Aggregator
CVE-2026-22619 | Eaton IPP Software up to 1.x uncontrolled search path
1 week 4 days ago
A vulnerability labeled as problematic has been found in Eaton IPP Software up to 1.x. The impacted element is an unknown function. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is tracked as CVE-2026-22619. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-22618 | Eaton IPP Software up to 1.x HTTP Response Header security check
1 week 4 days ago
A vulnerability identified as problematic has been detected in Eaton IPP Software up to 1.x. The affected element is an unknown function of the component HTTP Response Header Handler. Performing a manipulation results in security check for standard.
This vulnerability is identified as CVE-2026-22618. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
谷歌宣布为One和AI Pro订阅用户提供5折YouTube Premium订阅权限
1 week 4 days ago
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内。首先,我需要仔细阅读文章,抓住主要信息。
文章讲的是谷歌推出了一项特别优惠活动,针对Google One和Google AI Pro的订阅用户。优惠内容是半价订阅YouTube Premium。活动截止日期是4月29日,适用于美国、加拿大、巴西、德国、法国和日本这几个国家。需要注意的是,必须一次性按年度订阅才能享受半价优惠。
另外,文章还提到如果用户已经订阅了YouTube Premium,需要先取消再重新订阅,以避免重复收费。还提供了支持文档的链接,帮助用户操作。
现在我要把这些信息浓缩到100字以内。要确保包含优惠对象、优惠内容、适用地区、截止日期以及注意事项。
可能的结构是:谷歌为符合条件的订阅用户推出半价YouTube Premium优惠,限定地区和时间,并提醒用户操作注意事项。
这样应该能简洁明了地概括文章内容。
谷歌为符合条件的 Google One 和 Google AI Pro 用户推出 YouTube Premium 半价优惠活动,限定地区和时间,并提醒用户注意操作细节以避免重复收费。
CVE-2026-22617 | Eaton IPP Software up to 1.x Configuration missing secure attribute
1 week 4 days ago
A vulnerability categorized as problematic has been discovered in Eaton IPP Software up to 1.x. Impacted is an unknown function of the component Configuration Handler. Such manipulation leads to sensitive cookie without secure attribute.
This vulnerability is referenced as CVE-2026-22617. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
В СНГ выявлен первый случай применения передвижных СМС-бластеров
1 week 4 days ago
Для атаки преступникам даже не нужен интернет — хватит фургона и пары антенн.
CVE-2026-3599 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress REST API Endpoint add-item-to-cart product_data options sql injection
1 week 4 days ago
A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress. It has been rated as critical. This issue affects the function product_data of the file /wp-json/InkXEProductDesignerLite/add-item-to-cart of the component REST API Endpoint. This manipulation of the argument options causes sql injection.
The identification of this vulnerability is CVE-2026-3599. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-3773 | onlineada Accessibility Suite by Ability Plugin up to 4.20 on WordPress scan_id sql injection
1 week 4 days ago
A vulnerability was found in onlineada Accessibility Suite by Ability Plugin up to 4.20 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation of the argument scan_id results in sql injection.
This vulnerability was named CVE-2026-3773. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-3596 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress ink_pd_add_option opt_value authorization
1 week 4 days ago
A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress. It has been classified as critical. This affects the function ink_pd_add_option. The manipulation of the argument opt_value leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-3596. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-3595 | imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress REST API delete_customer inkxe_delete_customer authorization
1 week 4 days ago
A vulnerability was found in imprintnext Riaxe Product Customizer Plugin up to 2.1.2 on WordPress and classified as critical. Affected by this issue is the function inkxe_delete_customer of the file /wp-json/InkXEProductDesignerLite/customer/delete_customer of the component REST API. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-3595. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-5050 | jconti Payment Gateway for Redsys & WooCommerce Lite Plugin successful_request signature verification
1 week 4 days ago
A vulnerability has been found in jconti Payment Gateway for Redsys & WooCommerce Lite Plugin up to 7.0.0 on WordPress and classified as critical. Affected by this vulnerability is the function successful_request. Performing a manipulation results in improper verification of cryptographic signature.
