www.all-about-security.de
Linux-Kernel-Sicherheitslücken: Die drei kritischen CVEs erklärt
CISA warnt vor gefährlichen Linux-Kernel-Sicherheitslücken. Lesen Sie, welche Schwachstellen betroffen sind und was dies bedeutet.
#CVE is an active hashtag on Bluesky. In the last 30 days, 76 people shared 3,869 posts with it — around 129 a day. Activity is up 4% versus the previous week, peaking on Sep 16 with 238 posts.
Tags most often used together with #CVE.
www.all-about-security.de
Linux-Kernel-Sicherheitslücken: Die drei kritischen CVEs erklärt
CISA warnt vor gefährlichen Linux-Kernel-Sicherheitslücken. Lesen Sie, welche Schwachstellen betroffen sind und was dies bedeutet.
www.deutschlandfunk.de
Computer und Kommunikation
Das Neueste aus Computertechnik und Informationstechnologie. Beiträge und Interviews zu IT-Sicherheit, Informatik, Datenschutz, Smartphones, Cloud-Computing
infosec.exchange
Original post on infosec.exchange
stackflag.com
CVE-2026-93374: Chrome for Android may run malicious code
Google Chrome on Android versions before 153.0.8010.52 can be tricked by a specially crafted web page to run code outside its normal safety sandbox.
github.com
GitHub - BushidoUK/Ransomware-Vulnerability-Matrix: A collection of CVEs weaponized by ransomware operators
A collection of CVEs weaponized by ransomware operators - BushidoUK/Ransomware-Vulnerability-Matrix
sethmlarson.dev
New era of slop security reports for open source
I'm on the security report triage team for CPython, pip, urllib3, Requests, and a handful of other open source projects. I'm also in a trusted position such that I get "tagged in" to other open sou...
stackflag.com
CVE-2026-88857: OrdaSoft Joomla Gallery extension lets logged‑in admins run code
The free OrdaSoft Joomla Gallery extension for Joomla versions before 6.2.7 lets a user with administrator rights upload a file that the system saves.
stackflag.com
CVE-2026-88854: OrdaSoft Joomla Gallery lets anyone read database data
The free OrdaSoft Joomla Gallery extension for Joomla (versions before 6.2.7) lets any visitor use the public search box to run their own database queries.
stackflag.com
CVE-2026-88856: OrdaSoft Joomla Gallery extension lets attackers run code
The free OrdaSoft Joomla Gallery add‑on for Joomla versions before 6.2.7 lets a logged‑in user tell the system to execute any command it chooses.
stackflag.com
CVE-2026-79920: Ajenti admin panel lets low‑privilege users gain full system control
In versions of Ajenti before 2.2.16, any signed‑in user could ask the system to install, remove, or upgrade plugins.
stackflag.com
CVE-2026-85751: Mailu mail server can be tricked to skip login
Mailu installations that use proxy authentication but do not set the REAL_IP_HEADER may trust a client‑controlled X‑Forwarded‑By header.
stackflag.com
CVE-2026-94301: Apache MINA 2.0/2.1 allows filter bypass
Versions 2.0.30, 2.0.29, 2.1.14 and 2.1.13 of Apache MINA do not include a fix that blocks a way to bypass security checks using Java proxy objects.
stackflag.com
CVE-2026-82187: Web to Print Online Designer lets anyone upload files
The Web to Print Online Designer plugin for WordPress does not check what kind of files are uploaded and gives out the upload token to anyone who asks.
beta.vulnsea.com
CVE-2026-83549 — Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
thehackernews.com
Unbound 1.26.1でDNSSEC検証の重大な脆弱性を修正、RCEの危険性
Unbound 1.26.1で、DNSSEC検証時のヒープオーバーフロー脆弱性が修正されました。悪意あるDNSゾーンによるトリガーでリモートコード実行の危険があり、DNS インフラストラクチャの運営者は直ちにアップデートが必要です。
beta.vulnsea.com
CVE-2026-94101 — A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…
beta.vulnsea.com
CVE-2026-94096 — A vulnerability was found in Netcore NBR200V2 1.3.241127.071246
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…
forsmile.jp
thehackernews.com
Docker Sandboxes に重大な脆弱性、macOS ホストファイルへのアクセスが可能に
Docker Sandboxes に複数の脆弱性が発見され、悪意あるゲストコードがホストファイルや Unix ソケットにアクセス可能でした。バージョン 0.42.0 で修正済み、悪用報告はありません。
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.