Posts of last 24 hours
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
These are the top threats you should know about this week.
https://www.f5.com/labs/articles/weekly-threat-bulletin-july-29th-2026
Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group.
The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop.
https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/
A vulnerability classified as problematic has been found in pydantic pydantic-ai up to 1.105.0/2.0.0b5. Affected by this vulnerability is an unknown functionality of the component UI adapter. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-54249. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/384286
A vulnerability described as very critical has been identified in MSI Center 2.0.66.0. Affected is an unknown function of the file NTIOLib_X64.sys. Such manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-6102. An attack has to be approached locally. There is no exploit available.
https://vuldb.com/vuln/384285
A vulnerability marked as problematic has been reported in Autel MaxiCharger AC Elite Home 1.39.51. This impacts an unknown function of the component USB Interface. This manipulation causes improper authentication.
This vulnerability appears as CVE-2026-13306. The attack requires local access. There is no available exploit.
https://vuldb.com/vuln/384284
A vulnerability labeled as problematic has been found in Autel MaxiCharger AC Elite Home 1.39.51. This affects an unknown function of the component NFC interface. The manipulation results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-13309. The attack requires a local approach. No exploit exists.
https://vuldb.com/vuln/384283
A vulnerability identified as very critical has been detected in Autel MaxiCharger AC Elite Home 1.39.51. The impacted element is an unknown function of the component Custom USB Packet Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-13307. The attack needs to be performed locally. There is not any exploit available.
https://vuldb.com/vuln/384282
A vulnerability categorized as problematic has been discovered in Autel MaxiCharger AC Elite Home 1.39.51. The affected element is an unknown function. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is registered as CVE-2026-13305. The attack needs to be launched locally. No exploit is available.
https://vuldb.com/vuln/384281
A vulnerability was found in GitLab up to 19.0.4/19.1.2/19.2.0. It has been rated as problematic. Impacted is an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2026-6267. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/384280