-2023-20869
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 9 - VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
CVE-2023-20870
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 9 - VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
CVE-2023-34044
58 minutes 47 seconds ago
Currently trending CVE - Hype Score: 9 - VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds
read vulnerability that exists in the functionality for sharing host
Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual ...
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 12 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CyberStrikeLab Lab12 弱口令打穿内网
1 hour 13 minutes ago
仿真场景、内网渗透、横向移动、权限提升、权限维持、evasion、ATT&CK
Yokan-自定义&自动化 Web 渗透与外网打点平台
1 hour 13 minutes ago
Yokan 是一款专为网络安全从业人员、研究机构和企业红队设计的一体化 Web 渗透测试与外网打点平台。系统采用完全自定义的工具流架构,深度集成 ICP 官方查询、AI 智能 Fuzzing 推断以及“指纹到漏洞(Fingerprint-to-POC)”的自动化工作流。
2026阿里白帽大会 - Agent安全(智能体时代的攻防新范式)
1 hour 13 minutes ago
2026阿里白帽大会 - Agent安全(智能体时代的攻防新范式)
从 Claude Code 源码泄露看 Agent 工程化防线
1 hour 13 minutes ago
泄露的claude code分析完后刚好和我上一篇写的openclaw的防御分析连续起来,两个超级大热门一起进行分析
0day--JeecgBoot v3.9.1 多漏洞审计过程
1 hour 13 minutes ago
该文章记录了jeecgboot两个0day漏洞的挖掘过程
Java 安全 · AI & Security 两大技术图谱正式上线!
1 hour 14 minutes ago
Java 安全 · AI & Security 两大技术图谱正式上线!