微博微博哔哩哔哩哔哩哔哩新浪新闻新浪新闻新浪网新浪网GitHubGitHubCSDNCSDNIT之家IT之家36氪36氪Adafruit BlogAdafruit BlogAIbaseAIbaseAnt Bailing Developer BlogAnt Bailing Developer BlogAnthropicAnthropic小众软件小众软件AppleAppleAppleInsiderAppleInsiderArs TechnicaArs TechnicaBerkeley AI ResearchBerkeley AI ResearchBBC NewsBBC NewsBD Tech TalksBD Tech TalksBerkeley RDIBerkeley RDIBloombergBloombergBoston Dynamics BlogBoston Dynamics BlogByteDance Seed ResearchByteDance Seed ResearchClaude BlogClaude BlogClaude Code ReleasesClaude Code ReleasesCloudflare BlogCloudflare BlogCMU Machine Learning BlogCMU Machine Learning Blogcrates.iocrates.ioCrowd SupplyCrowd SupplyCSS-TricksCSS-Tricks51CTO51CTOCult of MacCult of MacCursor BlogCursor BlogDaring FireballDaring FireballDario AmodeiDario AmodeiDeepLearning.AI · The BatchDeepLearning.AI · The BatchGoogle DeepMind BlogGoogle DeepMind BlogDeepSeek GitHubDeepSeek GitHubDescript BlogDescript BlogDEV.toDEV.to数字尾巴数字尾巴Docker HubDocker HubDwarkesh PatelDwarkesh PatelEleutherAI BlogEleutherAI BlogEngadgetEngadgetFlathubFlathubfreeCodeCampfreeCodeCampGary MarcusGary Marcus极客公园极客公园果核剥壳果核剥壳GoogleGoogleHackadayHackadayHacker NewsHacker NewsHelloGitHubHelloGitHubHomebrewHomebrewHugging FaceHugging Face虎嗅虎嗅IEEE SpectrumIEEE Spectrum爱范儿爱范儿inclusionAIinclusionAIIndie HackersIndie HackersInfoQInfoQInterconnectsInterconnects稀土掘金稀土掘金Andrej KarpathyAndrej KarpathyMoonshot AI KimiMoonshot AI KimiLatent SpaceLatent SpaceLil'Log (Lilian Weng)Lil'Log (Lilian Weng)Linux.doLinux.doLMSYS BlogLMSYS BlogLobstersLobstersLWN.netLWN.netMacRumorsMacRumorsMake: MagazineMake: MagazineMaven CentralMaven CentralMediumMediumMeituan LongCatMeituan LongCatMeta AI BlogMeta AI BlogMeta EngineeringMeta EngineeringMidjourney UpdatesMidjourney UpdatesMiniMaxMiniMaxMIT News · RoboticsMIT News · RoboticsMIT Technology ReviewMIT Technology ReviewMozilla.ai BlogMozilla.ai BlogNew Atlas · RoboticsNew Atlas · Robotics9to5Mac9to5MacNodeSeekNodeSeek牛客牛客NuGetNuGetNVIDIANVIDIAOne Useful ThingOne Useful ThingOpen Robotics BlogOpen Robotics BlogOpenAIOpenAIOpenRouterOpenRouterPackagistPackagist远景论坛远景论坛PhoronixPhoronixPlanet ROSPlanet ROS吾爱破解吾爱破解Product HuntProduct HuntPyPIPyPIQoderQoderQwenQwenRFC EditorRFC EditorRobohubRobohubRobotics & Automation NewsRobotics & Automation NewsRobotics TomorrowRobotics TomorrowROS DiscourseROS Discourse阮一峰的网络日志阮一峰的网络日志RubyGemsRubyGemsRunwayRunwaySam AltmanSam AltmanAhead of AIAhead of AISecurityOnlineSecurityOnlineServeTheHomeServeTheHomeServiceNow AIServiceNow AISimon WillisonSimon WillisonSlashdotSlashdotSmashing MagazineSmashing MagazineSolidotSolidot少数派少数派Stack OverflowStack OverflowStack Overflow BlogStack Overflow BlogSubstackSubstackSuno BlogSuno BlogSynced ReviewSynced Review淘宝逛一逛淘宝逛一逛TechCrunchTechCrunchTech Xplore · RoboticsTech Xplore · RoboticsThe DecoderThe DecoderThe GradientThe GradientThe RegisterThe RegisterThe VergeThe VergeTindie BlogTindie BlogTomer TunguzTomer TunguzTom's HardwareTom's HardwareTransformer CircuitsTransformer Circuits优设网优设网UiverseUiverseV2EXV2EXVentureBeat · AIVentureBeat · AIWiredWiredxAI NewsxAI News小鹅通小鹅通Zhipu AI ResearchZhipu AI ResearchCISA KEVCISA KEVNVDNVDOSV.devOSV.devTelegram OSINTTelegram OSINT

科技热榜

4小时前更新
  • 01
    CVE-2026-87902 · WordPress Core Remote File Inclusion Vulnerability
    WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 02
    CVE-2026-67279 · Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
    Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 03
    CVE-2026-65660 · Microsoft SharePoint Code Injection Vulnerability
    Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 04
    CVE-2026-71362 · Adobe Commerce and Magento Incorrect Authorization Vulnerability
    Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 05
    CVE-2026-5430 · WSO2 Multiple Products Path Traversal Vulnerability
    WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 06
    CVE-2026-94127 · F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
    F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 07
    CVE-2026-93952 · Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
    Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 08
    CVE-2026-93616 · Check Point Multiple Products Path Traversal Vulnerability
    Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 09
    CVE-2026-85102 · Check Point Multiple Products Improper Certificate Validation Vulnerability
    Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 10
    CVE-2026-7273 · Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
    Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 11
    CVE-2026-53266 · Linux Kernel Out-of-Bounds Write Vulnerability
    Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 12
    CVE-2025-39964 · Linux Kernel Race Condition Vulnerability
    Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 13
    CVE-2025-39682 · Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
    Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 14
    CVE-2026-87886 · Acronis Backup Incorrect Default Permissions Vulnerability
    Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 15
    CVE-2026-76460 · Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
    Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 16
    CVE-2026-58704 · Google Pixel Improper Authorization Vulnerability
    Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 17
    CVE-2026-76461 · Cisco Secure Email Gateway SQL Injection Vulnerability
    Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 18
    CVE-2026-85706 · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
    GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 19
    CVE-2026-84869 · ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
    ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  • 20
    CVE-2026-42018 · JFrog Artifactory Improper Authentication Vulnerability
    JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
1分钟前更新
  • 01
    CVE-2026-94419 · LOW 2.3
    Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() validates it against that hash alone. Because the TLS 1.2 session ID is chosen by the server and sent in clear, AddSessionToCache() matches any other server's session on the same ID and overwrites the client-side entry with that server's master secret, cipher suite and version, while the handle continues to resolve; nothing on the write path compares the peer, the application's server ID or the WOLFSSL_CTX. Resuming through the handle then produces an abbreviated handshake in which no Certificate message is sent, so neither chain verification nor wolfSSL_check_domain_name() runs, and the attacker is accepted as the original server for the whole of that connection. Affected builds are those leaving NO_SESSION_CACHE_REF, NO_SESSION_CACHE, NO_CLIENT_CACHE and TITAN_SESSION_CACHE all undefined, which includes a plain ./configure, --enable-opensslextra and --enable-opensslall; fifteen integration options define NO_SESSION_CACHE_REF and are therefore not affected, among them --enable-all, --enable-distro, --enable-curl, --enable-nginx, --enable-haproxy, --enable-stunnel, --enable-wpas and the rest of the OPENSSL_COMPATIBLE_DEFAULTS family, and --enable-leanpsk, --enable-leantls, --enable-lowresource and --enable-tinytls13 disable the cache outright. The application must use the legacy reference flow, wolfSSL_get_session() or SSL_get_session() followed by wolfSSL_set_session(); wolfSSL_get1_session() returns the session object itself and is not affected, nor are wolfSSL_SetServerID() lookups. Only TLS 1.2 and below and DTLS 1.2 and below are reachable, since TLS 1.3 and ticket resumption with an empty ServerHello session ID both use a client-chosen cache key. The poisoned entry lives in the process-global cache, so it crosses WOLFSSL_CTX boundaries and persists until the entry is evicted or the session times out, 500 seconds by default. Releases v5.3.0 through v5.9.2 are affected; the fix adds a per-write generation counter to the cache and raises WOLFSSL_CACHE_VERSION from 2 to 3, so a cache persisted by an older build is rejected by a fixed one.
  • 02
    CVE-2026-94418 · LOW 2.3
    Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the parse returned 0, so any parse error hid it. ParseCertRelative() reaches its validity-date, name-constraint and critical-extension checks only after ConfirmSignature() has passed, so splitting the signature check out inverts the precedence that makes "override date errors" a sound policy, and ASN_SIG_CONFIRM_E is never surfaced anywhere. The attacker needs no key material from the real PKI and no CA compromise: a self-made certificate carrying the expected subject name, the trusted CA's subject as its issuer, arbitrary bytes where the signature goes, a validity window in the past and the attacker's own key pair is sufficient. Affected builds define WOLFSSL_SMALL_CERT_VERIFY, which is off by default, is not set implicitly by any platform or preset header, and is not reachable from any CMake option; the autotools routes are --enable-lowresource, --enable-leantls, --enable-tinytls13=cert and --enable-tinytls13=mutualauth, and examples/configs/user_settings_embedded.h reaches it through WC_CFG_SMALL_CERT_VERIFY, which ships as 0, while neither --enable-all nor --enable-distro enables it at all. The application must additionally install a verify callback through wolfSSL_CTX_set_verify() or wolfSSL_set_verify() with WOLFSSL_VERIFY_PEER that returns 1 for ASN_BEFORE_DATE_E or ASN_AFTER_DATE_E; wolfSSL ships this exact shape as myVerify() in wolfssl/test.h under VERIFY_OVERRIDE_DATE_ERR, which examples/client -D selects. An application with no callback, or whose callback returns preverify for date errors, still fails the handshake, and wolfSSL_CertManagerVerifyBuffer() and wc_CheckCertSignature() report ASN_SIG_CONFIRM_E correctly in the same binary. TLS 1.2 and TLS 1.3 are affected in both directions, and DTLS reaches the same function; where the forged certificate is a chain certificate the callback's consent causes it to be cached in the WOLFSSL_CTX certificate manager, so an exposed deployment must restart the context or the process rather than merely reconnect.
  • 03
    CVE-2026-100741 · CRITICAL 9.8
    Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password containing a backslash followed by an apostrophe, sent in any logon (SMTP AUTH, POP3, IMAP) that names an existing, active account. Exploitation requires a non-default configuration: event scripting enabled (off by default), the script language set to JScript (the default is VBScript), and an OnClientValidatePassword handler defined in the event script. The server wrote event values into the handler call as JScript string literals, escaping the apostrophe but not the backslash, so such a value closes the literal and the rest of it is parsed as script. The same flaw is reachable by a remote POP3 server through the message UID it returns, where an OnExternalAccountDownload handler is defined, and by a remote SMTP server through the error reply it rejects a delivery with, where an OnDeliveryFailed handler is defined. Before 6.2.25 the injected script can create any COM object, and from 6.2.25 it can with the default ScriptAllowedObjects value of '*'; WScript.Shell among them gives command execution as the service account. VBScript event scripts and the Linux builds of Progressive Robot Ltd's hMailServer are not affected.
  • 04
    CVE-2026-97319 · UNKNOWN
    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
  • 05
    CVE-2026-97227 · UNKNOWN
    The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
  • 06
    CVE-2026-96899 · UNKNOWN
    The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks.
  • 07
    CVE-2026-96897 · UNKNOWN
    The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected install.
  • 08
    CVE-2026-96896 · UNKNOWN
    The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
  • 09
    CVE-2026-96895 · UNKNOWN
    The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when rendering the block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
  • 10
    CVE-2026-92995 · UNKNOWN
    The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handler, allowing unauthenticated users to download the digital-goods files attached to any order without authorization.
  • 11
    CVE-2026-92436 · UNKNOWN
    The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loading a saved cart from a request-supplied identifier that is derived from a customer's email address, allowing an unauthenticated attacker who knows a customer's email address to confirm that the customer shops at the store and to read that customer's saved cart contents.
