RSS Feeds > Computer & Technik > Internet > Marketing > scip AG [Security - Consulting - Information - Process] | RSS Verzeichnis

scip AG [Security - Consulting - Information - Process]


Anzeigen einer beliebigen Anzahl von Sicherheitsl?cken aus der scip AG Datenbank.

Betreiber-URL: https://www.scip.ch
RSS-Feed-URL: https://www.scip.ch/alertRSS.xml
Die neuesten Einträge aus dem RSS-Feed von scip AG [Security - Consulting - Information - Process]:
CVE-2026-1249 | MP3 Audio Player Plugin up to 5.3/5.10 on WordPress load_lyrics_ajax_callback server-side request forgery
13.02.2026 23:32
A vulnerability identified as critical has been detected in MP3 Audio Player Plugin up to 5.3/5.10 on WordPress. This affects the function load_lyrics_ajax_callback. This manipulation causes server-si...
CVE-2026-1512 | Essential Addons for Elementor Plugin up to 6.5.9 on WordPress Info Box Widget cross site scripting
13.02.2026 23:32
A vulnerability categorized as problematic has been discovered in Essential Addons for Elementor Plugin up to 6.5.9 on WordPress. The impacted element is an unknown function of the component Info Box ...
CVE-2026-0550 | myCred Plugin up to 2.9.7.3 on WordPress Shortcode mycred_load_coupon cross site scripting
13.02.2026 23:31
A vulnerability was found in myCred Plugin up to 2.9.7.3 on WordPress. It has been rated as problematic. The affected element is the function mycred_load_coupon of the component Shortcode Handler. The...
CVE-2026-1843 | Super Page Cache Plugin up to 5.2.2 on WordPress Activity Log cross site scripting
13.02.2026 23:31
A vulnerability was found in Super Page Cache Plugin up to 5.2.2 on WordPress. It has been declared as problematic. Impacted is an unknown function of the component Activity Log. Executing a manipulat...
CVE-2025-15483 | Link Hopper Plugin up to 2.5 on WordPress hop_name cross site scripting
13.02.2026 23:31
A vulnerability was found in Link Hopper Plugin up to 2.5 on WordPress. It has been classified as problematic. This issue affects some unknown processing. Performing a manipulation of the argument hop...
CVE-2026-0751 | Payment Page Form for Stripe Plugin up to 1.4.6 on WordPress pricing_plan_select_text_font_family cross site scripting
13.02.2026 23:30
A vulnerability was found in Payment Page Form for Stripe Plugin up to 1.4.6 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Payment Page. Such man...
CVE-2026-1903 | Ravelry Designs Widget Plugin up to 1.0.0 on WordPress sb_ravelry_designs layout cross site scripting
13.02.2026 23:30
A vulnerability has been found in Ravelry Designs Widget Plugin up to 1.0.0 on WordPress and classified as problematic. This affects the function sb_ravelry_designs. This manipulation of the argument ...
CVE-2026-0736 | Collect.chat Chatbot Plugin up to 2.4.8 on WordPress _inpost_head_script[synth_header_script] cross site scripting
13.02.2026 23:30
A vulnerability, which was classified as problematic, was found in Collect.chat Chatbot Plugin up to 2.4.8 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the a...
CVE-2026-1792 | Geo Widget Plugin up to 1.0 on WordPress cross site scripting
13.02.2026 23:29
A vulnerability, which was classified as problematic, has been found in Geo Widget Plugin up to 1.0 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to ...
CVE-2026-1187 | ZoomifyWP Free Plugin up to 1.1 on WordPress Shortcode zoomify filename cross site scripting
13.02.2026 23:29
A vulnerability classified as problematic was found in ZoomifyWP Free Plugin up to 1.1 on WordPress. Affected is the function zoomify of the component Shortcode Handler. Executing a manipulation of th...
CVE-2026-1915 | Simple Plyr Plugin up to 0.0.1 on WordPress Shortcode plyr poster cross site scripting
13.02.2026 23:28
A vulnerability classified as problematic has been found in Simple Plyr Plugin up to 0.0.1 on WordPress. This impacts the function plyr of the component Shortcode Handler. Performing a manipulation of...
