Aggregator
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
23 hours 59 minutes ago
Vulnerability / Web SecurityA maximum-severity security vulnerability impacting LiteSpeed User-End
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
23 hours 59 minutes ago
A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild.
The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.
"Any cPanel user (including an attacker or a compromised account) may
The Hacker News
DMA Buffer Cache同步的批处理优化及高通平台的实践
1 day ago
活动,“笑傲内核”小组核心成员陈雪原将代表小组出席活动,进行主题分享《DMA Buffer Cache同步的批处理优化及高通平台的实践》。2026年5月30日,深圳《
21cnbao
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
1 day ago
Vulnerability / Website SecurityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) h
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
1 day ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core.
"Drupal Core
The Hacker News
中国公布2025年全国1%人口抽样调查主要数据
1 day ago
根据《全国人口普查条例》及国务院办公厅要求,中国于2025年11月1日开展了全国1%人口抽样调查。公报公布了此次调查推算的人口主要数据:全国人口为140545万人,男性占51.03%,女性占48.97
The Emerson Paradox
1 day ago
New StorybyAstounding StoriesbyAstounding Stories@astoundingstoriesDare to dream. Dare to go where
CVE-2026-9342 | SourceCodester Hospitals Patient Records Management System 1.0 view_history.php ID sql injection
1 day ago
A vulnerability, which was classified as critical, was found in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection.
This vulnerability is cataloged as CVE-2026-9342. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
RTX 4060 на слайдах, совсем другой результат в играх. Первые тесты китайской Lisuan LX 7G100 оказались болезненными для производителя
1 day ago
Видеокарта Lisuan LX 7G100 получила 12 ГБ памяти и собственную архитектуру, но драйверы и производительность пока ограничивают её возможности.
Submit #812834: sourcecodester Hospital's Patient Records Management System V1.0 SQL injection [Accepted]
1 day 1 hour ago
Submit #812834 / VDB-365305
july-skyload
Submit #812258: eladmin 2.7 Improper Access Controls [Duplicate]
1 day 1 hour ago
Submit #812258 / VDB-361917
AliceS614
CVE-2026-6895 | Wishlist Member Plugin up to 3.30.1 on WordPress REST API export_settings privileges management (EUVD-2026-31526)
1 day 1 hour ago
A vulnerability, which was classified as critical, has been found in Wishlist Member Plugin up to 3.30.1 on WordPress. This issue affects the function export_settings of the component REST API. The manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2026-6895. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-6898 | Wishlist Member Plugin up to 3.30.1 on WordPress REST API generate_api_key privileges management (EUVD-2026-31523)
1 day 1 hour ago
A vulnerability classified as critical was found in Wishlist Member Plugin up to 3.30.1 on WordPress. This vulnerability affects the function WishListMember3_Hooks::generate_api_key of the component REST API. Executing a manipulation can lead to improper privilege management.
This vulnerability is tracked as CVE-2026-6898. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-6897 | Wishlist Member Plugin up to 3.30.1 on WordPress REST API Team_Accounts privileges management (EUVD-2026-31525)
1 day 1 hour ago
A vulnerability classified as critical has been found in Wishlist Member Plugin up to 3.30.1 on WordPress. This affects the function Team_Accounts of the component REST API. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2026-6897. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-6419 | Wishlist Member Plugin up to 3.30.1 on WordPress Administrative API ajax_get_screen privileges management (EUVD-2026-31527)
1 day 1 hour ago
A vulnerability described as critical has been identified in Wishlist Member Plugin up to 3.30.1 on WordPress. Affected by this issue is the function ajax_get_screen of the component Administrative API. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-6419. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-45659 | Microsoft SharePoint Enterprise Server deserialization (WID-SEC-2026-1652)
1 day 1 hour ago
A vulnerability marked as critical has been reported in Microsoft SharePoint Enterprise Server. Affected by this vulnerability is an unknown functionality. This manipulation causes deserialization.
The identification of this vulnerability is CVE-2026-45659. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41147 | nukeviet CMS up to 4.5.7 Contact cross site scripting (GHSA-64rr-pp78-62ww)
1 day 1 hour ago
A vulnerability labeled as problematic has been found in nukeviet CMS up to 4.5.7. Affected is an unknown function of the component Contact Module. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-41147. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-47280 | Microsoft Azure Resource Manager improper authentication
1 day 1 hour ago
A vulnerability identified as critical has been detected in Microsoft Azure Resource Manager. This impacts an unknown function. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-47280. The attack is possible to be carried out remotely. No exploit exists.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
vuldb.com
CVE-2026-42827 | Microsoft 365 Copilot command injection
1 day 1 hour ago
A vulnerability categorized as critical has been discovered in Microsoft 365 Copilot. This affects an unknown function. Executing a manipulation can lead to command injection.
This vulnerability is handled as CVE-2026-42827. The attack can be executed remotely. There is not any exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.
vuldb.com