  • 12
    CVE-2026-89006 · UNKNOWN
    The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
  • 13
    CVE-2026-89003 · UNKNOWN
    The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
  • 14
    CVE-2026-89001 · UNKNOWN
    The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
  • 15
    CVE-2026-89000 · UNKNOWN
    The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
  • 16
    CVE-2026-86841 · UNKNOWN
    The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly assign, to inject arbitrary PHP objects, overwrite privileged site options, and read stored integration secrets.
  • 17
    CVE-2026-86839 · UNKNOWN
    The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff members' appointments and payments, including the associated customer's personal information.
  • 18
    CVE-2026-86609 · UNKNOWN
    The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin before 7.5.6 published under the same slug does not ship the affected feature.
  • 19
    CVE-2026-85002 · UNKNOWN
    The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.
  • 20
    CVE-2026-84069 · UNKNOWN
    The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion.
7分钟前更新
  • 01
    🔄
    🔄 Мапу оновлено ⚔️ Ворог просунувся поблизу Калеників . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 02
    🔄
    🔄 Мапу оновлено ⚔️ Ворог окупував Новоолександрівку , а також просунувся поблизу Юрківки та Василівки . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 03
    🇺🇦
    🇺🇦 Гарна порція скидів на голови кацапів з Краматорського відтинку від пілотів ББС 67 ОМБр "Залізні соколи" 📍 Локація — поблизу Федорівки . Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 04
    🇷🇺
    🇷🇺 Пілоти SIGNUM нищать логістику ворога 🍑 Для ворога "тил" давно перестав бути безпечним місцем. Саме такою технікою вони перевозять особовий склад, боєкомплект, забезпечення та все необхідне для ведення війни. 🫡 Маєш лідерські якості або сильну спеціальність? Приєднуйся до SIGNUM! Підберемо роль під твої навички ще ДО мобілізації. 📋 Залишай заявку: signum.army ☎️ Або телефонуй: +380680681619 Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 05
    🇵🇱
    🇵🇱 Російський Мі-8 залетів на 300 метрів у повітряний простір Польщі 🖥 Про інцидент повідомляє TVN24 з посиланням на Оперативне командування видів ЗС Польщі та його речника, підполковника Яцека Горишевського . ✈️ 23 вересня о 11:08 на північ від Бранєво у Вармінсько-Мазурському воєводстві російський Мі-8, який летів з Калінінградської області, зайшов у повітряний простір Польщі на максимальну глибину близько 300 метрів . У польському повітряному просторі він перебував 42 секунди . 👀 Політ відстежували радіолокаційні системи ЗС Польщі. Після порушення кордону в повітря підняли винищувачі, а наземні сили та засоби залишалися у готовності. ⚔️ За словами Горишевського, у цей час у прикордонному районі проходили навчання російських військ. Польська сторона стежила за цією активністю, а Мі-8 сам розвернувся та повернувся до Калінінградської області. «Можна чітко сказати, що росія вкотре перевіряє готовність нашої протиповітряної оборони», — заявив Горишевський в ефірі TVN24. ℹ️ Напередодні польські винищувачі перехопили над Балтійським морем російський розвідувальний Іл-20 приблизно за 40 км від польського узбережжя. Тоді порушення повітряного простору Польщі не зафіксували. 🔎 За даними…
  • 06
    В Україні запустили Defence Tech Academy — освітню платформу для оборонної галузі
    В Україні запустили Defence Tech Academy — освітню платформу для оборонної галузі Команда Blyskavka Tech та просвітницька ініціатива «Останній капіталіст» запустили Defence Tech Academy — онлайн-платформу для підготовки та розвитку фахівців української оборонної індустрії. На старті платформа запустила програми з: — технічної документації — юридичного супроводу Defence Tech — управління проєктами в Defence tech — продажів в оборонній галузі — Проведення стратегічних сесій для DefTech Викладачами стали фахівці з реальним досвідом роботи в українських Defence Tech-компаніях. Навчання побудоване навколо практичних завдань і передбачає менторську підтримку. Наступний великий напрям Defence Tech Academy — інженерні програми. Довгострокова мета команди — допомагати новим фахівцям переходити в оборонну індустрію та збільшувати кількість підготовлених кадрів для українських Defence Tech-компаній. Також команда планує запускати безкоштовні освітні проєкти — як у відкритому доступі, так і окремо для військовослужбовців. 👉 Більше про Defence Tech Academy: deftech.academy #реклама
  • 07
    🦅
    🦅 1 корпус НГУ «Азов» провів зачистку сил противника в своїй смузі відповідальності, які накопичилася за літо за рахунок просочування противника ➡️ Зачистку було проведено силами ЗРСП, 1-го та 6-го батальйонів 12-ї бригади спеціального призначення « Азов », ОЗСП « Туман » 1-го корпусу НГУ «Азов» та батальйону «Шквал» 425-го ОШП « Скеля », за підтримки ОЗСП « Lasar’s Group » НГУ, закривши просування противника в напрямку Дружківки. 🇷🇺 Противник весь час здійснює тиск піхотою, застосовуючи тактику інфільтрації малими групами за постійної підтримки великої кількості дронів. Ведення оборони на даному відтинку складає труднощі, адже кацапи мають значне накопичення і мають можливість здійснювати штурмові дії практично без пауз. Тож перед корпусом та в цілому новоствореним угрупування військ стоїть нелегка задача по стримуванню ворога. Успішні дії при таких умовах це велике досягнення. Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 08
    🔄
    🔄 Мапу оновлено ⚔️ Сили Оборони України здійснили зачистку поблизу Торецького . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 09
    🔄
    🔄 Мапу оновлено ⚔️ Ворог окупував Маркове та просунувся поблизу Федорівки . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 10
    🏹
    🏹 23 ОШП "Р.У.Г." 2 КНГУ "Хартія" продовжує повертати контроль поблизу Западного ➡️ Згідно з матеріалами відео, Сили Оборони змогли звільнити Западне та лісосмуги південніше. Крім того, вдалося ще й відкинути основні сили противника східніше. Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 11
    🇷🇺
    🇷🇺 Кремлівська платіжна мережа провела понад $6,9 млрд через міжнародні банки за фальшивими документами 🖥 Повʼязана з кремлем фінтех-компанія A7 за допомогою фіктивних фірм і підроблених документів провела через міжнародну банківську систему понад $6,9 млрд, обходячи західні санкції, пише Financial Times. 🔎 Журналісти FT отримали витік внутрішніх документів A7. Компанію наприкінці 2024 року створили за підтримки підсанкційного Промсвязьбанку та молдовського олігарха Ілана Шора. 👀 Мережа використовувала понад сотню компаній-прокладок, зокрема в ОАЕ, Гонконзі, Великій Британії та Угорщині. Для платежів готували фальшиві інвойси й печатки, а також змінювали митні коди, щоб приховати справжній зміст операцій. 📌 Через схему оплачували товари, повʼязані з війною, та закупівлі для російських силових структур. Спочатку A7 переказувала кошти через Киргизстан, а після посилення контролю змістила частину операцій до ОАЕ. ℹ️ У платежах фігурували Standard Chartered, Citigroup, Deutsche Bank, JPMorgan і First Abu Dhabi Bank. За даними FT, більшість банків згодом закрили повʼязані з A7 рахунки та заявили про дотримання санкційних вимог. Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 12
    Відчуваєте, що AI поступово "відбирає" вашу інженерну експертизу?
