voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🚨 EUVD-2026-34929
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: LatePoint – Calendar Booking Plugin for Appointments and Events
🏢 Vendor: latepoint
📅 Updated: 2026-06-05
📝 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34929
🚨 EUVD-2026-34930
📊 Score: 4.9/10 (CVSS v3.1)
📦 Product: Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
🏢 Vendor: ExpressTech
📅 Updated: 2026-06-05
📝 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order' parameter in all versions up to, and including, 11.1.2 du...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34930
🚨 EUVD-2026-34931
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: Event Monster – Event Manager, Ticket Booking & Registration
🏢 Vendor: awordpresslife
📅 Updated: 2026-06-05
📝 The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is d...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34931
🚨 EUVD-2026-34928
📊 Score: 7.5/10 (CVSS v3.1)
📦 Product: WP User Manager – User Profile Builder & Membership
🏢 Vendor: wpusermanager
📅 Updated: 2026-06-05
📝 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34928
🚨 EUVD-2026-34927
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
🏢 Vendor: smub
📅 Updated: 2026-06-05
📝 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34927
🚨 EUVD-2025-210080
📊 Score: 3.8/10 (CVSS v3.1)
📦 Product: WPvivid — Backup, Migration & Staging
🏢 Vendor: wpvividplugins
📅 Updated: 2026-06-05
📝 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210080
🚨 EUVD-2026-34925
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Simple SEO Slideshow
🏢 Vendor: spyrosvl
📅 Updated: 2026-06-05
📝 The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping. This makes it possible f...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34925
🚨 EUVD-2026-34926
📊 Score: 4.3/10 (CVSS v3.1)
📦 Product: Frontend User Notes
🏢 Vendor: absikandar
📅 Updated: 2026-06-05
📝 The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it po...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34926
🚨 EUVD-2026-34924
📊 Score: 6.4/10 (CVSS v3.1)
📦 Product: Express Payment For Stripe
🏢 Vendor: payaddons
📅 Updated: 2026-06-05
📝 The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up to, and including, 1.28.0. This is due to insufficient input sanit...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34924
🚨 EUVD-2026-34921
📊 Score: 6.9/10 (CVSS v3.1)
📦 Product: idna
🏢 Vendor: kjd
📅 Updated: 2026-06-05
📝 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34921
🔴 CVE-2025-71318 - Critical (9.8)
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuratio...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2025-5088 - High (8.3)
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please not...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-5088/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-48095 - High (8.8)
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
#chrome extension Doodle Jump Trump seems malicious. Its #cybersecurity badness score is 90/100!
```json
{"id": "kofdhccjlmfceakkllbenajnnpjdepde", "score": 90, "platform": "chrome", "name": "Doodle Jump Trump"}
```
Production of DDR4 memory and motherboards is restarting amid unprecedented memory shortages — PC industry preparing for a world without DDR5
Back to the (stone) DDR4 age.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
OpenAI CEO Sam Altman admits AI token costs are becoming 'a huge issue' — company seeks improved value as overspending becomes a meme
OpenAI's clients are complaining about out-of-control AI spending, and they're asking Sam Altman to make it more efficient so they don't blow their annual AI budgets in just one quarter.
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//mett-a-massk-loogiin[.]godaddysites[.]com/
🧬 Analysis at: https://urldna.io/scan/6a21af373b775000052249cf
#cybersecurity #phishing #infosec #urldna #scam #infosec
AMD's Helios MI455X AI platform breaks cover, initial systems use UALink-over-Ethernet interconnects — AM…
AMD’s Helios set to compete against Nvidia’s NVL72 VR200 rack-scale system later this year, but its UALink-over-Ethernet interconnection may affect performance in certain workloads before real UALink interconnects are d…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Possible Phishing 🎣
on: ⚠️hxxps[:]//bafybeihwozsbkca37gpl4alioopaguh4wssj6vmeeynfgt3xiomy2ifgla[.]ipfs[.]dweb[.]link/portalsupport[.]html
🧬 Analysis at: https://urldna.io/scan/6a22e47b3b77500003ffb5d8
#cybersecurity #phishing #infosec #urldna #scam #infosec
🚨 EUVD-2026-34895
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: issues
🏢 Vendor: haxtheweb
📅 Updated: 2026-06-05
📝 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerability where authentication tokens remain valid after user logout. This allows attackers who obtain valid tokens...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34895
🚨 EUVD-2026-34894
📊 Score: 8.7/10 (CVSS v3.1)
📦 Product: haxcms-php
🏢 Vendor: haxtheweb
📅 Updated: 2026-06-05
📝 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only validates file extensions using a regex pattern without checking the actual fil...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34894
🚨 EUVD-2026-34893
📊 Score: 8.8/10 (CVSS v3.1)
📦 Product: haxcms-php
🏢 Vendor: haxtheweb
📅 Updated: 2026-06-05
📝 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_token cookie is set without the Secure flag. This allows it to be transmitted over unencrypted HTTP, making i...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34893
🚨 EUVD-2026-34902
📊 Score: 6.5/10 (CVSS v3.1)
📦 Product: haxcms-nodejs, haxcms-php
🏢 Vendor: haxtheweb
📅 Updated: 2026-06-05
📝 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary file...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34902
🚨 EUVD-2026-34899
📊 Score: 10.0/10 (CVSS v3.1)
📦 Product: Altium Enterprise Server
🏢 Vendor: Altium
📅 Updated: 2026-06-05
📝 A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can forge...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34899
🟠 CVE-2026-11400 - High (8)
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rd...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11400/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🟠 CVE-2026-11401 - High (8)
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11401/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
🔴 CVE-2026-45748 - Critical (9.8)
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled ho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Everest Forms Pro WordPress Plugin Vulnerability Has Been Patched
A critical vulnerability in the Everest Forms Pro WordPress plugin is being actively exploited by threat actors to compromise vulnerable websites.
