Entry Thumbnail

dTRINITY dLEND Index Manipulation

# dTRINITY dLEND cbBTC Liquidity Index Manipulation On 2026-03-18, the dTRINITY dLEND lending protocol (an Aave v3 fork deployed on Ethereum mainnet) was exploited through a **flash loan abuse combined with a logic error** in the flash loan repayment accounting. An attacker manipulated the cbBTC reserve’s liquidity index from 1.0 […]

Posted by
Entry Thumbnail

Hangzhou Hikvision Digital Technology Co., Ltd. Face Recognition Modules SADP XML parsing stack-based buffer overflow vulnerability

CVE-2025-66176 A stack-based buffer overflow vulnerability exists in the SADP XML parsing functionality of Hangzhou Hikvision Digital Technology Co., Ltd. Ultra Face Recognition Terminal 3.7.60_250613 and Face Recognition Terminal for Turnstyle 3.7.0_240524 (under emulation). A specially crafted network packet can lead to remote code execution. An attacker can send a […]

Posted by
Entry Thumbnail

Canva Affinity EMF File EMR_HEADER offDescription Out-Of-Bounds Read Vulnerability

CVE-2025-61979 An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. The versions below were either tested or verified to be vulnerable […]

Posted by
Entry Thumbnail

Canva Affinity EMF File EMR_HEADER nDescription Out-Of-Bounds Read Vulnerability

CVE-2025-62500 An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. The versions below were either tested or verified to be vulnerable […]

Posted by