    Відчуваєте, що AI поступово "відбирає" вашу інженерну експертизу? Все більше Middle та Senior Engineers стикаються з однією проблемою: AI спрощує виконання задач, але разом із цим інженер дедалі частіше стає просто executor — замість того, щоб проєктувати складні системи та приймати архітектурні рішення. Через це виникає відчуття, що професійно стоїш на місці. Саме для досвідчених інженерів Neoversity створили master-level програму Engineering of Autonomous AI Systems . Це не курс про промпти, Cursor чи використання ChatGPT. Це навчання про те, як проєктувати production-grade системи навколо AI: керовані, надійні, захищені та готові до масштабування. За 18 місяців ви опануєте: → Advanced RAG та Vector Databases → Autonomous Agents та Multi-Agent Orchestration → Harness Engineering → AI Security та Red Teaming → ML System Design → MLOps для AI → Control Patterns → AI Governance ✔️ Bridge Course + 9 дисциплін + Capstone ✔️ Онлайн паралельно з роботою ✔️ Для досвідчених Engineers із 3+ роками комерційної розробки ✔️ Міжнародний диплом магістра Якщо відчуваєте, що настав час перейти від використання AI до архітектури AI-систем — ця програма саме про цей перехід. 👉 Детальніше: https://c…
  • 13
    🇺🇸
    🇺🇸 🇩🇰 США, Данія та Гренландія підпишуть угоду про розширення американської військової присутності в Арктиці 🖥 Президент США Дональд Трамп, премʼєр-міністерка Данії Метте Фредеріксен і премʼєр Гренландії Єнс-Фредерік Нільсен мають підписати тристоронню безпекову угоду під час Генасамблеї ООН у Нью-Йорку. 🔎 Вона передбачає створення двох нових американських військових обʼєктів на острові, у Нарсарсуаку на території колишньої авіабази та у Местерсвігу, який нині використовують данські сили спеціальних операцій. 👀 США вже мають у Гренландії космічну базу Пітуффік. Нова угода має стати найбільшим розширенням американської військової інфраструктури на острові з часів Холодної війни. ℹ️ Трамп заявив, що угода надасть США «постійний контроль» над безпекою Гренландії. Данія натомість наполягає, що зберігає суверенітет над островом, а Гренландія має право на самовизначення. Повний текст домовленості ще не оприлюднили. 🤝 Учасники прагнуть перевести арктичну безпеку у рамку колективного нагляду НАТО та закрити суперечку, яку Трамп раніше загострив закликами придбати Гренландію. Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 14
    🔄
    🔄 Мапу оновлено ⚔️ Сили Оборони України повернули контроль поблизу Западного . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 15
    🌀
    🌀 Бійці 33 ОШП поділилися кадрами роботи на Гуляйпільському відтинку ⚔️ Кацапське командування відчайдушно намагається збити інтенсивність наступальних дій 33 ОШП та 1 ОШП своїми зустрічними атаками, масово направляючи окупантів у зустрічні бої. Але всі ці спроби незмінно зустрічаються зі щільним вогневим ураженням FPV ще на дальніх підступах. Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 16
    🇨🇳
    🇨🇳 Китай виключив із партії та армії двох топгенералів 🖥 Китайська влада виключила з Комуністичної партії та звільнила з військової служби Чжан Юся і Лю Чженьлі . Їм закидають серйозні порушення партійної дисципліни й законів, зокрема корупцію та політичну нелояльність, повідомляє Reuters. 🔎 Чжан був заступником голови Центральної військової комісії КНР і членом Політбюро. Лю входив до складу комісії та очолював її Об’єднаний штаб. Розслідування щодо обох почали у січні, а в серпні їх уже вивели зі складу комісії. ℹ️ Китайське керівництво звинуватило генералів у формуванні угруповань, невиконанні обов’язків, політичних та економічних порушеннях. Подробиць справи публічно не розкрили. 🪖 Це продовження антикорупційної кампанії Сі Цзіньпіна, яку він почав у 2012 році . У війську вона посилилася з 2023 року , коли чистки торкнулися Ракетних військ та вищого командування НВАК. 📌 У травні 2026 року колишні міністри оборони Вей Фенхе та Лі Шанфу отримали смертні вироки з дворічною відстрочкою за корупцію. Якщо протягом цього строку вони не скоять нових злочинів, покарання замінять на довічне ув’язнення без права на дострокове звільнення, повідомляв Reuters. 👀 Після усунення Чжана та Лю се…
  • 17
    🇺🇦
    🇺🇦 Тільки факти: оперативно та без маніпуляцій. Важливі історії, незалежна журналістика та головні події дня. Приєднуйтесь до Радіо Свобода! #реклама
  • 18
    🔄
    🔄 Мапу оновлено ⚔️ Сили Оборони України звільнили Шандриголове та Дерилове , а також просунулися поблизу Шандриголового . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 19
    🔄
    🔄 Мапу оновлено ⚔️ Ворог просунувся поблизу Котлиного . 💬 У випадку неточностей, можете повідомити нам про це через бот @newsdeepstatebot . 🗺 deepstatemap.live Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
  • 20
    🤝
    🤝 Український досвід медичної евакуації переймають у Швеції 👥 У рамках відрядження до Королівства Швеція, що відбулося на початку вересня, військовослужбовці 1 окремого медичного батальйону Сухопутних військ ЗСУ поділились досвідом з воїнами Сухопутних військ Швеції та Лейбгвардії, одного з найстаріших полків світу. 💳 Українські медики розповіли про організацію системи військової медицини в умовах широкомасштабної війни. Основну увагу приділили евакуації поранених з поля бою за допомогою наземних роботизованих комплексів. 🔵 Окремий блок зустрічей був присвячений НРК MAUL, створеному з урахуванням практичного досвіду 1 омедб. Шведські військові дізнались не лише про концепцію цього наземного робота, а й про практику його застосування. 🛡 Із військовослужбовцями Першого медичного зустрівся Головнокомандувач Збройних сил Королівства Швеція генерал Мікаель Классон. Він особисто ознайомився з українським досвідом медичної евакуації та застосування НРК, наголосив, що українці здобувають цей досвід ціною крові, і подякував за можливість допомогти Швеції зміцнювати її безпеку. Мапа 🛑 Блог 🛑 Написати нам 🛑 ЗСУHelp 🛑 Підтримати нас