Pulse ID: 6a23367b6aeddabfb3f24a51
Pulse Link: https://otx.alienvault.com/pulse/6a23367b6aeddabfb3f24a51
Pulse Author: cryptocti
Created: 2026-06-05 20:50:03
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #Vulnerability #Word #Wordpress #bot #cryptocti
🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
⚫ Adaptive, Agentic AI Worms Loom as Next Enterprise Threat
🔗 https://www.darkreading.com/cyber-risk/adaptive-agentic-ai-worms-enterprise-cyber-threat
AI worms, or "viruses with wings and brains," adapt to new environments, seek out vulnerabilities, and will likely strike within a year, researchers say.
New by me: Security Signal Weekly: May 30-June 5, 2026
https://www.kylereddoch.me/blog/security-signal-weekly-may-30-june-5-2026/
I cracked open a '1,000W' portable charger after it failed me in minutes - the cause was clear (and gooey)
Meet the 'too good to be true' portable charger. Here's my general buying advice for these types of products.
https://www.zdnet.com/article/1000w-gan-charger-hands-on/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #ZDNet [ZDNet]
#US #NSA using #Anthropic’s #Mythos for #cyberattacks
Just months after the U.S. Department of Defense (DOD) labelled Anthropic a "supply chain risk", completely cutting off the firm from being a vendor of any #AI wares, a new report claims that the National Security Agency (NSA) is using Anthropic's #cybersecurity-focused Mythos model "for offensive cyber operations" with the help of "half a dozen" staff from Anthropic embedded inside the agency
https://www.ft.com/content/d02d91b3-2636-454e-9442-dc7e69f51815
https://archive.is/20260605120028/https://www.ft.com/content/d02d91b3-2636-454e-9442-dc7e69f51815
Wyze recalls over 320,000 security cameras due to fire and explosion hazards
Wyze is recalling hundreds of thousands of its security cameras.
https://www.androidauthority.com/wyze-security-camera-recall-3675182/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
Possible Phishing 🎣
on: ⚠️hxxp[:]//amazon-clone-psi-eight[.]vercel[.]app
🧬 Analysis at: https://urldna.io/scan/6a21d2f33b77500008814817
#cybersecurity #phishing #infosec #urldna #scam #infosec
This adapter adds Android Auto to most GM EVs, but there’s a catch
There isn't a subscription, but there's a high upfront cost and no guarantee it'll work forever.
https://www.androidauthority.com/evplay-android-auto-gm-adapter-3675224/
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #AndroidAuthority [Android Authority]
🚨 EUVD-2026-34848
📊 Score: 5.3/10 (CVSS v3.1)
📦 Product: CollegeManagementSystem, CollegeManagementSystem
🏢 Vendor: tittuvarghese
📅 Updated: 2026-06-05
📝 A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file dashboard_pa...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34848
🚨 EUVD-2026-34847
📊 Score: n/a
📦 Product: DataDog::DogStatsd
🏢 Vendor: BINARY
📅 Updated: 2026-06-05
📝 DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.
DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.
The format_event method (used by the event method) does no...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34847
Mantine-datatable (and others) compromised – owner account suspended
https://github.com/icflorescu/mantine-datatable/discussions/813
#HackerNews #MantineDatatable #Compromise #OwnerSuspended #SecurityAlert #GitHubDiscussion #Cybersecurity
🚨 EUVD-2026-34846
📊 Score: n/a
📦 Product: DataDog::DogStatsd
🏢 Vendor: BINARY
📅 Updated: 2026-06-05
📝 DataDog::DogStatsd versions through 0.07 for Perl allow metric injections.
DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources.
The send_stats method does not remove newlines from metric names ($stat va...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34846