CVE-2026-1985 | Press3D Plugin up to 1.0.2 on WordPress 3D Model Block cross site scripting
13.02.2026 23:28
A vulnerability described as problematic has been identified in Press3D Plugin up to 1.0.2 on WordPress. This affects an unknown function of the component 3D Model Block. Such manipulation leads to cr...
CVE-2026-0753 | Super Simple Contact Form Plugin up to 1.6.2 on WordPress sscf_name cross site scripting
13.02.2026 23:28
A vulnerability marked as problematic has been reported in Super Simple Contact Form Plugin up to 1.6.2 on WordPress. The impacted element is an unknown function. This manipulation of the argument ssc...
CVE-2026-0735 | User Language Switch Plugin up to 1.6.10 on WordPress tab_color_picker_language_switch cross site scripting
13.02.2026 23:28
A vulnerability labeled as problematic has been found in User Language Switch Plugin up to 1.6.10 on WordPress. The affected element is an unknown function. The manipulation of the argument tab_color_...
CVE-2026-1394 | WP Quick Contact Us Plugin up to 1.0 on WordPress Setting cross-site request forgery
13.02.2026 23:28
A vulnerability identified as problematic has been detected in WP Quick Contact Us Plugin up to 1.0 on WordPress. Impacted is an unknown function of the component Setting Handler. The manipulation lea...
CVE-2026-0693 | Allow HTML in Category Descriptions Plugin up to 1.2.4 on WordPress wp_kses_data cross site scripting
13.02.2026 23:28
A vulnerability categorized as problematic has been discovered in Allow HTML in Category Descriptions Plugin up to 1.2.4 on WordPress. This issue affects the function wp_kses_data. Executing a manipul...
CVE-2026-1910 | UpMenu Plugin up to 3.1 on WordPress Shortcode upmenu-menu lang cross site scripting
13.02.2026 23:28
A vulnerability was found in UpMenu Plugin up to 3.1 on WordPress. It has been rated as problematic. This vulnerability affects the function upmenu-menu of the component Shortcode Handler. Performing ...
CVE-2026-0559 | MasterStudy LMS Plugin up to 3.7.11 on WordPress Shortcode stm_lms_courses_grid_display cross site scripting
13.02.2026 23:28
A vulnerability was found in MasterStudy LMS Plugin up to 3.7.11 on WordPress. It has been declared as problematic. This affects the function stm_lms_courses_grid_display of the component Shortcode Ha...
CVE-2026-1905 | Sphere Manager Plugin up to 1.0.2 on WordPress Shortcode show_sphere_image width cross site scripting
13.02.2026 23:26
A vulnerability was found in Sphere Manager Plugin up to 1.0.2 on WordPress. It has been classified as problematic. Affected by this issue is the function show_sphere_image of the component Shortcode ...
CVE-2025-14852 | MDirector Newsletter Plugin up to 4.5.8 on WordPress Setting mdirectorNewsletterSave cross-site request forgery
13.02.2026 23:25
A vulnerability was found in MDirector Newsletter Plugin up to 4.5.8 on WordPress and classified as problematic. Affected by this vulnerability is the function mdirectorNewsletterSave of the component...
CVE-2026-0557 | WP Data Access Plugin up to 5.5.63 on WordPress Shortcode wpda_app cross site scripting
13.02.2026 23:25
A vulnerability has been found in WP Data Access Plugin up to 5.5.63 on WordPress and classified as problematic. Affected is the function wpda_app of the component Shortcode Handler. The manipulation ...
CVE-2026-1795 | Address Bar Ads Plugin up to 1.0.0 on WordPress cross site scripting
13.02.2026 23:25
A vulnerability, which was classified as problematic, was found in Address Bar Ads Plugin up to 1.0.0 on WordPress. This impacts an unknown function. Executing a manipulation can lead to cross site sc...
CVE-2026-0745 | User Language Switch Plugin up to 1.6.10 on WordPress download_language info_language server-side request forgery
13.02.2026 23:25
A vulnerability, which was classified as critical, has been found in User Language Switch Plugin up to 1.6.10 on WordPress. This affects the function download_language. Performing a manipulation of th...
CVE-2026-1901 | QuestionPro Surveys Plugin up to 1.0 on WordPress Shortcode cross site scripting
13.02.2026 23:25
A vulnerability classified as problematic was found in QuestionPro Surveys Plugin up to 1.0 on WordPress. The impacted element is an unknown function of the component Shortcode Handler. Such manipulat...