2分钟前更新
  • 013.8万
  • 022.2万
    security-audit-skill
    A coding-agent skill for multi-phase security audits with independently verified, machine-readable findingscloudflare
  • 0314.8万
    claude-code
    Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.anthropics
  • 048.8万
    paperclip
    The open-source app everyone uses to manage agents at workpaperclipai
  • 053.5万
    hindsight
    Hindsight: Agent Memory That Learnsvectorize-io
  • 063.0万
    WeKnora
    Open-source LLM knowledge platform: turn raw documents into a queryable RAG, an autonomous reasoning agent, and a self-maintaining Wiki.Tencent
  • 0726.8万
    ECC
    The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.affaan-m
  • 087.9万
    orca
    Orca is the ADE for working with a fleet of parallel agents. Run any coding agent with your own subscription. Available on desktop, mobile and remote runtime.stablyai
  • 093.2万
    claude-code-templates
    CLI tool for configuring and monitoring Claude Codedavila7
  • 104.2万
    open-code-review
    Secure, fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.alibaba
  • 112.6万
    knowledge-work-plugins
    Open source repository of plugins primarily intended for knowledge workers to use in Claude Coworkanthropics
  • 129.9万
    agent-skills
    Production-grade engineering skills for AI coding agents.addyosmani
  • 1310.3万
    pytorch
    Tensors and Dynamic neural networks in Python with strong GPU accelerationpytorch
  • 145.1万
    CLI-Anything
    "CLI-Anything: Making ALL Software Agent-Native" -- CLI-Hub: https://clianything.cc/HKUDS
  • 151.3万
    quiche
    🥧 Savoury implementation of the QUIC transport protocol and HTTP/3cloudflare
  • 165181
    Octop
    A smarter, self-hosted AI assistant — multi-user, multi-agent.TencentCloud
  • 173539
    treg
    OpenRouter for agent tools. Join community here: https://discord.gg/6mQYYfFMAnsuperdesigndev
  • 182.0万
    univer
    The Office Harness for AI Agents — Spreadsheets, Docs, Slides, Canvas, Relational Tables, and PDF in one runtime.dream-num
  • 01
    Compressing Streaming Neural Audio Encoders via Latent-Space Distillation
    System-wide Dictation on Apple devices runs entirely on-device, and the speech it transcribes reaches the foundation model through a tokenizer: an encoder that maps short windows of waveform onto the representation the language model reads. Because that model is sparsely activated under Instruction-Following Pruning, only a small subset of its experts occupies DRAM at any time, so the always-on tokenizer competes for the same memory, and its parameter count bears directly on power and latency. I
  • 02
    A Practical Recipe for Semi-Supervised Federated ASR: Online Pseudo-Labels with Server Update Stabilization
    Semi-supervised federated learning (SSFL) trains models on clients’ unlabeled data using a teacher to generate pseudo-labels, with a small labeled seed dataset on the server. Automatic Speech Recognition (ASR) is particularly fragile here: pseudo-label errors compound across the output sequence and across training rounds into divergence, leaving a large gap to fully-supervised FL. We show that closing this gap turns on two coupled design axes—the teacher (which model generates the pseudo-labels)
  • 03
    How to Guide Your Language Flow
    We introduce a new method to guide flow matching models. Our approach, which we call probe guidance, uses the frozen internal states of an existing diffusion model to construct a guidance signal. This works using a similar principle as autoguidance, but eliminates the need for an additional forward pass at inference time and provides a reliable path to ensure that the weak and strong model share similar dynamics. We apply and benchmark this method on continuous diffusion language models, where p
  • 04
    Dynamically Scaled Activation Steering
    Activation steering has emerged as a powerful method for guiding the behavior of generative models towards desired outcomes such as toxicity mitigation. However, most existing methods apply interventions uniformly across all inputs, degrading model performance when steering is unnecessary. We introduce Dynamically Scaled Activation Steering (DSAS), a method-agnostic steering framework that decouples when to steer from how to steer. DSAS adaptively modulates the strength of existing steering tran
  • 05
    REVERSAL-BENCH: A Reversibility Axis and Reset Oracle for Measuring the Reset-Free RL Cliff
    A central goal of autonomous reinforcement learning is continuous policy training without external resets. However, existing paradigms largely depend on underlying environmental reversibility, a property absent in real world manipulation, where events such as pushing objects off tables or spilling granular substances cannot be undone. We introduce REVERSAL-BENCH, a benchmark that controls reversibility via a continuous parameter ρ∈ [0, 1] and provides a reset oracle, a ground-truth verification
  • 06
    Shared Selective Persistent Memory for Agentic LLM Systems
    Agentic LLM systems that generate code through multi-turn tool use face a fundamental context problem: each session starts from zero, discarding the configuration choices, domain constraints, data schemas, and tool-use patterns that made previous sessions productive. Naively persisting entire conversation histories is both token-inefficient and counterproductive—irrelevant context degrades generation quality. We introduce shared selective persistent memory, a memory architecture for agentic syst
  • 07
    Glyph: A Multi-Strategy Agentic System for Column Description and Sensitivity-Ontology Tagging of Enterprise Data Catalogs
