Aggregator
2026-05-31: Seven days of scans and probes and web traffic hitting my web server
5 days 13 hours hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
3 hours 28 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CVE-2026-50522
6 hours ago
Currently trending CVE - Hype Score: 6 - Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-13230
6 hours ago
Currently trending CVE - Hype Score: 1 - An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes
sensitive geolocation information without requiring authentication. This issue
allows an attacker on the same local network to retrieve ...
CVE-2026-9770
6 hours ago
Currently trending CVE - Hype Score: 1 - Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem
that is shared across devices. An
attacker with access to the firmware image can extract the embedded key.
Successful
exploitation may allow an ...
CVE-2026-60137
6 hours ago
Currently trending CVE - Hype Score: 19 - WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVE-2026-63030
6 hours ago
Currently trending CVE - Hype Score: 19 - WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
CVE-2026-58644
6 hours ago
Currently trending CVE - Hype Score: 1 - Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-15410
6 hours ago
Currently trending CVE - Hype Score: 2 - Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute ...
CVE-2026-15409
6 hours ago
Currently trending CVE - Hype Score: 3 - A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
CVE-2026-27510
6 hours ago
Currently trending CVE - Hype Score: 10 - Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores ...
CVE-2026-27509
6 hours ago
Currently trending CVE - Hype Score: 10 - Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join ...
KRYBIT
6 hours 53 minutes ago
You must login to view this content
cohenido
Payload
7 hours 19 minutes ago
You must login to view this content
cohenido
RALord
7 hours 55 minutes ago
You must login to view this content
cohenido
RALord
7 hours 56 minutes ago
You must login to view this content
cohenido
Qilin
9 hours 14 minutes ago
You must login to view this content
cohenido
《半秒钟》——XZ 后门启示录
9 hours 20 minutes ago
2024 年 3月 29 日,一位微软工程师在家执行例行测试时,发现登录测试机的时间比往常慢了约半秒。大多数人都不会认为这是什么大问题。但他却深入展开了调查,在流行压缩工具 XZ Utils 中发现了一个故意植入的隐蔽后门。有人花了两年时间才把后门植入到该工具中。Adrian Mastronardi 发表了一本关于 XZ 后门事件的书《Half a Second》,在非商业使用、禁止衍生的 CC 许可证(CC BY-NC-ND 4.0)下免费提供。本书讲述了
一位精疲力竭的志愿者独自维护着代码,被耐心而巧妙的操纵,最终交出了代码的维护权;一位工程师凭借一连串的运气和来之不易的直觉,在半秒钟的好奇心驱使下发现了这次攻击;以及构建该后门的幕后操纵者,此人至今身份不明,其身份可能永远也无法被揭露。
AI驱动的内存紧缺冲击印度智能手机市场
11 hours 32 minutes ago
AI驱动的内存紧缺冲击印度智能手机市场根据市场研究公司 Counterpoint Research 的数据,印度作为全球仅次于中国的第二大智能手机出货市场,在4月至6月季度中智能手机出货量同比下降10