Aggregator
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
6 hours 9 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
Weekly Threat Bulletin – July 29th, 2026
8 hours 6 minutes ago
These are the top threats you should know about this week.
A little-known npm package was North Korea’s warm-up act for the axios hack
8 hours 31 minutes ago
Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group.
The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop.
Greg Otto
CVE-2026-54249 | pydantic pydantic-ai up to 1.105.0/2.0.0b5 UI adapter path traversal
8 hours 39 minutes ago
A vulnerability classified as problematic has been found in pydantic pydantic-ai up to 1.105.0/2.0.0b5. Affected by this vulnerability is an unknown functionality of the component UI adapter. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-54249. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-6102 | MSI Center 2.0.66.0 NTIOLib_X64.sys privileges management
9 hours 8 minutes ago
A vulnerability described as very critical has been identified in MSI Center 2.0.66.0. Affected is an unknown function of the file NTIOLib_X64.sys. Such manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-6102. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2026-13306 | Autel MaxiCharger AC Elite Home 1.39.51 USB Interface improper authentication
9 hours 8 minutes ago
A vulnerability marked as problematic has been reported in Autel MaxiCharger AC Elite Home 1.39.51. This impacts an unknown function of the component USB Interface. This manipulation causes improper authentication.
This vulnerability appears as CVE-2026-13306. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2026-13309 | Autel MaxiCharger AC Elite Home 1.39.51 NFC interface stack-based overflow
9 hours 9 minutes ago
A vulnerability labeled as problematic has been found in Autel MaxiCharger AC Elite Home 1.39.51. This affects an unknown function of the component NFC interface. The manipulation results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-13309. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2026-13307 | Autel MaxiCharger AC Elite Home 1.39.51 Custom USB Packet heap-based overflow
9 hours 9 minutes ago
A vulnerability identified as very critical has been detected in Autel MaxiCharger AC Elite Home 1.39.51. The impacted element is an unknown function of the component Custom USB Packet Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-13307. The attack needs to be performed locally. There is not any exploit available.
vuldb.com
CVE-2026-13305 | Autel MaxiCharger AC Elite Home 1.39.51 signature verification
9 hours 9 minutes ago
A vulnerability categorized as problematic has been discovered in Autel MaxiCharger AC Elite Home 1.39.51. The affected element is an unknown function. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is registered as CVE-2026-13305. The attack needs to be launched locally. No exploit is available.
vuldb.com
CVE-2026-6267 | GitLab up to 19.0.4/19.1.2/19.2.0 access control
9 hours 10 minutes ago
A vulnerability was found in GitLab up to 19.0.4/19.1.2/19.2.0. It has been rated as problematic. Impacted is an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2026-6267. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-6336 | GitLab up to 19.0.4/19.1.2/19.2.0 Project Import improper authorization
9 hours 10 minutes ago
A vulnerability was found in GitLab up to 19.0.4/19.1.2/19.2.0. It has been declared as problematic. This issue affects some unknown processing of the component Project Import. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-6336. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-13308 | Autel MaxiCharger AC Elite Home 1.39.51 OCPP Service integer underflow
9 hours 11 minutes ago
A vulnerability was found in Autel MaxiCharger AC Elite Home 1.39.51. It has been classified as critical. This vulnerability affects unknown code of the component OCPP Service. This manipulation causes integer underflow.
This vulnerability is tracked as CVE-2026-13308. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-46678 | pydantic AI up to 1.98.x Cloud Metadata Blocklist force_download encoding error
9 hours 12 minutes ago
A vulnerability was found in pydantic AI up to 1.98.x and classified as critical. This affects an unknown part of the component Cloud Metadata Blocklist. The manipulation of the argument force_download results in encoding error.
This vulnerability is identified as CVE-2026-46678. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-65975 | pydantic AI prior 1.107.1/2.5.0 UI Adapters sanitize_messages authorization
9 hours 12 minutes ago
A vulnerability has been found in pydantic AI and classified as problematic. Affected by this issue is the function sanitize_messages of the component UI Adapters. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-65975. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
Supply chain challenges loom large in quantum race, White House official says
9 hours 19 minutes ago
Brad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges.
The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.
Tim Starks
CVE-2026-63118 | modelcontextprotocol ruby-sdk up to 0.22.x StreamableHTTPTransport dns rebinding
9 hours 25 minutes ago
A vulnerability, which was classified as critical, was found in modelcontextprotocol ruby-sdk up to 0.22.x. Affected by this vulnerability is the function MCP::Server::Transports::StreamableHTTPTransport of the component StreamableHTTPTransport. Executing a manipulation can lead to reliance on reverse dns resolution.
The identification of this vulnerability is CVE-2026-63118. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-67433 | Linuxfabrik monitoring-plugins 6.0.0 logfile check legacy database migration sqlite3.connect link following
9 hours 26 minutes ago
A vulnerability, which was classified as very critical, has been found in Linuxfabrik monitoring-plugins 6.0.0. Affected is the function sqlite3.connect of the component logfile check legacy database migration. Performing a manipulation results in link following.
This vulnerability was named CVE-2026-67433. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2026-67431 | modelcontextprotocol ruby-sdk up to 0.22.x StreamableHTTPTransport improper authentication (EUVD-2026-50501)
9 hours 26 minutes ago
A vulnerability classified as critical was found in modelcontextprotocol ruby-sdk up to 0.22.x. This impacts the function MCP::Server::Transports::StreamableHTTPTransport of the component StreamableHTTPTransport. Such manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-67431. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-67430 | modelcontextprotocol ruby-sdk up to 0.22.x StreamableHTTPTransport allocation of resources
9 hours 27 minutes ago
A vulnerability classified as problematic has been found in modelcontextprotocol ruby-sdk up to 0.22.x. This affects the function MCP::Server::Transports::StreamableHTTPTransport of the component StreamableHTTPTransport. This manipulation causes allocation of resources.
This vulnerability is handled as CVE-2026-67430. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com