English
全部
搜索
图片
视频
地图
资讯
Copilot
更多
购物
航班
旅游
笔记本
Top stories
Sports
U.S.
Local
World
Science
Technology
Entertainment
Business
More
Politics
过去 30 天
时间不限
过去 1 小时
过去 24 小时
过去 7 天
最佳匹配
最新
腾讯网
27 天
高危Markdown转PDF漏洞可通过Markdown前置元数据实现JS注入攻击(CVSS 10.0)
2025年11月24日,广受欢迎的npm包md-to-pdf(每周下载量超47,000次的命令行工具)曝出高危漏洞(CVE-2025-65108)。该漏洞获得CVSS满分10分评级,攻击者可通过恶意前置元数据解析执行任意JavaScript代码。任何使用该包处理不可信Markdown内容的应用程序、构建系统或云服务 ...
一些您可能无法访问的结果已被隐去。
显示无法访问的结果
今日热点
US strikes ISIS targets
Johannesburg mass shooting
Crowd marches against ICE
More Epstein files published
Taiwan knife attack
Joshua knocks out Jake Paul
US seizes another vessel
Today in history: 1913
Wheelchair user in space
3 police officers shot in NY
Rome to charge tourists
Sides with immigration judges
Rare weather warning issued
Judge blocks Trump's plan
Announces retirement
Judge overturns conviction
ICE detainee dies
DOJ appeals tossed cases
Mamdani appointee resigns
US sanctions more relatives
Suspend radio broadcaster
To pay $169M luxury tax
Exits NY governor's race
Signs prison reform bill
Ex-Pak PM, wife sentenced
Picks Southcom commander
Bowen Yang to exit 'SNL'
Trump endorses Blakeman
College Football Playoff
San Francisco power outage
Ex-NY prison guard sentenced
Australia honors victims
反馈