Aggregator
«Просто поставь Linux» — Apple услышала и теперь предлагает Linux прямо внутри вашего Mac
1 week ago
Apple выпустила container machines — постоянные Linux-виртуалки для разработчиков на Mac.
大师兄影视 去广告版
1 week ago
应用简介:大师兄影视app是一款安卓影视聚合应用,它跟很多同类应用一样采集全网影视资源,而有点又跟大部分的影视应用稍有不同,大师兄影视主要采用自建高清源,片源存储国内
CVE-2026-11676 | Google Chrome up to 149.0.7827.53 on Linux Dawn sandbox (ID 516949)
1 week ago
A vulnerability identified as critical has been detected in Google Chrome on Linux. Affected by this issue is some unknown functionality of the component Dawn. Performing a manipulation results in sandbox issue.
This vulnerability is known as CVE-2026-11676. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-11658 | Google Chrome up to 149.0.7827.53 Extensions improper isolation or compartmentalization (ID 513564)
1 week ago
A vulnerability has been found in Google Chrome and classified as critical. Affected by this issue is some unknown functionality of the component Extensions. This manipulation causes improper isolation or compartmentalization.
This vulnerability is tracked as CVE-2026-11658. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-11655 | Google Chrome up to 149.0.7827.53 on macOS Media external control of assumed-immutable web parameter (ID 513396)
1 week ago
A vulnerability was found in Google Chrome on macOS. It has been declared as critical. This issue affects some unknown processing of the component Media. Executing a manipulation can lead to external control of assumed-immutable web parameter.
This vulnerability is registered as CVE-2026-11655. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-11661 | Google Chrome up to 149.0.7827.53 on Windows Views use after free (ID 513748)
1 week ago
A vulnerability categorized as critical has been discovered in Google Chrome on Windows. The affected element is an unknown function of the component Views. The manipulation results in use after free.
This vulnerability is reported as CVE-2026-11661. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-11660 | Google Chrome up to 149.0.7827.53 New Tab Page sandbox (ID 513731)
1 week ago
A vulnerability identified as critical has been detected in Google Chrome. The impacted element is an unknown function of the component New Tab Page. This manipulation causes sandbox issue.
This vulnerability appears as CVE-2026-11660. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-11664 | Google Chrome up to 149.0.7827.53 Payments use after free (ID 513830)
1 week ago
A vulnerability described as critical has been identified in Google Chrome. Affected is an unknown function of the component Payments. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-11664. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-11667 | Google Chrome up to 149.0.7827.53 WebRTC out-of-bounds (ID 514671)
1 week ago
A vulnerability classified as problematic has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component WebRTC. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-11667. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-11666 | Google Chrome up to 149.0.7827.53 Input clickjacking (ID 514009)
1 week ago
A vulnerability was found in Google Chrome. It has been classified as problematic. The affected element is an unknown function of the component Input. The manipulation leads to clickjacking.
This vulnerability is listed as CVE-2026-11666. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-12176 | SourceCodester CET Automated Grading System with AI Predictive Analytics /index.php cross site scripting (EUVD-2026-36656)
1 week ago
A vulnerability classified as problematic has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-12176. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
Submit #837732: https://www.sourcecodester.com/ CET Automated Grading System with AI Predictive Analytics in PHP and MySQL Version: 1.0 Cross Site Scripting - Reflected XSS [Accepted]
1 week ago
Submit #837732 / VDB-370818
Abhay mp
CVE-2026-11769 | Grafana Operator up to 5.23.0 path traversal (EUVD-2026-36641)
1 week ago
A vulnerability described as critical has been identified in Grafana Operator up to 5.23.0. The affected element is an unknown function. Executing a manipulation can lead to path traversal.
This vulnerability is handled as CVE-2026-11769. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
Social experiment in Kuwait
1 week ago
CVE-2026-12175 | CodeAstro Student Attendance Management System 1.0 createStudents.php admissionNumber sql injection (EUVD-2026-36655)
1 week ago
A vulnerability marked as critical has been reported in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection.
This vulnerability is known as CVE-2026-12175. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
1 week ago
Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or outside the U.S., citing national security concerns.
The AI company said it received an order at 5:21 p.m. ET, instructing it to suspend
The Hacker News
U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
1 week ago
Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI)
Учёные создали тест из 1490 рабочих задач для ИИ. Лидеры индустрии справились только с четвертью
1 week ago
Автоматизация будущего внезапно споткнулась о простые повседневные задачи.
CVE-2026-12174 | D-Link DCS-935L 1.10.01 HTTP /web/cgi-bin/greece/rhea snprintf data format string (EUVD-2026-36654)
1 week ago
A vulnerability labeled as critical has been found in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string.
This vulnerability is traded as CVE-2026-12174. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com