Aggregator
PHP曝两大高危漏洞:CVE-2025-1735(SQL注入/崩溃)与CVE-2025-6491(SOAP拒绝服务)威胁众多Web应用
5 months 1 week ago
安全客
巴西CIEE平台曝重大数据泄露:超24.8万份简历、病历与视频外泄,源头为谷歌云存储配置错误
5 months 1 week ago
安全客
Apache APISIX 存在 OpenID Connect 身份验证绕过漏洞(CVE-2025-46647):可跨 Issuer 非授权访问
5 months 1 week ago
安全客
Lucee 高危漏洞(CVE-2025-34074,CVSS 9.4):计划任务被滥用,Metasploit 模块已上线
5 months 1 week ago
安全客
Alleged Data Breach of Schrödinger
5 months 1 week ago
Alleged Data Breach of Schrödinger
Dark Web Informer - Cyber Threat Intelligence
善用表情符号能在交流中给对方留下好印象
5 months 1 week ago
在全球范围内,表情符号每天被使用超过 100 亿次,为数字对话注入微妙的情感。然而它们对人们如何理解这些对话的实际影响尚不清楚——虽然这些小符号经常被积极解读,但有时也会被误读并引起误解。因此研究人员评估了表情符号如何影响人们对发送表情符号的人的看法。在研究中,美国 260 名参与者被要求阅读 15 段基于文本的对话,并想象他们与一位密友进行了这些交流。这些对话要么仅有纯文本回复,要么包含表情符号。阅读完这些对话样本后,参与者被问及一系列关于他们对消息发送者的感受的问题。总体而言,参与者认为包含表情符号的消息比纯文本消息回应得更积极。这使发件人更讨人喜欢,使两者关系显得更亲近。令人惊讶的是,这种效果的产生与使用的表情符号类型无关,无论是直接表达发件人情绪的表情符号——比如笑脸,还是展示其他物体的中性表情符号,两者并没有产生实质差异。
xAI预推出“Grok 4 Code”,剑指Claude与Gemini编程能力霸主地位
5 months 1 week ago
安全客
大规模Android诈骗曝光:352款广告恶意App、NFC盗刷、短信木马肆虐全球
5 months 1 week ago
安全客
Cisco修复统一通信平台严重漏洞(CVE-2025-20309):默认Root账号可被远程接管
5 months 1 week ago
安全客
Google发布VeO 3视频生成模型:AI助力电影级画面创作正式开放使用
5 months 1 week ago
安全客
CVE-2025-49274 | Neom Blog Theme up to 0.0.9 on WordPress cross site scripting (EUVD-2025-19986)
5 months 1 week ago
A vulnerability classified as problematic has been found in Neom Blog Theme up to 0.0.9 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-49274. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-49247 | Team Showcase Plugin up to 25.05.12 on WordPress cross site scripting (EUVD-2025-19985)
5 months 1 week ago
A vulnerability was found in Team Showcase Plugin up to 25.05.12 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-49247. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50032 | Paytiko for WooCommerce Plugin up to 1.3.14 on WordPress authorization (EUVD-2025-19992)
5 months 1 week ago
A vulnerability was found in Paytiko for WooCommerce Plugin up to 1.3.14 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-50032. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-49866 | Nikel Beautiful Cookie Consent Banner Plugin up to 4.6.1 on WordPress cross site scripting (EUVD-2025-19989)
5 months 1 week ago
A vulnerability has been found in Nikel Beautiful Cookie Consent Banner Plugin up to 4.6.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-49866. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-47627 | LCweb PrivateContent Plugin up to 2.3.2 on WordPress filename control (EUVD-2025-19981)
5 months 1 week ago
A vulnerability has been found in LCweb PrivateContent Plugin up to 2.3.2 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is known as CVE-2025-47627. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-47634 | Keylor Mendoza WC Pickup Store Plugin up to 1.8.9 on WordPress authorization (EUVD-2025-19982)
5 months 1 week ago
A vulnerability classified as critical has been found in Keylor Mendoza WC Pickup Store Plugin up to 1.8.9 on WordPress. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-47634. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-47565 | ashanjay EventON Plugin up to 4.9.9 on WordPress authorization (EUVD-2025-19980)
5 months 1 week ago
A vulnerability was found in ashanjay EventON Plugin up to 4.9.9 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2025-47565. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-48231 | codepeople Booking Calendar Contact Form Plugin up to 1.2.58 on WordPress cross site scripting (EUVD-2025-19983)
5 months 1 week ago
A vulnerability was found in codepeople Booking Calendar Contact Form Plugin up to 1.2.58 on WordPress. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-48231. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-39487 | Rankie Plugin up to 1.8.2 on WordPress cross site scripting (EUVD-2025-19978)
5 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Rankie Plugin up to 1.8.2 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-39487. The attack may be launched remotely. There is no exploit available.
vuldb.com