Aggregator
AI 工具作弊的流行迫使普林斯顿推翻无人监考制度
1 month 1 week ago
1893 年普林斯顿大学学生请愿取消考试中教师监考的制度,大学随后制定了《荣誉规章(Honor Code)》,学生承诺——我以我的人格保证,我没有在这次考试中违反《荣誉规章》的学术诚信政策。这种无人监考的制度实施了 133 年,直到本周被投票取消,原因是 AI 作弊工具的流行。2025 年对大四学生的调查发现,29.9% 的学生承认至少在一次作业或考试中作弊。其中攻读工程学理学士(BSE)学位的学生承认作弊的比例高达 40.8%,而文学学士学生“仅”为 26.4%。作弊基本上是借助了生成式 AI 工具。荣誉规章依赖于学生举报,但手机、AI 以及不愿告密的文化,许多人对作弊行为视而不见。学生说,在考试期间男厕所排起来长队,表明了作弊的普遍。调查显示,44.6% 的大四学生目睹过作弊行为,但选择不举报。普林斯顿大学教职工本周投票取消了无人监考,这次投票只有一个人投了反对票。从 7 月 1 日开始,所有课堂考试必须由教师监考。
CVE-2026-44482 | richardhbtz soundcloud-rpc up to 0.1.7 Preload API input validation (GHSA-p37x-32p8-445f)
1 month 1 week ago
A vulnerability, which was classified as critical, was found in richardhbtz soundcloud-rpc up to 0.1.7. This affects an unknown part of the component Preload API. Executing a manipulation can lead to improper input validation.
The identification of this vulnerability is CVE-2026-44482. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-42559 | modelcontextprotocol rust-sdk up to 1.3.x streamable_http_server origin validation (ID 815)
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in modelcontextprotocol rust-sdk up to 1.3.x. Affected by this issue is some unknown functionality of the file crates/rmcp/src/transport/streamable_http_server/. Performing a manipulation results in origin validation error.
This vulnerability was named CVE-2026-42559. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-42457 | loft-sh loft up to 4.4.2/4.5.4/4.6.1/4.7.0 Name cross site scripting (GHSA-x7cq-v3h6-426c)
1 month 1 week ago
A vulnerability classified as problematic was found in loft-sh loft up to 4.4.2/4.5.4/4.6.1/4.7.0. Affected by this vulnerability is an unknown functionality. Such manipulation of the argument Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-42457. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41933 | givanz Vvveb up to 1.0.8.2 Directory Listing exposure of information through directory listing
1 month 1 week ago
A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.8.2. Affected is an unknown function of the component Directory Listing Handler. This manipulation causes exposure of information through directory listing.
This vulnerability is handled as CVE-2026-41933. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-62628 | AMD AIM-T Manageability Service prior 5.1.0.1382 OpenSSL uncontrolled search path
1 month 1 week ago
A vulnerability described as problematic has been identified in AMD AIM-T Manageability Service, Cloud Manageability Service, Management Plug-In for SCCM, Management Console, Manageability API and DASH CLI. This impacts an unknown function of the component OpenSSL. The manipulation results in uncontrolled search path.
This vulnerability is known as CVE-2025-62628. Attacking locally is a requirement. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42881 | squinky86 STIGQter up to 1.2.6 path traversal (GHSA-mcv5-5j7p-vqh7)
1 month 1 week ago
A vulnerability marked as critical has been reported in squinky86 STIGQter up to 1.2.6. This affects an unknown function. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-42881. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-44375 | AArnott Nerdbank.MessagePack up to 1.1.61 memory allocation (GHSA-2cwq-pwfr-wcw3)
1 month 1 week ago
A vulnerability labeled as problematic has been found in AArnott Nerdbank.MessagePack up to 1.1.61. The impacted element is an unknown function. Executing a manipulation can lead to uncontrolled memory allocation.
This vulnerability appears as CVE-2026-44375. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-44308 | awspring spring-cloud-aws/spring-cloud-aws-sns up to 4.0.1 HTTP Endpoint data authenticity (GHSA-r4w4-wv68-qv85)
1 month 1 week ago
A vulnerability identified as critical has been detected in awspring spring-cloud-aws and spring-cloud-aws-sns up to 4.0.1. The affected element is an unknown function of the component HTTP Endpoint. Performing a manipulation results in insufficient verification of data authenticity.
