Posts of last 24 hours
A vulnerability marked as critical has been reported in Cozmoslabs Paid Member Subscriptions Plugin up to 3.0.7 on WordPress. Impacted is an unknown function. This manipulation causes improper control of resource identifiers.
This vulnerability appears as CVE-2026-59539. The attack may be initiated remotely. There is no available exploit.
https://vuldb.com/vuln/383444
A vulnerability labeled as critical has been found in Ruben Garcia GamiPress Plugin up to 7.9.7 on WordPress. This issue affects some unknown processing. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-59538. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/383443
A vulnerability identified as critical has been detected in Thrive mes Thrive Product Manager up to 10.9.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-59535. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/383442
A vulnerability categorized as critical has been discovered in Aurovrata Venet Post My CF7 Form Plugin up to 6.2.0 on WordPress. This affects an unknown part. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-59534. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/383441
CVE-2026-59533 | Christoph Vielgrader Relevanssi Light Plugin up to 1.2.2 on WordPress sql injection
A vulnerability was found in Christoph Vielgrader Relevanssi Light Plugin up to 1.2.2 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-59533. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/383440
国际能源署(IEA)的《Electricity Mid-Year Update 2026》报告预测,2026 年全球电力需求将增长 3.6%,2027 年将进一步增长 3.8%。全球电力消耗量到 2027 年将达到 30,700 TWh,相比下 2025 年为 28,600 TWh。
可再生能源有望在 2026 年超过煤炭成为全球最大的发电来源,2026 年可再生能源发电量将增长逾 8%,全球发电量中的份额将从 2025 年的 33% 提高至 2027 年的 37%。报告警告,天气相关变化可能会影响电力需求趋势,增加不确定性。2026 年强于预期的厄尔尼诺现象可能会增加制冷需求,进一步推高电力需求,同时可能导致部分地区的水力发电和风力发电量下降,增加对其它发电方式的依赖。
https://www.solidot.org/story?sid=84937
Philadelphia, Pennsylvania, July 27th, 2026, CyberNewswire Security Risk Advisors is proud to share that CRN, a brand of The Channel Company, has recognized Joe Cicero as a finalist in the second annual CRN Best of the Channel Awards in the Best Channel Visionary of the Year category. As a finalist, Joe is being spotlighted for […]
The post Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards appeared first on Cyber Security News.
https://cybersecuritynews.com/security-risk-advisors-named-a-finalist-in-crns-2026-best-of-the-channel-awards/
2008年至今,一个`?`让nginx rewrite模块躺着一个CVSS 9.2的堆溢出漏洞。脚本引擎「两遍扫描」中,算长度的引擎和执行拷贝的引擎状态不一致——一个认为「不需要escape」,另一个认为「需要」,导致按原始长度分配buffer却写入了escape展开后的内容。本文通过GDB调试验证了RCE的真实障碍,并开源了一套5模块自动化检测框架,从根因出发检测同类漏洞,而非依赖已知CVE签名
https://xz.aliyun.com/news/92385
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
https://hackread.com/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts/
本文复盘 Hack The Box 靶机 Jarmis 的完整渗透过程:从 nmap 扫描与 JARM 指纹识别入手,分析 API 行为、模糊查询与恶意指纹数据库,逐步发现 Fetch Jarm 功能背后的服务端请求特征。随后利用重定向验证 SSRF,借助 Gopher 构造原始 HTTP POST 请求,最终打通内网 OMI 服务的 CVE-2021-38647 认证绕过漏洞,以 root 权限
https://xz.aliyun.com/news/92380