ZCyberNews
中文

Articles

432 articles

CVE-2024-57728: SimpleHelp Path Traversal Lets Admins UploadHIGH
Vulnerabilities

CVE-2024-57728: SimpleHelp Path Traversal Lets Admins Upload

CISA adds CVE-2024-57728 to Known Exploited Vulnerabilities: SimpleHelp path traversal via zip slip allows admin users to upload arbitrary files and execute code. Due May 8, 2026.

CVE-2024-57728
3 min read
CVE-2025-2749: Kentico Xperience Path Traversal Under Active ExploitHIGH
Vulnerabilities

CVE-2025-2749: Kentico Xperience Path Traversal Under Active Exploit

CISA adds CVE-2025-2749 to KEV catalog: Kentico Xperience path traversal lets authenticated Staging Sync Server upload arbitrary files. Due date for federal agencies: May 4, 2026.

CVE-2025-2749
3 min read
EMQX QoS 2 Race Condition CVE-2026-8741 Affects Up to 6.2.0HIGH
Vulnerabilities

EMQX QoS 2 Race Condition CVE-2026-8741 Affects Up to 6.2.0

CVE-2026-8741 (CVSS 3.1) enables remote exploitation of a race condition in EMQX's QoS 2 PUBLISH packet handler, affecting all versions up to 6.2.0.

CVE-2026-8741
3 min read
Grafana GitHub Token Breach Lets Attacker Download Full CodebaseHIGH
Industry News

Grafana GitHub Token Breach Lets Attacker Download Full Codebase

An attacker used a compromised GitHub token to download Grafana's entire private codebase. The company says no customer data was accessed and the incident involved an extortion...

3 min read
HACS Path Traversal CVE-2021-47942 Lets Attackers Steal HomeHIGH
Vulnerabilities

HACS Path Traversal CVE-2021-47942 Lets Attackers Steal Home

CVE-2021-47942 (CVSS 7.5) in Home Assistant Community Store 1.10.0 lets unauthenticated attackers read .storage/auth files via /hacsfiles/ traversal, forge JWT tokens, and gain...

CVE-2021-47942
3 min read
Open5GS AMF Flaw CVE-2026-8743 Enables Remote Authorization BypassMEDIUM
Vulnerabilities

Open5GS AMF Flaw CVE-2026-8743 Enables Remote Authorization Bypass

CVE-2026-8743 (CVSS 6.5) in Open5GS up to 2.7.6 lets remote attackers bypass authorization via the AMF/MME ranuefindbyamfuengap_id function. Exploit public.

CVE-2026-8743
3 min read
Open5GS NRF DoS CVE-2026-8731 Lets Remote Attackers Crash SBI ClientMEDIUM
Vulnerabilities

Open5GS NRF DoS CVE-2026-8731 Lets Remote Attackers Crash SBI Client

CVE-2026-8731 (CVSS 4.3) in Open5GS up to 2.7.7 lets remote attackers trigger a denial-of-service via the NRF component's SBI client_pool argument. Exploit code is public.

CVE-2026-8731
3 min read
Pixel 10 VPU Driver Bug Lets Userspace Map Kernel MemoryHIGH
Vulnerabilities

Pixel 10 VPU Driver Bug Lets Userspace Map Kernel Memory

Google Project Zero found a Pixel 10 VPU driver flaw allowing userspace to map arbitrary physical memory, including the kernel image. Exploit required 5 lines of code.

CVE-2025-54957
4 min read
PublicCMS Payment Logic Flaw CVE-2026-8738 Allows UnauthorizedMEDIUM
Vulnerabilities

PublicCMS Payment Logic Flaw CVE-2026-8738 Allows Unauthorized

CVE-2026-8738 (CVSS 6.5) in Sanluan PublicCMS 5.202506.d lets remote attackers manipulate the trade payment flow via business logic errors in TradeOrderController.pay.

CVE-2026-8738
3 min read
AI Agents Automate Exploitation of Obscure VulnerabilitiesHIGH
Industry News

AI Agents Automate Exploitation of Obscure Vulnerabilities

AI agents now discover and exploit obscure vulnerabilities autonomously, while AI-generated code floods pipelines with flaws. Defenders must adapt to agent-scale threats.

3 min read
Avada Builder WordPress Plugin Flaws Expose Site CredentialsHIGH
Vulnerabilities

Avada Builder WordPress Plugin Flaws Expose Site Credentials

CVE-2026-4782 and CVE-2026-4798 in Avada Builder (1M+ installs) let attackers read wp-config.php and extract database hashes. Patch to version 3.15.3.

CVE-2026-4782CVE-2026-4798
3 min read
Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape RiskHIGH
Vulnerabilities

Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape Risk

CVE-2026-8573 (CVSS 8.3) and CVE-2026-8577 (CVSS 8.8) in Chrome 148 on Windows allow sandbox escape and RCE via crafted video or HTML pages. Update now.

CVE-2026-8577CVE-2026-8573
4 min read
← PrevPage 2 of 36Next →