CVE-2025-14873 | LatePoint Plugin up to 5.2.5 on WordPress call_by_route_name cross-site request forgery
13.02.2026 23:25
A vulnerability classified as problematic has been found in LatePoint Plugin up to 5.2.5 on WordPress. The affected element is the function call_by_route_name. This manipulation causes cross-site requ...
CVE-2026-1796 | StyleBidet Plugin up to 1.0.0 on WordPress cross site scripting
13.02.2026 23:24
A vulnerability described as problematic has been identified in StyleBidet Plugin up to 1.0.0 on WordPress. Impacted is an unknown function. The manipulation results in cross site scripting. This vul...
CVE-2026-2022 | Smart Forms Plugin up to 2.6.99 on WordPress rednao_smart_forms_get_campaigns authorization
13.02.2026 23:23
A vulnerability marked as problematic has been reported in Smart Forms Plugin up to 2.6.99 on WordPress. This issue affects the function rednao_smart_forms_get_campaigns. The manipulation leads to mis...
CVE-2026-1303 | MailChimp Campaigns Plugin up to 3.2.4 on WordPress mailchimp_campaigns_manager_disconnect_app authorization
13.02.2026 23:23
A vulnerability labeled as problematic has been found in MailChimp Campaigns Plugin up to 3.2.4 on WordPress. This vulnerability affects the function mailchimp_campaigns_manager_disconnect_app. Execut...
CVE-2026-1939 | Percent to Infograph Plugin up to 1.0 on WordPress Shortcode cross site scripting
13.02.2026 23:23
A vulnerability identified as problematic has been detected in Percent to Infograph Plugin up to 1.0 on WordPress. This affects an unknown part of the component Shortcode Handler. Performing a manipul...
CVE-2026-1096 | Best-wp-google-map Plugin up to 2.1 on WordPress Shortcode latitude/longitudinal cross site scripting
13.02.2026 23:23
A vulnerability categorized as problematic has been discovered in Best-wp-google-map Plugin up to 2.1 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Hand...
CVE-2026-1258 | Mail Mint Plugin up to 1.19.2 on WordPress API Endpoint order-by/order-type/selectedCourses sql injection
13.02.2026 23:22
A vulnerability was found in Mail Mint Plugin up to 1.19.2 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component API Endpoint. This m...
CVE-2026-1254 | Modula Image Gallery Plugin up to 2.13.6 on WordPress REST API modulaImages authorization
13.02.2026 23:22
A vulnerability was found in Modula Image Gallery Plugin up to 2.13.6 on WordPress. It has been declared as problematic. Affected is an unknown function of the component REST API. The manipulation of ...
CVE-2026-1987 | Scheduler Widget Plugin up to 0.1.6 on WordPress scheduler_widget_ajax_save_event ID resource injection
13.02.2026 23:22
A vulnerability was found in Scheduler Widget Plugin up to 0.1.6 on WordPress. It has been classified as problematic. This impacts the function scheduler_widget_ajax_save_event. The manipulation of th...
CVE-2025-8572 | Truelysell Core Plugin up to 1.8.7 on WordPress User Registration user_role Remote Code Execution
13.02.2026 23:22
A vulnerability was found in Truelysell Core Plugin up to 1.8.7 on WordPress and classified as critical. This affects an unknown function of the component User Registration Handler. Executing a manipu...
CVE-2026-1944 | CallbackKiller Service Widget Plugin up to 1.2 on WordPress Setting cbk_save authorization
13.02.2026 23:20
A vulnerability has been found in CallbackKiller Service Widget Plugin up to 1.2 on WordPress and classified as problematic. The impacted element is the function cbk_save of the component Setting Hand...
CVE-2026-2024 | PhotoStack Gallery Plugin up to 0.4.1 on WordPress postid sql injection
13.02.2026 23:20
A vulnerability, which was classified as critical, was found in PhotoStack Gallery Plugin up to 0.4.1 on WordPress. The affected element is an unknown function. Such manipulation of the argument posti...
CVE-2026-0727 | Accordion and Accordion Slider Plugin up to 1.4.5 on WordPress Attachment Metadata wp_aas_save_attachment_data authorization
13.02.2026 23:20
A vulnerability, which was classified as problematic, has been found in Accordion and Accordion Slider Plugin up to 1.4.5 on WordPress. Impacted is the function wp_aas_save_attachment_data of the comp...