This vulnerability is reported as CVE-2026-44308. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-44484 | Lightning-AI pytorch-lightning 2.6.2/2.6.3 malicious code (GHSA-w37p-236h-pfx3)
1 month 1 week ago
A vulnerability categorized as critical has been discovered in Lightning-AI pytorch-lightning 2.6.2/2.6.3. Impacted is an unknown function. Such manipulation leads to embedded malicious code.
This vulnerability is documented as CVE-2026-44484. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-44216 | bytecodealliance wasmtime up to 36.0.7/43.0.1/44.0.0 WebAssembly allocation of resources
1 month 1 week ago
A vulnerability was found in bytecodealliance wasmtime up to 36.0.7/43.0.1/44.0.0. It has been rated as problematic. This issue affects some unknown processing of the component WebAssembly Module. This manipulation causes allocation of resources.
This vulnerability is registered as CVE-2026-44216. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-62619 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics KVM Key Download Endpoint missing authentication
1 month 1 week ago
A vulnerability was found in AMD Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 3000 Desktop Processors, Ryzen Threadripper PRO 3000 WX-Series Processors, Ryzen 7030 Mobile Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen 9000HX Processors, Ryzen AI 300 Processors, Ryzen Threadripper PRO 5000 WX-Series Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 4000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen AI Max 300 Processors, Not public, Ryzen Threadripper PRO 9000 WX-Series Processors and Device Management Portal. It has been declared as critical. This vulnerability affects unknown code of the component KVM Key Download Endpoint. The manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2025-62619. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-44371 | OSC ondemand up to 4.0.10/4.1.4/4.2.1 File Browser cross site scripting (GHSA-xcv4-m435-m33h)
1 month 1 week ago
A vulnerability was found in OSC ondemand up to 4.0.10/4.1.4/4.2.1. It has been classified as problematic. This affects an unknown part of the component File Browser. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-44371. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42186 | OpenBao up to 2.5.2 improper removal of sensitive information before storage or transfer (GHSA-vv66-6rp4-wr4f)
1 month 1 week ago
A vulnerability was found in OpenBao up to 2.5.2 and classified as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper removal of sensitive information before storage or transfer.
This vulnerability is tracked as CVE-2026-42186. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-62625 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics KVM Key Download privileges management
1 month 1 week ago
A vulnerability has been found in AMD Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7020 Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 3000 Desktop Processors, Ryzen Threadripper PRO 3000 WX-Series Processors, Ryzen 7030 Mobile Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen 9000HX Processors, Ryzen AI 300 Processors, Ryzen Threadripper PRO 5000 WX-Series Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 4000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 3000 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen AI Max 300 Processors, Ryzen Threadripper 7000 Processors, Not public, Ryzen Threadripper 9000 Processors, Ryzen Threadripper PRO 9000 WX-Series Processors and Device Management Portal and classified as critical. Affected by this vulnerability is an unknown functionality of the component KVM Key Download. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2025-62625. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-44374 | backstage plugin-catalog-backend-module-unprocessed up to 0.6.10 Unprocessed Entities Read Endpoint authorization (GHSA-p7g9-rp3g-mgfg)
1 month 1 week ago
A vulnerability, which was classified as problematic, was found in backstage plugin-catalog-backend-module-unprocessed, plugin-catalog-unprocessed-entities and plugin-catalog-unprocessed-entities-common up to 0.6.10. Affected is an unknown function of the component Unprocessed Entities Read Endpoint. Such manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-44374. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-41932 | givanz Vvveb up to 1.0.8.2 Signup::addUser display_name cross site scripting
1 month 1 week ago
A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.8.2. This impacts the function Signup::addUser. This manipulation of the argument display_name causes cross site scripting.
The identification of this vulnerability is CVE-2026-41932. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-69443 | coleam00 Archon 0.1.0 UI Including API privilege escalation
1 month 1 week ago
A vulnerability classified as critical was found in coleam00 Archon 0.1.0. This affects an unknown function of the component UI Including API. The manipulation results in privilege escalation.
This vulnerability was named CVE-2025-69443. The attack may be performed from remote. There is no available exploit.
vuldb.com
Смена пароля по пьяни стоила мужчине $400 тысяч в биткоинах. Claude вернул их через 11 лет
1 month 1 week ago
ИИ разгрёб старый ноутбук — и нашел резервные копии там, где никто не догадался посмотреть.