ZCyberNews
中文

Articles

460 articles

CVE-2026-7301: SGLang Scheduler RCE via Pickle DeserializationCRITICAL
Vulnerabilities

CVE-2026-7301: SGLang Scheduler RCE via Pickle Deserialization

CVE-2026-7301 (CVSS 9.8) lets attackers execute arbitrary code on SGLang servers by sending malicious pickle payloads to the scheduler's ROUTER socket, which binds to 0.0.0.0 by...

CVE-2026-7301
4 min read
CVE-2026-8836: CVSS 10.0 Stack Overflow in lwIP SNMPv3 ParserCRITICAL
Vulnerabilities

CVE-2026-8836: CVSS 10.0 Stack Overflow in lwIP SNMPv3 Parser

CVE-2026-8836 is a CVSS 10.0 stack-based buffer overflow in lwIP up to 2.2.1's SNMPv3 USM handler. Remote unauthenticated attackers can trigger code execution via crafted...

CVE-2026-8836
3 min read
Cookie Law Bar 1.2.1 Stored XSS Enables Cookie TheftMEDIUM
Vulnerabilities

Cookie Law Bar 1.2.1 Stored XSS Enables Cookie Theft

CVE-2021-47957 (CVSS 6.4) in Cookie Law Bar 1.2.1 lets authenticated attackers inject persistent scripts via the Bar Message field, affecting all WordPress site visitors.

CVE-2021-47957
3 min read
CouchCMS 2.2.1 XSS Lets Authenticated Users Inject Arbitrary JS viaMEDIUM
Vulnerabilities

CouchCMS 2.2.1 XSS Lets Authenticated Users Inject Arbitrary JS via

CVE-2021-47955 (CVSS 5.4): CouchCMS 2.2.1 contains a stored XSS flaw allowing authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files via...

CVE-2021-47955
3 min read
CVE-2024-57728: SimpleHelp Path Traversal Lets Admins UploadHIGH
Vulnerabilities

CVE-2024-57728: SimpleHelp Path Traversal Lets Admins Upload

CISA adds CVE-2024-57728 to Known Exploited Vulnerabilities: SimpleHelp path traversal via zip slip allows admin users to upload arbitrary files and execute code. Due May 8, 2026.

CVE-2024-57728
3 min read
CVE-2025-2749: Kentico Xperience Path Traversal Under Active ExploitHIGH
Vulnerabilities

CVE-2025-2749: Kentico Xperience Path Traversal Under Active Exploit

CISA adds CVE-2025-2749 to KEV catalog: Kentico Xperience path traversal lets authenticated Staging Sync Server upload arbitrary files. Due date for federal agencies: May 4, 2026.

CVE-2025-2749
3 min read
EMQX QoS 2 Race Condition CVE-2026-8741 Affects Up to 6.2.0HIGH
Vulnerabilities

EMQX QoS 2 Race Condition CVE-2026-8741 Affects Up to 6.2.0

CVE-2026-8741 (CVSS 3.1) enables remote exploitation of a race condition in EMQX's QoS 2 PUBLISH packet handler, affecting all versions up to 6.2.0.

CVE-2026-8741
3 min read
Grafana GitHub Token Breach Lets Attacker Download Full CodebaseHIGH
Industry News

Grafana GitHub Token Breach Lets Attacker Download Full Codebase

An attacker used a compromised GitHub token to download Grafana's entire private codebase. The company says no customer data was accessed and the incident involved an extortion...

3 min read
HACS Path Traversal CVE-2021-47942 Lets Attackers Steal HomeHIGH
Vulnerabilities

HACS Path Traversal CVE-2021-47942 Lets Attackers Steal Home

CVE-2021-47942 (CVSS 7.5) in Home Assistant Community Store 1.10.0 lets unauthenticated attackers read .storage/auth files via /hacsfiles/ traversal, forge JWT tokens, and gain...

CVE-2021-47942
3 min read
Open5GS AMF Flaw CVE-2026-8743 Enables Remote Authorization BypassMEDIUM
Vulnerabilities

Open5GS AMF Flaw CVE-2026-8743 Enables Remote Authorization Bypass

CVE-2026-8743 (CVSS 6.5) in Open5GS up to 2.7.6 lets remote attackers bypass authorization via the AMF/MME ranuefindbyamfuengap_id function. Exploit public.

CVE-2026-8743
3 min read
Open5GS NRF DoS CVE-2026-8731 Lets Remote Attackers Crash SBI ClientMEDIUM
Vulnerabilities

Open5GS NRF DoS CVE-2026-8731 Lets Remote Attackers Crash SBI Client

CVE-2026-8731 (CVSS 4.3) in Open5GS up to 2.7.7 lets remote attackers trigger a denial-of-service via the NRF component's SBI client_pool argument. Exploit code is public.

CVE-2026-8731
3 min read
Pixel 10 VPU Driver Bug Lets Userspace Map Kernel MemoryHIGH
Vulnerabilities

Pixel 10 VPU Driver Bug Lets Userspace Map Kernel Memory

Google Project Zero found a Pixel 10 VPU driver flaw allowing userspace to map arbitrary physical memory, including the kernel image. Exploit required 5 lines of code.

CVE-2025-54957
4 min read
← PrevPage 4 of 39Next →