Posts of last few hours
A vulnerability marked as critical has been reported in Roskus Prospero Flow CRM up to 5.4.6. This vulnerability affects the function ProductRepository::save of the component Product Management. This manipulation of the argument ID causes improper authorization.
This vulnerability is handled as CVE-2026-19734. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/389492
A vulnerability was found in maalfer Pentestify up to 2.3.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Markdown renderer. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-19744. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/389654
A vulnerability categorized as critical has been discovered in Zalktis Programmas Zalktis up to 2026.1.585/2026.2.591. This issue affects the function Dazadi.sql_txt of the component Invoice Import. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-59109. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/389713
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html
A vulnerability categorized as critical has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2026-86210. The attack may be launched remotely. Furthermore, there is an exploit available.
https://vuldb.com/vuln/399345
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. It has been rated as critical. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection.
This vulnerability appears as CVE-2026-86209. The attack may be initiated remotely. In addition, an exploit is available.
https://vuldb.com/vuln/399344
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. It has been declared as critical. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection.
This vulnerability is reported as CVE-2026-86208. The attack can be launched remotely. Moreover, an exploit is present.
https://vuldb.com/vuln/399343
Submit #896590 / VDB-399345
https://vuldb.com/submit/896590
Submit #896589 / VDB-399344
https://vuldb.com/submit/896589
Submit #896588 / VDB-399343
https://vuldb.com/submit/896588
https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497107&idx=1&sn=ce97a317ab04587edd2ce4697fd1db90
两年前,蒂姆·安德鲁斯疲惫不堪,唯一想做的就是睡觉。糖尿病和高血压毁掉了他的肾脏,而通过过滤血液维持他生命的频繁透析治疗令人精疲力竭。尽管只有 66 岁,他却毫无精力与食欲,虚弱得无法行走,还曾两次心脏病发作。肾移植本可以救他的命,但器官供应短缺。根据美国器官共享联合网络的数据,约有 9 万人在等待肾移植,平均每天有 11 人在等待中去世。而且由于安德鲁斯的血型较为罕见,他获得匹配的人类肾脏的几率尤其渺茫。当他听说麻省总医院布里格姆的医生正在为患者移植转基因猪的肾脏时,他主动联系了他们。“我想,如果我要死了,不如为人类做点事,参与这个实验,”他说。2025 年 1 月 25 日,安德鲁斯接受了转基因猪肾的移植,带着它生活了九个月。今年他成为已知首例在猪肾移植后接受人类供体肾脏的患者,周四发表于《柳叶刀》的一篇论文中描述了这一里程碑式的成就。他的病例为移植医学中一个引人关注的概念提供了初步证据:猪肾虽尚非永久性解决方案,但可以作为通往人类器官移植的“桥梁”。这些猪肾来自经过大量基因编辑的猪,其中一些编辑旨在防止严重的器官排斥反应,还有一些用于灭活猪基因组中的病毒。
https://www.solidot.org/story?sid=85295
Специалисты прогнали 188000 объявлений через Gemma и нашли тысячи материалов, которые уже прошли модерацию.
https://www.securitylab.ru/news/576936.php
一周前,Debian 项目经过投票允许以负责任的方式使用生成式 AI,Debian 项目表示,它既不反对也不支持在软件、包、文档等的开发和维护中使用生成式 AI 工具。但项目也认识到,如果能负责任的使用 AI 工具,将能显著提高贡献者的效率,使他们将有限的时间投入到需要技术专长、判断力、审核和协作的工作中。现在,Android 自由软件应用商店 F-Droid 考虑采用与 Debian 相同的 AI 政策,它的政策提议直接拷贝了 Debian 的政策全文,只是将 Debian 的名字替换为 F-Droid。
https://www.solidot.org/story?sid=85294
A vulnerability was found in WWBN AVideo up to 29.0. It has been classified as problematic. This affects an unknown function of the component YPTSocket Plugin. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-86188. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/399342
A vulnerability was found in GetGrav Grav up to 2.0.19 and classified as problematic. The impacted element is the function addJs of the file Grav/Common/Assets of the component Twig Sandbox Policy. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2026-86197. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/399341
A vulnerability has been found in Grav Form Plugin up to 9.1.21 and classified as critical. The affected element is an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-86194. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/399340
A vulnerability, which was classified as problematic, was found in getgrav API Plugin up to 1.0.19. Impacted is an unknown function of the component Forgot-Password Endpoint. Such manipulation leads to open redirect.
This vulnerability is listed as CVE-2026-86196. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/399339
A vulnerability, which was classified as critical, has been found in GetGrav grav-plugin-api up to 1.0.19. This issue affects the function stripSuperFlags of the component InvitationsController. This manipulation causes improper privilege management.
This vulnerability is tracked as CVE-2026-86195. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/399338
A vulnerability classified as problematic was found in GetGrav Grav Plugin up to 1.0.19. This vulnerability affects unknown code of the component User Management Guards. The manipulation results in improper privilege management.
This vulnerability is identified as CVE-2026-86193. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/399337
Latest Blog Posts
- 1 week 6 days ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago