Aggregator
CVE-2026-2340 | Samba vfs_worm insufficient privileges (EUVD-2026-32312 / Nessus ID 316800)
1 week 2 days ago
A vulnerability classified as problematic has been found in Samba. Affected by this issue is some unknown functionality of the component vfs_worm. This manipulation causes improper handling of insufficient permissions or privileges.
The identification of this vulnerability is CVE-2026-2340. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-1933 | Samba NTFS access control (EUVD-2026-32275 / Nessus ID 316851)
1 week 2 days ago
A vulnerability marked as critical has been reported in Samba. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-1933. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-62574 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition Install Local Privilege Escalation (Nessus ID 329223 / WID-SEC-2026-2443)
1 week 2 days ago
A vulnerability was found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition and classified as problematic. This vulnerability affects unknown code of the component Install. The manipulation results in Local Privilege Escalation.
This vulnerability is identified as CVE-2026-62574. The attack is only possible with local access. There is not any exploit available.
vuldb.com
CVE-2026-52688 | PowerDNS Recursor up to 5.2.11/5.3.8/5.4.3 input validation (WID-SEC-2026-2471)
1 week 2 days ago
A vulnerability labeled as critical has been found in PowerDNS Recursor up to 5.2.11/5.3.8/5.4.3. This impacts an unknown function. Such manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2026-52688. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-57231 | podman-container-tools podman up to 5.8.3 information disclosure (EUVD-2026-39807 / Nessus ID 323664)
1 week 2 days ago
A vulnerability, which was classified as problematic, was found in podman-container-tools podman up to 5.8.3. This affects an unknown part. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-57231. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-60166 | Oracle Java SE 8u491 JavaFX information disclosure (WID-SEC-2026-2443)
1 week 2 days ago
A vulnerability was found in Oracle Java SE 8u491. It has been classified as problematic. This impacts an unknown function of the component JavaFX. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2026-60166. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-60526 | Oracle Java SE 8u491/8u491-perf Installation sandbox (WID-SEC-2026-2443)
1 week 2 days ago
A vulnerability, which was classified as critical, was found in Oracle Java SE 8u491/8u491-perf. This issue affects some unknown processing of the component Installation. Such manipulation leads to sandbox issue.
This vulnerability is uniquely identified as CVE-2026-60526. The attack can be launched remotely. No exploit exists.
vuldb.com
OpenClaw 官方安卓客户端,为什么评分只有 1.9?
1 week 2 days ago
Запирай двери, глуши двигатели. Дыра в безопасности позволяла хакерам перехватывать контроль над арендованными авто
1 week 2 days ago
Слабая защита оставила водителей наедине с чужими командами из интернета.
多起事故后 美国启动车门安全新规制定程序
1 week 2 days ago
美国汽车安全监管机构正式启动车门逃生系统联邦法规的制定程序,此举将对特斯拉公司等采用电动隐藏式门把手的车企产生深远影响。美国国家公路交通安全管理局周四表示,已批准一份请愿申请,将开始推进新联邦法规的制
Ransomware in 2026: More groups, more victims, no slowdown
1 week 2 days ago
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. Black Kite’s 2026 Ransomware Report documents a more fragmented market, with multiple ransomware playbooks scaling at the same time. Monthly victim count by threat actor (Source: Black Kite) Between April 2025 and March 2026, 61 new ransomware groups entered the market, averaging more than one group per week. … More →
The post Ransomware in 2026: More groups, more victims, no slowdown appeared first on Help Net Security.
Anamarija Pogorelec
对话格式塔彭雷:AI 的下一站,是解读人的大脑
1 week 2 days ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
对话格式塔彭雷:AI 的下一站,是解读人的大脑
1 week 2 days ago
脑机接口从意念控制光标走向更大范围的大脑读写。
网友发帖称Namecheap在未经核实的情况下 将域名所在账户转给其他人
1 week 2 days ago
CVE-2022-40179 | Siemens Desigo PXG3.W200-2 Operation Web Application cross-site request forgery (ssa-360783 / EUVD-2022-43482)
1 week 2 days ago
A vulnerability identified as problematic has been detected in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. The impacted element is an unknown function of the component Operation Web Application. This manipulation causes cross-site request forgery.
This vulnerability is registered as CVE-2022-40179. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2022-40180 | Siemens Desigo PXG3.W200-2 Operation Web Application cross-site request forgery (ssa-360783 / EUVD-2022-43483)
1 week 2 days ago
A vulnerability labeled as problematic has been found in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. This affects an unknown function of the component Operation Web Application. Such manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2022-40180. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2022-40181 | Siemens Desigo PXG3.W200-2 Device Embedded Browser cross site scripting (ssa-360783 / EUVD-2022-43484)
1 week 2 days ago
A vulnerability classified as problematic was found in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. Affected by this issue is some unknown functionality of the component Device Embedded Browser. The manipulation results in improper neutralization of encoded uri schemes in a web page.
This vulnerability is known as CVE-2022-40181. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2022-40178 | Siemens Desigo PXG3.W200-2 Operation Web Application cross site scripting (ssa-360783 / EUVD-2022-43481)
1 week 2 days ago
A vulnerability categorized as problematic has been discovered in Siemens Desigo PXM30-1, Desigo PXM30.E, Desigo PXM40-1, Desigo PXM40.E, Desigo PXM50-1, Desigo PXM50.E, Desigo PXG3.W100-1, Desigo PXG3.W100-2, Desigo PXG3.W200-1 and Desigo PXG3.W200-2. The affected element is an unknown function of the component Operation Web Application. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2022-40178. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
微软测试广告支持的已购游戏云端串流
1 week 2 days ago
微软在一篇博客文章中透露,其已开始测试一种广告支持的方式来串流你游戏库中的游戏。这个新选项将允许玩家无需支付费用即可串流游戏。玩家无需付费,而是在游玩环节开始前观看广告。观看完毕后,他们随后将被允许串