The National Institute of Standards and Technology (NIST) has announced changes to the way it handles cybersecurity vulnerabilities and exposures (CVEs) listed in its National Vulnerability Database (NVD), stating it will only enrich those that fulfil certain conditions owing to an explosion in CVE submissions.
"CVEs that do not meet those criteria will still be listed in the NVD but will not
23-year-old Kamerin Stokes of Memphis, Tennessee, was sentenced to 30 months in prison for selling access to tens of thousands of hacked DraftKings accounts. [...]
A vulnerability categorized as critical has been discovered in unitecms Unlimited Elements for Elementor Plugin up to 2.0.6 on WordPress. This affects the function URLtoRelative/URLToPath of the component Setting Handler. Executing a manipulation of the argument URL can lead to path traversal.
This vulnerability is registered as CVE-2026-4659. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in essentialplugin Accordion and Accordion Slider Plugin 1.4.6 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in embedded malicious code.
This vulnerability is cataloged as CVE-2026-6443. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in flightbycanto Canto Plugin up to 3.1.1 on WordPress. It has been declared as critical. Affected by this vulnerability is the function updateOptions of the file class-canto.php. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2026-6441. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Qihui jtbc5 CMS 5.0.3.6. It has been classified as problematic. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This manipulation of the argument path causes path traversal.
This vulnerability is tracked as CVE-2026-6487. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in classroombookings up to 2.17.0 and classified as problematic. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting.
This vulnerability is identified as CVE-2026-6486. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
日程安排平台 Cal.com 最近宣布从开源转为闭源,理由是 AI 工具更容易从开源代码中发现漏洞,而安全性依赖于模糊,因此闭源有助于提高安全。开源论坛软件 Discourse 对此做出了回应,强调会继续开源,同时表示不敢苟同其对软件安全的看法。Discourse 认为 AI 工具并不需要源代码去发现漏洞,它们针对的是编译后的二进制文件和黑盒 API。闭源并不会让软件更安全。世界最重要的互联网基础设施运行在以 Linux 为代表的开源软件之上,开源代码时刻暴露在无数人的注视之下。它遭受无情的攻击,但也在无止境的加固。这就是安全领域开源真正的意义所在:透明性不是消除风险,但能带来更强大的防御能力。开源带来了一种紧迫感:当代码公开时,你会预料到代码会被仔细审查,因此会更早更积极投入资源,在攻击者前面发现和修复问题。闭源只是给你带来虚幻的安全感。