    Enterprise data lakes accumulate tables faster than human stewards can document or classify them, leaving columns with missing descriptions and unassigned governance labels. This documentation debt undermines data discovery, access control, and regulatory compliance. We present Glyph, a production system that frames two coupled problems, column description generation and column type annotation for data classification, as cooperating LLM agents orchestrated as stateful graphs. The Descriptor grou
  • 08
    DACA-GRPO: Denoising-Aware Credit Assignment for Reinforcement Learning in Diffusion Language Models
    Diffusion large language models are a compelling alternative to autoregressive models, yet existing RL methods for diffusion treat all denoising steps as equally important and rely on biased, high-variance likelihood estimates. We identify two fundamental weaknesses: the absence of temporal credit assignment across the denoising trajectory, and the systematic bias of mean-field likelihood estimates used for policy optimization. To address these, we propose Denoising-Aware Credit Assignment for G
  • 09
    Trajectory as the Teacher: Few-Step Discrete Flow Matching via Energy-Navigated Distillation
    Discrete flow matching generates text by iteratively transforming noise tokens into coherent language, but may require hundreds of forward passes. Distillation uses the multi-step trajectory to train a student to reproduce the process in a few steps. When the student underperforms, the usual explanation is insufficient capacity. We argue the opposite: the trajectory is the bottleneck, not the student. Each training trajectory is built through a chain of blind stochastic jumps with no evaluation
  • 10
    How Value Induction Reshapes LLM Behaviour
    Conversational Large Language Models are post-trained on language that expresses specific behavioural traits, such as curiosity, open-mindedness, and empathy, and values, such as helpfulness, harmlessness, and honesty. This is done to increase utility, ensure safety, and improve the experience of the people interacting with the model. However, values are complex and inter-related – inducing one could modify behaviour on another. Further, inducing certain values can make models more addictive or
  • 016.8亿
    hashbrown
    排名:1 · 版本:0.17.1 · A Rust port of Google's SwissTable hash map · 累计下载:2,535,629,284 · 近期下载:679,848,588
  • 026.2亿
    syn
    排名:2 · 版本:3.0.6 · Parser for Rust source code · 累计下载:2,486,802,743 · 近期下载:617,182,105
  • 035.9亿
    getrandom
    排名:3 · 版本:0.4.3 · A small cross-platform library for retrieving random data from system source · 累计下载:2,093,068,354 · 近期下载:586,343,575
  • 044.6亿
    rand
    排名:4 · 版本:0.10.3 · Random number generators and other randomness functionality. · 累计下载:1,778,620,103 · 近期下载:456,547,425
  • 054.5亿
    rand_core
    排名:5 · 版本:0.1.1 · Core random number generator traits and tools for implementation. · 累计下载:1,796,617,675 · 近期下载:448,392,997
  • 064.4亿
    bitflags
    排名:6 · 版本:2.13.2 · A macro to generate structures which behave like bitflags. · 累计下载:1,905,216,749 · 近期下载:441,646,811
  • 074.2亿
    windows-sys
    排名:7 · 版本:0.61.2 · Rust for Windows · 累计下载:1,620,433,452 · 近期下载:420,722,887
  • 083.8亿
    quote
    排名:8 · 版本:1.0.47 · Quasi-quoting macro quote!(...) · 累计下载:1,668,523,917 · 近期下载:381,159,852
  • 093.8亿
    thiserror
    排名:9 · 版本:2.0.21 · derive(Error) · 累计下载:1,518,978,905 · 近期下载:379,666,892
  • 103.8亿
    thiserror-impl
    排名:10 · 版本:2.0.21 · Implementation detail of the `thiserror` crate · 累计下载:1,519,172,471 · 近期下载:379,623,385
  • 113.7亿
    libc
    排名:11 · 版本:1.0.0-alpha.4 · Raw FFI bindings to platform libraries like libc. · 累计下载:1,681,201,081 · 近期下载:374,304,616
  • 123.7亿
    indexmap
    排名:12 · 版本:2.14.2 · A hash table with consistent order and fast iteration. · 累计下载:1,591,814,465 · 近期下载:368,095,828
  • 133.7亿
    proc-macro2
    排名:13 · 版本:1.0.107 · A substitute implementation of the compiler's `proc_macro` API to decouple token-based libraries from the procedural macro use case. · 累计下载:1,662,454,700 · 近期下载:367,488,559
  • 143.7亿
    memchr
    排名:14 · 版本:2.8.3 · Provides extremely fast (uses SIMD on x86_64, aarch64 and wasm32) routines for 1, 2 or 3 byte search and single substring search. · 累计下载:1,462,743,829 · 近期下载:367,008,498
  • 153.4亿
    itertools
    排名:15 · 版本:0.15.0 · Extra iterator adaptors, iterator methods, free functions, and macros. · 累计下载:1,554,791,569 · 近期下载:342,547,348
  • 163.4亿
    unicode-ident
    排名:16 · 版本:1.0.26 · Determine whether characters have the XID_Start or XID_Continue properties according to Unicode Standard Annex #31 · 累计下载:1,420,075,088 · 近期下载:339,665,570
  • 173.4亿
    base64
    排名:17 · 版本:0.23.1 · encodes and decodes base64 as bytes or utf8 · 累计下载:1,624,065,996 · 近期下载:339,416,400
  • 183.3亿
    cfg-if
    排名:18 · 版本:1.0.5 · A macro to ergonomically define an item depending on a large number of #[cfg] parameters. Structured like an if-else chain, the first matching branch is the item that gets emitted. · 累计下载:1,482,610,468 · 近期下载:327,350,991
  • 193.3亿
    serde_json
    排名:19 · 版本:1.0.151 · A JSON serialization file format · 累计下载:1,347,598,926 · 近期下载:326,186,257
  • 203.2亿
    itoa
    排名:20 · 版本:1.0.18 · Fast integer primitive to string conversion · 累计下载:1,385,115,367 · 近期下载:324,939,814
2分钟前更新
10小时前更新
  • 0119.8万
    Sober
    排名:1 · Play, chat & explore on Roblox · 分类:game · 近 30 天安装:198,181 · 趋势分:-0.99 · 许可:LicenseRef-proprietary=https://sober.vinegarhq.org/notice.txt · 开发者已验证VinegarHQ & Sober contributors
  • 0218.7万
    Firefox
    排名:2 · Fast, Private & Safe Web Browser · 分类:network · 近 30 天安装:186,694 · 趋势分:-0.11 · 许可:MPL-2.0 · 开发者已验证Mozilla
  • 0317.6万
    Discord
    排名:3 · Talk, play, hang out · 分类:network · 近 30 天安装:176,169 · 趋势分:-1.64 · 许可:LicenseRef-proprietary · 开发者已验证Discord Inc.
