Current Conditions
São Paulo
nevoeiro

20 ℃
94%
Temperatura
Umidade
Fonte: OpenWeatherMap. - 19:00:02
  1. [USD] USD 69,782.84
  1. [BRL] BRL 360,442.34 [USD] USD 69,782.84 [GBP] GBP 52,004.83 [EUR] EUR 60,091.33
    Price index provided by blockchain.info.
  2. Bitcoin Core version 29.3 is now available for download. See the release notes for more information about the bug fixes in this release.
    If you have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.

[CVE-2025-43723] [Modified: 20-02-2026] [Analyzed] [V3.1 S5.9:MEDIUM] Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

[CVE-2025-47286] [Modified: 21-11-2025] [Analyzed] [V3.1 S7.2:HIGH] Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of the iTop instance, execute code on the server. Versions 2.7.13 and 3.2.2 escape and check the config parameter before executing a command based on it.

[CVE-2025-47773] [Modified: 21-11-2025] [Analyzed] [V3.1 S8.8:HIGH] Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is edited via an AJAX call. Versions 2.7.13 and 3.2.2 protect rendered HTML content.

[CVE-2025-63288] [Modified: 11-12-2025] [Analyzed] [V3.1 S7.5:HIGH] In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

[CVE-2025-12428] [Modified: 13-11-2025] [Analyzed] [V3.1 S8.8:HIGH] Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

[CVE-2025-12429] [Modified: 13-11-2025] [Analyzed] [V3.1 S8.8:HIGH] Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

[CVE-2025-12430] [Modified: 13-11-2025] [Analyzed] [V3.1 S7.5:HIGH] Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

[CVE-2025-12431] [Modified: 13-11-2025] [Analyzed] [V3.1 S6.5:MEDIUM] Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)

[CVE-2025-12432] [Modified: 13-11-2025] [Analyzed] [V3.1 S8.8:HIGH] Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

[CVE-2025-12433] [Modified: 13-11-2025] [Analyzed] [V3.1 S4.3:MEDIUM] Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

[CVE-2025-12434] [Modified: 13-11-2025] [Analyzed] [V3.1 S4.2:MEDIUM] Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

[CVE-2025-12435] [Modified: 13-11-2025] [Analyzed] [V3.1 S5.4:MEDIUM] Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

[CVE-2025-12436] [Modified: 13-11-2025] [Analyzed] [V3.1 S5.9:MEDIUM] Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

[CVE-2025-12437] [Modified: 13-11-2025] [Analyzed] [V3.1 S7.5:HIGH] Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

[CVE-2025-12438] [Modified: 13-11-2025] [Analyzed] [V3.1 S8.8:HIGH] Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: Medium)

[CVE-2025-12439] [Modified: 13-11-2025] [Analyzed] [V3.1 S5.5:MEDIUM] Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)

[CVE-2025-12440] [Modified: 13-11-2025] [Analyzed] [V3.1 S5.3:MEDIUM] Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

[CVE-2025-12441] [Modified: 13-11-2025] [Analyzed] [V3.1 S4.3:MEDIUM] Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

[CVE-2025-12443] [Modified: 13-11-2025] [Analyzed] [V3.1 S4.3:MEDIUM] Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

[CVE-2025-12444] [Modified: 13-11-2025] [Analyzed] [V3.1 S4.2:MEDIUM] Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)