CVE-2026-1932 | Appointment Booking Calendar Plugin up to 1.0.2 on WordPress REST API Endpoint authorization
13.02.2026 23:20
A vulnerability classified as problematic was found in Appointment Booking Calendar Plugin up to 1.0.2 on WordPress. This issue affects some unknown processing of the component REST API Endpoint. The ...
CVE-2026-1306 | midi-Synth Plugin up to 1.1.0 on WordPress export unrestricted upload
13.02.2026 23:19
A vulnerability classified as critical has been found in midi-Synth Plugin up to 1.1.0 on WordPress. This vulnerability affects the function export. The manipulation leads to unrestricted upload. Thi...
CVE-2025-6792 | WPGuppy One to one user Chat Plugin up to 1.1.4 on WordPress Chat Message channel-authorize information disclosure
13.02.2026 23:19
A vulnerability described as problematic has been identified in WPGuppy One to one user Chat Plugin up to 1.1.4 on WordPress. This affects an unknown part of the file /wp-json/guppylite/v2/channel-aut...
CVE-2026-1988 | Flexi Product Slider and Grid for WooCommerce Plugin Attribute path equivalence
13.02.2026 23:19
A vulnerability marked as critical has been reported in Flexi Product Slider and Grid for WooCommerce Plugin up to 1.0.5 on WordPress. Affected by this issue is the function Attribute. Performing a ma...
CVE-2026-26273 | idno known up to 1.6.2 Password Reset Page information disclosure
13.02.2026 23:15
A vulnerability labeled as problematic has been found in idno known up to 1.6.2. Affected by this vulnerability is an unknown functionality of the component Password Reset Page. Such manipulation lead...
CVE-2025-70957 | TON Lite Server prior 2024.09 resource consumption
13.02.2026 23:15
A vulnerability identified as problematic has been detected in TON Lite Server. Affected is an unknown function. This manipulation causes resource consumption. The identification of this vulnerabilit...
CVE-2025-69633 | Advanced Popup Creator Module up to 1.2.6 on PrestaShop AdvancedPopup.php getPopups/updateVisits sql injection
13.02.2026 23:14
A vulnerability categorized as critical has been discovered in Advanced Popup Creator Module up to 1.2.6 on PrestaShop. This impacts the function getPopups/updateVisits of the file classes/AdvancedPop...
CVE-2025-70866 | LavaLite CMS up to 10.1.0 Role-Based Access Control /admin/login access control
13.02.2026 23:13
A vulnerability was found in LavaLite CMS up to 10.1.0. It has been rated as critical. This affects an unknown function of the file /admin/login of the component Role-Based Access Control. The manipul...
CVE-2026-26334 | Calero VeraSMART 2022 R1 Veramark.Framework.dll Veramark.Core.Config hard-coded credentials
13.02.2026 23:13
A vulnerability was found in Calero VeraSMART 2022 R1. It has been declared as critical. The impacted element is the function Veramark.Core.Config in the library Veramark.Framework.dll. Executing a ma...
CVE-2025-70954 | TON Virtual Machine 2024.10/2025.04 INMSGPARAM null pointer dereference
13.02.2026 23:12
A vulnerability was found in TON Virtual Machine 2024.10/2025.04. It has been classified as problematic. The affected element is an unknown function of the component INMSGPARAM Handler. Performing a m...
CVE-2026-26269 | Vim up to 9.1.2147 NetBeans Feature src/netbeans.c special_keys stack-based overflow (GHSA-9w5c-hwr9-hc68)
13.02.2026 23:12
A vulnerability was found in Vim up to 9.1.2147 and classified as critical. Impacted is the function special_keys of the file src/netbeans.c of the component NetBeans Feature. Such manipulation leads ...
CVE-2025-70955 | TON Virtual Machine prior 2024.10 denial of service
13.02.2026 23:12
A vulnerability has been found in TON Virtual Machine and classified as problematic. This issue affects some unknown processing. This manipulation causes denial of service. This vulnerability appears...
CVE-2026-26335 | Calero VeraSMART prior 2022 R1 web.config hard-coded key
13.02.2026 23:11
A vulnerability, which was classified as critical, was found in Calero VeraSMART. This vulnerability affects unknown code of the file C:\Program Files (x86)\Veramark\VeraSMART\WebRoot\web.config. The ...
CVE-2025-70956 | TON Virtual Machine prior 2025.04 VmState::run_child_vm denial of service
13.02.2026 23:11
A vulnerability, which was classified as problematic, has been found in TON Virtual Machine. This affects the function VmState::run_child_vm. The manipulation leads to denial of service. This vulnera...
CVE-2026-26333 | Calero VeraSMART prior 2022 R1 Remoting HTTP Service WebRoot\\web.config WebClient missing authentication
13.02.2026 23:09
A vulnerability classified as critical was found in Calero VeraSMART. Affected by this issue is the function WebClient of the file WebRoot\web.config of the component Remoting HTTP Service. Executing ...
CVE-2025-69770 | MojoPortal CMS 2.9.0.1 ZIP File SkinList.aspx unrestricted upload
13.02.2026 20:44
A vulnerability classified as critical has been found in MojoPortal CMS 2.9.0.1. Affected by this vulnerability is an unknown functionality of the file /DesignTools/SkinList.aspx of the component ZIP ...
CVE-2025-66676 | IObit Unlocker 1.3.0.11 denial of service
13.02.2026 20:43
A vulnerability described as problematic has been identified in IObit Unlocker 1.3.0.11. Affected is an unknown function. Such manipulation leads to denial of service. This vulnerability is listed as...
CVE-2026-25964 | Tandoor Recipes up to 2.5.0 file_path path traversal (GHSA-6485-jr28-52xx)
13.02.2026 20:43
A vulnerability marked as critical has been reported in Tandoor Recipes up to 2.5.0. This impacts an unknown function. This manipulation of the argument file_path causes path traversal. This vulnerab...
CVE-2026-26187 | treeverse lakeFS up to 1.76.x Local Block Adapter adapter.go strings.HasPrefix path traversal (GHSA-699m-4v95-rmpm)
13.02.2026 20:43
A vulnerability labeled as critical has been found in treeverse lakeFS up to 1.76.x. This affects the function strings.HasPrefix of the file pkg/block/local/adapter.go of the component Local Block Ada...
CVE-2026-25991 | Tandoor Recipes up to 2.5.0 Cookmate Integration cookmate.py server-side request forgery (GHSA-j6xg-85mh-qqf7)
13.02.2026 20:32
A vulnerability identified as critical has been detected in Tandoor Recipes up to 2.5.0. The impacted element is an unknown function of the file cookbook/integration/cookmate.py of the component Cookm...
CVE-2026-21870 | bacnet-stack up to 1.4.2/1.5.0.rc2 tokenizer.c tokenizer_string off-by-one (GHSA-pc83-wp6w-93mx)
13.02.2026 20:31
A vulnerability categorized as problematic has been discovered in bacnet-stack up to 1.4.2/1.5.0.rc2. The affected element is the function tokenizer_string of the file src/bacnet/basic/program/ubasic/...
CVE-2026-26264 | bacnet-stack BACnet Stack up to 1.4.3rc1/1.5.0rc3 wp.c wp_decode_service_request out-of-bounds (GHSA-phjh-v45p-gmjj)
13.02.2026 20:31
A vulnerability was found in bacnet-stack BACnet Stack up to 1.4.3rc1/1.5.0rc3. It has been rated as problematic. Impacted is the function wp_decode_service_request of the file wp.c. Performing a mani...
CVE-2026-21878 | bacnet-stack BACnet Stack up to 1.5.0.rc3 apps/readfile/main.c path traversal (GHSA-p8rx-c26w-545j)
13.02.2026 20:31
A vulnerability was found in bacnet-stack BACnet Stack up to 1.5.0.rc3. It has been declared as critical. This issue affects some unknown processing of the file apps/readfile/main.c. Such manipulation...
CVE-2026-26208 | Alex4SSB ADB-Explorer up to Beta 0.9.26019 JSON File Parser Newtonsoft.Json deserialization (ID 294)
13.02.2026 20:31
A vulnerability was found in Alex4SSB ADB-Explorer up to Beta 0.9.26019. It has been classified as critical. This vulnerability affects unknown code of the file Newtonsoft.Json of the component JSON F...