  • 0417.2万
    Brave
    排名:4 · Fast Internet, AI, Adblock · 分类:network · 近 30 天安装:172,291 · 趋势分:-1.66 · 许可:MPL-2.0 · 开发者已验证Brave Software
  • 0516.7万
    Google Chrome
    排名:5 · The browser built to be yours · 分类:network · 近 30 天安装:167,411 · 趋势分:-0.41 · 许可:LicenseRef-proprietaryGoogle
  • 0614.2万
    Bottles
    排名:6 · Run Windows software · 分类:utility · 近 30 天安装:142,041 · 趋势分:-0.17 · 许可:GPL-3.0-only · 开发者已验证The Bottles Contributors
  • 0711.6万
    Spotify
    排名:7 · Online music streaming service · 分类:audiovideo · 近 30 天安装:116,285 · 趋势分:-1.04 · 许可:LicenseRef-proprietary=https://www.spotify.com/us/legal/end-user-agreement/Spotify
  • 0810.4万
    VLC
    排名:8 · VLC media player, the open-source multimedia player · 分类:audiovideo · 近 30 天安装:104,345 · 趋势分:0.40 · 许可:GPL-2.0+VideoLAN et al.
  • 099.8万
    Steam
    排名:9 · Launcher for the Steam software distribution service · 分类:game · 近 30 天安装:97,662 · 趋势分:-0.97 · 许可:LicenseRef-proprietaryValve Corporation
  • 109.7万
    Flatseal
    排名:10 · Manage Flatpak permissions · 分类:utility · 近 30 天安装:96,612 · 趋势分:0.76 · 许可:GPL-3.0-or-later · 开发者已验证Martin Abente Lahaye
  • 119.6万
    Heroic
    排名:11 · Play Epic, GOG and Amazon Games · 分类:game · 近 30 天安装:96,154 · 趋势分:-0.58 · 许可:GPL-3.0 · 开发者已验证Heroic Games Launcher
  • 129.1万
    OBS Studio
    排名:12 · Live stream and record videos · 分类:audiovideo · 近 30 天安装:91,436 · 趋势分:-0.59 · 许可:GPL-2.0-or-later · 开发者已验证OBS Project
  • 138.9万
    Telegram
    排名:13 · New era of messaging · 分类:network · 近 30 天安装:89,249 · 趋势分:0.10 · 许可:GPL-3.0 · 开发者已验证Telegram FZ-LLC
  • 148.4万
    ONLYOFFICE Desktop Editors
    排名:14 · Office productivity suite · 分类:office · 近 30 天安装:83,676 · 趋势分:-0.20 · 许可:AGPL-3.0-only · 开发者已验证ONLYOFFICE
  • 158.1万
    Prism Launcher
    排名:15 · Custom Minecraft Launcher to easily manage multiple Minecraft installations at once · 分类:game · 近 30 天安装:80,816 · 趋势分:-0.34 · 许可:GPL-3.0-only · 开发者已验证Prism Launcher Contributors
  • 167.5万
    Obsidian
    排名:16 · Markdown-based knowledge base · 分类:office · 近 30 天安装:75,019 · 趋势分:-0.81 · 许可:LicenseRef-proprietary=https://obsidian.md/eula · 开发者已验证Obsidian
  • 176.8万
    RetroArch
    排名:17 · Frontend for emulators, game engines and media players · 分类:game · 近 30 天安装:67,875 · 趋势分:-1.34 · 许可:GPL-3.0-or-later · 开发者已验证libretro
  • 186.7万
    LocalSend
    排名:18 · Share files to nearby devices · 分类:utility · 近 30 天安装:67,303 · 趋势分:0.37 · 许可:Apache-2.0 · 开发者已验证Tien Do Nam
  • 196.7万
    ProtonUp-Qt
    排名:19 · Install Wine- and Proton-based compatibility tools · 分类:game · 近 30 天安装:66,668 · 趋势分:0.03 · 许可:GPL-3.0 · 开发者已验证DavidoTek
  • 206.6万
    Extension Manager
    排名:20 · Install GNOME Extensions · 分类:utility · 近 30 天安装:66,330 · 趋势分:0.55 · 许可:GPL-3.0-or-later · 开发者已验证Matthew Jakeman
  • 216.2万
    Dolphin Emulator
    排名:21 · GameCube / Wii / Triforce Emulator · 分类:game · 近 30 天安装:61,814 · 趋势分:-1.69 · 许可:GPL-2.0+Dolphin Emulator Project
  • 226.2万
    GNU Image Manipulation Program
    排名:22 · High-end image creation and manipulation · 分类:graphics · 近 30 天安装:61,669 · 趋势分:-0.65 · 许可:GPL-3.0+ AND LGPL-3.0+ · 开发者已验证The GIMP team
  • 236.0万
    Zen
    排名:23 · Stay focused, browse faster · 分类:network · 近 30 天安装:60,428 · 趋势分:-2.13 · 许可:MPL-2.0 · 开发者已验证Zen Team
  • 246.0万
    Gear Lever
    排名:24 · Manage AppImages · 分类:utility · 近 30 天安装:60,119 · 趋势分:0.58 · 许可:GPL-3.0-or-later · 开发者已验证Lorenzo Paderi
  • 256.0万
    LibreOffice
    排名:25 · The LibreOffice productivity suite · 分类:office · 近 30 天安装:59,782 · 趋势分:0.05 · 许可:MPL-2.0 · 开发者已验证The Document Foundation
  • 265.8万
    qBittorrent
    排名:26 · An open-source Bittorrent client · 分类:network · 近 30 天安装:57,658 · 趋势分:-0.23 · 许可:GPL-3.0-or-later and OpenSSL · 开发者已验证The qBittorrent Project
  • 275.7万
    Visual Studio Code
    排名:27 · Code editing. Redefined. · 分类:development · 近 30 天安装:57,446 · 趋势分:-2.04 · 许可:LicenseRef-proprietary=https://code.visualstudio.com/licenseMicrosoft Corporation
