Aggregator
CVE-2026-0251 | Palo Alto GlobalProtect App/Global Protect App on Windows untrusted search path (EUVD-2026-30102 / WID-SEC-2026-1542)
CVE-2026-4053 | Mattermost up to 10.11.13/11.5.1/11.5.x API Endpoint operation after expiration (WID-SEC-2026-1154)
CVE-2026-4054 | Mattermost up to 10.11.13/11.4.3/11.5.1/11.5.x SVG File unusual condition (WID-SEC-2026-1154)
KDE Secures €1.2M Sovereign Tech Fund Grant to Build a Windows Alternative
The KDE ecosystem has secured a grant totaling €1,285,200 from the Sovereign Tech Fund, a German public-interest entity
The post KDE Secures €1.2M Sovereign Tech Fund Grant to Build a Windows Alternative appeared first on Penetration Testing Tools.
CVE-2026-6381 | WP Maps Plugin up to 4.9.2 on WordPress path traversal
希音收购美国服装品牌Everlane
Magecart Attack: Critical Flaw in FunnelKit Plugin Sparks Credit Card Skimming on 40,000+ WooCommerce Sites
Proprietors of WordPress e-commerce platforms have fallen under siege due to a critical vulnerability discovered in the Funnel
The post Magecart Attack: Critical Flaw in FunnelKit Plugin Sparks Credit Card Skimming on 40,000+ WooCommerce Sites appeared first on Penetration Testing Tools.
A week in security (May 11 – May 17)
PolarProxy 2.0 Released
PolarProxy 2.0 Released
NGINX堆缓冲区溢出漏洞已经开始被黑客利用 安全公司提醒用户尽快升级
打破虚拟与现实的边界,这 6 款网页解谜游戏值得一试
CVE-2026-3220 | Autoptimize Plugin up to 3.1.14 on WordPress Regular Expression cross site scripting
CVE-2026-6495 | Ajax Load More Plugin up to 7.8.3 on WordPress cross site scripting (EUVD-2026-30733)
Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints
The development framework Next.js has remediated a critical security vulnerability, designated as CVE-2026-44578, which afflicts applications deployed on
The post Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints appeared first on Penetration Testing Tools.
CVE-2026-6379 | WP Photo Album Plus Plugin 9.1.11.0 on WordPress sql injection
CVE-2026-1631 | Feeds for YouTube Plugin up to 2.6.3 on WordPress License Key actions authorization
ChatGPT теперь знает, сколько вы тратите на кофе. И готов это обсудить
Operation Masquerade: FBI Executes Remote Reset on Thousands of Routers to Purge Russian Malware
The Federal Bureau of Investigation (FBI) has executed a remote reset of thousands of domestic and small-office routers
The post Operation Masquerade: FBI Executes Remote Reset on Thousands of Routers to Purge Russian Malware appeared first on Penetration Testing Tools.