Posts of last few hours
A vulnerability marked as critical has been reported in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection.
This vulnerability is known as CVE-2026-86223. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
https://vuldb.com/vuln/399376
A vulnerability labeled as critical has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection.
This vulnerability is traded as CVE-2026-86222. The attack may be launched remotely. Furthermore, there is an exploit available.
https://vuldb.com/vuln/399375
A vulnerability identified as critical has been detected in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection.
This vulnerability appears as CVE-2026-86221. The attack may be initiated remotely. In addition, an exploit is available.
https://vuldb.com/vuln/399374
A vulnerability categorized as critical has been discovered in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection.
This vulnerability is reported as CVE-2026-86220. The attack can be launched remotely. Moreover, an exploit is present.
https://vuldb.com/vuln/399373
A vulnerability was found in DynamiApps Frontend Admin Plugin up to 3.29.12 on WordPress. It has been rated as critical. Impacted is the function ActionPost::conditions_logic. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-75816. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/399372
A vulnerability was found in MemberDash Plugin up to 1.8.5 on WordPress. It has been declared as critical. This issue affects some unknown processing. Executing a manipulation of the argument ID can lead to authorization bypass.
This vulnerability is registered as CVE-2026-16310. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/399371
A vulnerability was found in HivePress Authentication Plugin up to 1.1.4 on WordPress. It has been classified as critical. This vulnerability affects the function authenticate_user of the component Facebook Authenticator. Performing a manipulation of the argument access_token results in improper authentication.
This vulnerability is cataloged as CVE-2026-18056. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/399370
A vulnerability was found in N-able N-central up to 2026.3.1.13 and classified as critical. This affects an unknown part. Such manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-86218. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/399369
Vulnerability / Network SecurityAttackers are exploiting MikroTik routers with their Secure Shell
https://buaq.net/go-440463.html
The Python Risk Identification Tool for generative AI (PyRIT) is an open sourceframework built to
https://buaq.net/go-440461.html
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER
https://buaq.net/go-440464.html
Будущее из «Терминатора» пока выглядит как старая немецкая вики.
https://www.securitylab.ru/news/576985.php
We use cookies on our website to give you the most relevant experience by remembering your preferenc
https://buaq.net/go-440465.html
微软杰出工程师直言「手敲代码彻底过时」;小米澎程武士黑套装官图公布;全球首例:我国完成人工智能超声机器人引导下先天性心脏病封堵术
https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113208&idx=1&sn=9e1f7a7a30522b1f04454ea5f1262a3e
本文通过拆解六款智能渗透 Agent 的源码与真实执行链路,分析它们在状态管理、上下文控制、工具调用和证据约束上的工程设计与取舍。
https://xz.aliyun.com/news/92778
本文记录了一次基于Linux的后门的分析过程。分析从投递器脚本入手,由投递器带出s、p、p2、mulu-agent-c 四个文件,文章分别对投递器和四个恶意文件进行详细分析。
https://xz.aliyun.com/news/92662
2026 年 8 月16日,笔者在处置一起服务器入侵事件时,发现攻击者通过篡改宝塔面板 nginx 全局配置(16 个 `enable-php-*.conf`)注入 `sub_filter` 恶意指令,对全站实施"仅移动端 + 搜索引擎来源 + 中国时区"的精准流量劫持。沿恶意 JS 的 C2 基础设施逐层追踪,最终挖出一个**集"蜘蛛池软件销售 + 网站流量劫持服务"于一体的黑产 SEO 团伙*
https://xz.aliyun.com/news/92709
把确定性留给系统,把不确定性交给模型。
https://xz.aliyun.com/news/92758
Latest Blog Posts
- 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago