Aggregator
Ищет дыры не хуже Mythos, а токенов жрёт втрое меньше. OpenAI выкатила GPT-5.6 Sol для кибербеза
18 hours 54 minutes ago
Новая линейка Sol, Terra и Luna рассчитана на сложные технические задачи, но пока доступна только ограниченному кругу клиентов.
CVE-2026-9677 | Shariff for WordPress Plugin up to 1.0.11 on WordPress Setting generateshariff shariff_infourl cross site scripting (EUVD-2026-39947)
19 hours 9 minutes ago
A vulnerability classified as problematic was found in Shariff for WordPress Plugin up to 1.0.11 on WordPress. The impacted element is the function generateshariff of the component Setting Handler. Executing a manipulation of the argument shariff_infourl can lead to cross site scripting.
This vulnerability appears as CVE-2026-9677. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-13245 | maxfoundry MaxButtons Plugin up to 9.8.5 on WordPress view cross site scripting (EUVD-2026-39944)
19 hours 9 minutes ago
A vulnerability classified as problematic has been found in maxfoundry MaxButtons Plugin up to 9.8.5 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument view results in cross site scripting.
This vulnerability is reported as CVE-2026-13245. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-12404 | webaways NEX-Forms Plugin up to 9.2.2 on WordPress authorization (EUVD-2026-39945)
19 hours 10 minutes ago
A vulnerability described as problematic has been identified in webaways NEX-Forms Plugin up to 9.2.2 on WordPress. Impacted is an unknown function. Such manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-12404. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-10820 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin authorization (EUVD-2026-39946)
19 hours 10 minutes ago
A vulnerability marked as critical has been reported in Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin up to 4.16.16 on WordPress. This issue affects some unknown processing. This manipulation causes authorization bypass.
This vulnerability is registered as CVE-2026-10820. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
A deep dive into SmallVector::push_back
19 hours 20 minutes ago
SmallVector is LLVM's most-used container, andpush_back its hot operation. For the
Свиток превратился в кусок угля при извержении Везувия. Теперь его прочитали от начала до конца — а внутри оказался трактат о том, как жить достойно
19 hours 35 minutes ago
Машинное обучение взломало древнюю капсулу времени.
[iOS捷径] 添加Codex捷径实现快速启动 无需每次点击ChatGPT再转到Codex
19 hours 44 minutes ago
2026年6月27日 14:36下载00.68K
苹果拟向中国长鑫存储科技采购内存芯片
20 hours 3 minutes ago
六名知情人士透露,苹果公司正在游说特朗普政府,寻求获准从长鑫存储科技采购内存芯片;而长鑫存储科技因被指与中国人民解放军有联系,已被五角大楼列入黑名单。这家iPhone制造商一直在游说白宫,希望获得批准
Вэнс укусил Трампа и заразил его бешенством. ИИ-поисковики поверили в фейк, который реддиторы запустили ради эксперимента
20 hours 16 minutes ago
Фальшивые посты, скриншоты и псевдосайт помогли выдуманной истории пройти через фильтры доверия.
不同数据库被”拖库”特征-托管vs自建+是/否开启审计日志取证实测
20 hours 50 minutes ago
在入侵类应急响应中,客户最常见的诉求之一是:“帮我判断数据库到底有没有被黑客拖库?” 但数据库类型种阅读更多
Zgao
不同数据库被”拖库”特征-托管vs自建+是/否开启审计日志取证实测
20 hours 50 minutes ago
在入侵类应急响应(IR)中,客户最常见的诉求之一是:“帮我判断数据库到底有没有被黑客拖库?” 但数据库类型五花八门(MySQL、PostgreSQL、Redis、MongoDB、SQL
Представь: заходишь в класс, а учитель — гуманоидный робот. Это уже происходит в одной из школ
21 hours 9 minutes ago
Американцы решили опробовать ИИ-помощника Optio в роли преподавателя. И вот, что из этого вышло…
OpenAI推出GPT-5.6 但因为美国政府要求 新模型仅面向少数合作伙伴开放预览权限
21 hours 10 minutes ago
CVE-2026-36907 | Axiomatic axiomatic-systems prior 1.8.9 AP4_StsdAtom stack-based overflow (Issue 1005 / EUVD-2026-39934)
21 hours 16 minutes ago
A vulnerability labeled as critical has been found in Axiomatic axiomatic-systems. This vulnerability affects the function AP4_StsdAtom::AP4_StsdAtom. The manipulation results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2026-36907. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-50767 | Koha Library Management System up to 25.11 cross site scripting (EUVD-2026-39942)
21 hours 17 minutes ago
A vulnerability identified as problematic has been detected in Koha Library Management System up to 25.11. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-50767. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-50766 | Koha Library Management System up to 25.11 cross site scripting (EUVD-2026-39941)
21 hours 17 minutes ago
A vulnerability categorized as problematic has been discovered in Koha Library Management System up to 25.11. Affected by this issue is some unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-50766. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-50765 | Koha Library Management System up to 25.11 cross site scripting (EUVD-2026-39940)
21 hours 17 minutes ago
A vulnerability was found in Koha Library Management System up to 25.11. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-50765. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-54350 | budibase up to 3.39.11 JSON Parser queries.ts collection.find sql injection (GHSA-8qv3-p479-cj62 / EUVD-2026-39914)
21 hours 17 minutes ago
A vulnerability was found in budibase up to 3.39.11. It has been declared as critical. Affected is the function collection.find of the file packages/server/src/sdk/workspace/queries/queries.ts of the component JSON Parser. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-54350. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com