This vulnerability is known as CVE-2026-5050. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
领英数据显示AI并非招聘下降的罪魁祸首
1 week 4 days ago
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解主要信息。
文章讲的是微软旗下的领英首席全球事务和法律官布莱克·劳伊特在世界经济峰会上的发言。他说,自2022年以来,招聘下降了约20%。但他不认为这是AI导致的,反而指出这与利率上升有关。
接下来,我需要提取关键点:领英高管、招聘下降20%、时间点是2022年、反驳AI影响就业的观点、认为利率上升是主要原因。
然后,我要把这些信息用简洁的语言表达出来,确保不超过100字,并且直接描述内容,不需要开头语。
可能会这样组织句子:“微软领英高管表示自2022年以来招聘下降约20%,但否认AI为主要原因,认为与利率上升关系更大。”
检查一下字数和是否涵盖了所有关键点。看起来没问题。
微软领英高管表示自2022年以来招聘下降约20%,但否认AI为主要原因,认为与利率上升关系更大。
CVE-2026-3861 | LINE Client up to 26.2.x on iOS Web denial of service (EUVD-2026-23196)
1 week 4 days ago
A vulnerability, which was classified as problematic, was found in LINE Client up to 26.2.x on iOS. Affected is an unknown function of the component Web Handler. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-3861. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2023-3634 | Festo MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD inclusion of undocumented features or chicken bits (VDE-2023-020 / EUVD-2023-44280)
1 week 4 days ago
A vulnerability, which was classified as very critical, was found in Festo MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L4-AGD, MSE6-C2M-5000-FB36-D-M-RG-BAR-M12L5-AGD, MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L4-MQ1-AGD, MSE6-C2M-5000-FB43-D-M-RG-BAR-M12L5-MQ1-AGD, MSE6-C2M-5000-FB44-D-M-RG-BAR-AMI-AGD, MSE6-C2M-5000-FB44-D-RG-BAR-AMI-AGD, MSE6-D2M-5000-CBUS-S-RG-BAR-VCB-AGD, MSE6-E2M-5000-FB13-AGD, MSE6-E2M-5000-FB36-AGD, MSE6-E2M-5000-FB37-AGD, MSE6-E2M-5000-FB43-AGD and MSE6-E2M-5000-FB44-AGD. This issue affects some unknown processing. Executing a manipulation can lead to inclusion of undocumented features or chicken bits.
This vulnerability is handled as CVE-2023-3634. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-40118 | Arcserve UDP Console 10.3 incorrectly specified destination in a communication channel (EUVD-2026-23192)
1 week 4 days ago
A vulnerability was found in Arcserve UDP Console 10.3 and classified as critical. The affected element is an unknown function. The manipulation results in incorrectly specified destination in a communication channel.
This vulnerability was named CVE-2026-40118. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-6351 | Openfind MailGates/MailAudit prior 5.2.10.099/6.1.10.054 System File crlf injection (EUVD-2026-23167)
1 week 4 days ago
A vulnerability, which was classified as problematic, was found in Openfind MailGates and MailAudit. The impacted element is an unknown function of the component System File Handler. The manipulation results in crlf injection.
This vulnerability is known as CVE-2026-6351. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-22616 | Eaton IPP Software up to 1.x Web Interface excessive authentication (EUVD-2026-23175)
1 week 4 days ago
A vulnerability has been found in Eaton IPP Software up to 1.x and classified as problematic. Impacted is an unknown function of the component Web Interface. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is uniquely identified as CVE-2026-22616. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-22615 | Eaton IPP Software up to 1.x input validation (EUVD-2026-23174)
1 week 4 days ago
A vulnerability, which was classified as problematic, has been found in Eaton IPP Software up to 1.x. The affected element is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2026-22615. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-5872 | Wago Smart Designer up to 2.33.1 information exposure (VDE-2023-045 / EUVD-2023-58146)
1 week 4 days ago
A vulnerability has been found in Wago Smart Designer up to 2.33.1 and classified as problematic. This affects an unknown function. This manipulation causes information exposure through discrepancy.
This vulnerability is handled as CVE-2023-5872. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-3581 | iandunn Basic Google Maps Placemarks Plugin up to 1.10.7 on WordPress authorization (EUVD-2026-23180)
1 week 4 days ago
A vulnerability, which was classified as critical, has been found in iandunn Basic Google Maps Placemarks Plugin up to 1.10.7 on WordPress. This impacts an unknown function. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-3581. The attack may be initiated remotely. There is no available exploit.
vuldb.com