Current Conditions
São Paulo
nuvens quebradas

16 ℃
85%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 23:00:02
  1. [USD] USD 89,802.54
  1. [BRL] BRL 474,588.48 [USD] USD 89,802.54 [GBP] GBP 66,521.41 [EUR] EUR 76,417.92
    Price index provided by blockchain.info.
  2. Bitcoin Core version 30.2 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-10940] [Modified: 16-01-2026] [Analyzed] [V3.1 S2.4:LOW] A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing manipulation of the argument HTML results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

[CVE-2025-27261] [Modified: 02-10-2025] [Analyzed] [V3.1 S9.8:CRITICAL] Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.

[CVE-2025-57317] [Modified: 16-10-2025] [Analyzed] [V3.1 S7.5:HIGH] apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess function of apidoc-core versions thru 0.15.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.

[CVE-2025-59422] [Modified: 14-10-2025] [Analyzed] [V3.1 S3.1:LOW] Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same workspace to read chat messages of other users. A regular user is able to read the query data and the filename of the admins and probably other users chats, if they know the conversation_id. This impacts the confidentiality of chats. This issue has been patched in version 1.9.0.

[CVE-2025-59426] [Modified: 08-10-2025] [Analyzed] [V3.1 S4.3:MEDIUM] Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. In deployments where a reverse proxy forwards client-supplied X-Forwarded-* headers to the origin as-is, or where the origin trusts them without validation, an attacker can inject an arbitrary host and trigger an open redirect that sends users to a malicious domain. This issue has been patched in version 1.130.1.

[CVE-2025-59831] [Modified: 16-10-2025] [Analyzed] [V3.1 S8.8:HIGH] git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. This vulnerability manifests with the library's primary exported API: gitCommiters(options, callback) which allows specifying options such as cwd for current working directory and revisionRange as a revision pointer, such as HEAD. However, the library does not sanitize for user input or practice secure process execution API to separate commands from their arguments and as such, uncontrolled user input is concatenated into command execution. This issue has been patched in version 0.1.2.

[CVE-2025-59834] [Modified: 14-10-2025] [Analyzed] [V3.1 S9.8:CRITICAL] ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition and implementation. This issue has been patched via commit 041729c.

[CVE-2025-59839] [Modified: 14-10-2025] [Analyzed] [V3.1 S8.6:HIGH] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through wikitext. This issue has been patched via commit 4e075d3.

[CVE-2025-5494] [Modified: 22-10-2025] [Analyzed] [V3.1 S3.9:LOW] ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

[CVE-2025-27262] [Modified: 02-10-2025] [Analyzed] [V3.1 S7.8:HIGH] Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.

[CVE-2025-36601] [Modified: 31-10-2025] [Analyzed] [V3.1 S4.0:MEDIUM] Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Information disclosure.

[CVE-2025-36857] [Modified: 11-12-2025] [Analyzed] [V3.1 S3.3:LOW] Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom configuration files. These files, which are loaded in alphabetical order, can override or change the settings of the original configuration files, creating a security vulnerability. This issue stems from improper directory access management. This vulnerability was remediated in version 7.5.021 of the product.

[CVE-2025-40836] [Modified: 02-10-2025] [Analyzed] [V3.1 S9.8:CRITICAL] Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.

[CVE-2025-40837] [Modified: 02-10-2025] [Analyzed] [V3.1 S8.8:HIGH] Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.

[CVE-2025-40838] [Modified: 02-10-2025] [Analyzed] [V3.1 S7.5:HIGH] Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.

[CVE-2025-46148] [Modified: 03-10-2025] [Analyzed] [V3.1 S5.3:MEDIUM] In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

[CVE-2025-46149] [Modified: 03-10-2025] [Analyzed] [V3.1 S5.3:MEDIUM] In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

[CVE-2025-46150] [Modified: 03-10-2025] [Analyzed] [V3.1 S5.3:MEDIUM] In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

[CVE-2025-46152] [Modified: 03-10-2025] [Analyzed] [V3.1 S5.3:MEDIUM] In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

[CVE-2025-46153] [Modified: 03-10-2025] [Analyzed] [V3.1 S5.3:MEDIUM] PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, and nn.Dropout3d for fallback_random=True.