  • 285.6万
    Lutris
    排名:28 · Video game preservation platform · 分类:game · 近 30 天安装:56,005 · 趋势分:0.10 · 许可:GPL-3.0-or-later · 开发者已验证Lutris Team
  • 295.6万
    PPSSPP
    排名:29 · A PlayStation Portable emulator · 分类:game · 近 30 天安装:55,885 · 趋势分:-1.53 · 许可:GPL-2.0-or-later · 开发者已验证Henrik Rydgård
  • 305.4万
    Proton VPN
    排名:30 · Secures your internet and protects your online privacy · 分类:network · 近 30 天安装:53,931 · 趋势分:-1.44 · 许可:GPL-3.0Proton AG
  • 314.9万
    ProtonPlus
    排名:31 · Manage Proton, Wine, DXVK, and VKD3D tools for Linux game launchers · 分类:game · 近 30 天安装:48,770 · 趋势分:-1.85 · 许可:GPL-3.0-or-later · 开发者已验证Vysp3r
  • 324.6万
    melonDS
    排名:32 · Nintendo DS and DSi emulator · 分类:game · 近 30 天安装:46,071 · 趋势分:-1.78 · 许可:GPL-3.0 · 开发者已验证Arisotura
  • 334.5万
    Mission Center
    排名:33 · Monitor system resource usage · 分类:system · 近 30 天安装:45,018 · 趋势分:-0.09 · 许可:GPL-3.0-or-later · 开发者已验证Mission Center Developers
  • 344.5万
    Stremio
    排名:34 · Freedom to Stream · 分类:utility · 近 30 天安装:45,012 · 趋势分:-0.27 · 许可:GPL-3.0-only · 开发者已验证Stremio
  • 354.5万
    Protontricks
    排名:35 · Apps and fixes for Proton games · 分类:utility · 近 30 天安装:44,787 · 趋势分:-1.03 · 许可:GPL-3.0 · 开发者已验证Janne Pulkkinen
  • 364.4万
    Bitwarden
    排名:36 · A secure and free password manager for all of your devices · 分类:utility · 近 30 天安装:44,205 · 趋势分:-0.17 · 许可:GPL-3.0 · 开发者已验证Bitwarden Inc.
  • 374.3万
    xemu
    排名:37 · Original Xbox Emulator · 分类:game · 近 30 天安装:43,325 · 趋势分:-1.85 · 许可:GPL-2.0-only · 开发者已验证xemu project
  • 384.3万
    Bazaar
    排名:38 · Discover and install apps · 分类:utility · 近 30 天安装:42,922 · 趋势分:1.68 · 许可:GPL-3.0-or-later · 开发者已验证The Bazaar Contributors
  • 394.2万
    LibreWolf
    排名:39 · LibreWolf Web Browser · 分类:network · 近 30 天安装:42,377 · 趋势分:-2.01 · 许可:MPL-2.0 · 开发者已验证LibreWolf Community
  • 403.9万
    Kdenlive
    排名:40 · Video editor · 分类:audiovideo · 近 30 天安装:39,253 · 趋势分:-0.13 · 许可:GPL-3.0-only · 开发者已验证KDE
  • 413.8万
    FreeTube
    排名:41 · Watch YouTube privately · 分类:audiovideo · 近 30 天安装:37,858 · 趋势分:0.12 · 许可:AGPL-3.0+ · 开发者已验证FreeTube Team
  • 423.8万
    Whatsie
    排名:42 · Feature-rich WhatsApp Web client for the Linux desktop · 分类:network · 近 30 天安装:37,650 · 趋势分:-0.70 · 许可:MIT · 开发者已验证Keshav Bhatt
  • 433.7万
    PrimeHack
    排名:43 · Dolphin Emu fork for various Metroid Prime mods · 分类:game · 近 30 天安装:37,013 · 趋势分:-1.76 · 许可:GPL-2.0+ · 开发者已验证Shiiion, SirMangler
  • 443.7万
    Tor Browser Launcher
    排名:44 · A program to help you download, keep updated, and run Tor Browser · 分类:network · 近 30 天安装:36,854 · 趋势分:-4.75 · 许可:MIT · 开发者已验证Tor Project
  • 453.7万
    Fedora Media Writer
    排名:45 · Create a Fedora live USB drive · 分类:system · 近 30 天安装:36,630 · 趋势分:-0.43 · 许可:GPL-2.0+ · 开发者已验证Jan Grulich
  • 463.6万
    ScummVM
    排名:46 · Interpreter for numerous adventure games and role-playing games · 分类:game · 近 30 天安装:35,885 · 趋势分:-1.81 · 许可:GPL-3.0-or-later · 开发者已验证The ScummVM Team
  • 473.6万
    Supermodel
    排名:47 · A Sega Model 3 Arcade Emulator · 分类:game · 近 30 天安装:35,784 · 趋势分:-1.92 · 许可:GPL-3.0-or-laterThe Supermodel Team
  • 483.4万
    Krita
    排名:48 · Digital Painting, Creative Freedom · 分类:graphics · 近 30 天安装:34,417 · 趋势分:0.99 · 许可:GPL-3.0-only · 开发者已验证Krita Foundation
  • 493.3万
    Microsoft Edge
    排名:49 · Introducing the new Microsoft Edge web browser. It’s time to expect more. More privacy. More control. More productivity. More value. · 分类:network · 近 30 天安装:33,201 · 趋势分:-0.44 · 许可:LicenseRef-proprietaryMicrosoft Corporation
  • 503.3万
    Chromium Web Browser
    排名:50 · The web browser from Chromium project · 分类:network · 近 30 天安装:32,926 · 趋势分:10.52 · 许可:BSD-3-Clause and LGPL-2.1+ and Apache-2.0 and IJG and MIT and GPL-2.0+ and ISC and OpenSSL and (MPL-1.1 or GPL-2.0 or LGPL-2.0)The Chromium Authors