CVE-2026-26190 | milvus-io milvus up to 2.5.26/2.6.9 Full REST API /expr missing authentication (GHSA-7ppg-37fh-vcr6)
13.02.2026 20:30
A vulnerability was found in milvus-io milvus up to 2.5.26/2.6.9 and classified as critical. This affects an unknown part of the file /expr of the component Full REST API. The manipulation results in ...
CVE-2026-2441 | Google Chrome up to 145.0.7632.45 CSS use after free (ID 483569 / Nessus ID 299033)
13.02.2026 20:29
A vulnerability has been found in Google Chrome and classified as critical. Affected by this issue is some unknown functionality of the component CSS. The manipulation leads to use after free. This v...
CVE-2026-1912 | Citations tools Plugin up to 0.3.2 on WordPress Shortcode cross site scripting
13.02.2026 18:31
A vulnerability, which was classified as problematic, was found in Citations tools Plugin up to 0.3.2 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcod...
CVE-2026-1983 | SEATT Plugin up to 1.5.0 on WordPress cross-site request forgery
13.02.2026 18:31
A vulnerability, which was classified as problematic, has been found in SEATT Plugin up to 1.5.0 on WordPress. Affected is an unknown function. Performing a manipulation results in cross-site request ...
CVE-2026-2144 | Magic Login Mail or QR Code Plugin up to 2.05 on WordPress QR Code File Storage wp_mail race condition
13.02.2026 18:31
A vulnerability classified as problematic was found in Magic Login Mail or QR Code Plugin up to 2.05 on WordPress. This impacts the function wp_mail of the component QR Code File Storage. Such manipul...
CVE-2026-1164 | Easy Voice Mail Plugin up to 1.2.5 on WordPress Message cross site scripting
13.02.2026 18:30
A vulnerability classified as problematic has been found in Easy Voice Mail Plugin up to 1.2.5 on WordPress. This affects an unknown function. This manipulation of the argument Message causes cross si...
CVE-2026-1904 | Simple Wp Colorfull Accordion Plugin up to 1.0 on WordPress Shortcode Title cross site scripting
13.02.2026 18:30
A vulnerability described as problematic has been identified in Simple Wp Colorfull Accordion Plugin up to 1.0 on WordPress. The impacted element is an unknown function of the component Shortcode Hand...
CVE-2026-1754 | personal-authors-category Plugin up to 0.3 on WordPress cross site scripting
13.02.2026 18:30
A vulnerability marked as problematic has been reported in personal-authors-category Plugin up to 0.3 on WordPress. The affected element is an unknown function. The manipulation leads to cross site sc...
CVE-2026-2027 | AMP Enhancer Plugin up to 1.0.49 on WordPress Setting cross site scripting
13.02.2026 18:30
A vulnerability labeled as problematic has been found in AMP Enhancer Plugin up to 1.0.49 on WordPress. Impacted is an unknown function of the component Setting Handler. Executing a manipulation can l...
CVE-2026-0692 | BlueSnap Payment Gateway for WooCommerce Plugin up to 3.3.0 on WordPress X-Forwarded-For get_ip_address authorization
13.02.2026 18:30
A vulnerability identified as problematic has been detected in BlueSnap Payment Gateway for WooCommerce Plugin up to 3.3.0 on WordPress. This issue affects the function WC_Geolocation::get_ip_address ...
CVE-2025-1790 | Genetec Sipelia Plugin up to 2.14.270 unnecessary privileges
13.02.2026 18:28
A vulnerability categorized as critical has been discovered in Genetec Sipelia Plugin up to 2.14.270. This vulnerability affects unknown code. Such manipulation leads to execution with unnecessary pri...
CVE-2026-26268 | Cursor up to 2.4 authorization (GHSA-8pcm-8jpx-hv8r)
13.02.2026 18:27
A vulnerability was found in Cursor up to 2.4. It has been rated as problematic. This affects an unknown part. This manipulation causes missing authorization. The identification of this vulnerability...
CVE-2026-26226 | lukilabs beautiful-mermaid up to 0.1.2 SVG Attribute cross site scripting
13.02.2026 18:25
A vulnerability was found in lukilabs beautiful-mermaid up to 0.1.2. It has been declared as problematic. Affected by this issue is some unknown functionality of the component SVG Attribute Handler. T...
CVE-2025-70095 | Open Source Point of Sale 3.4.1 cross site scripting
13.02.2026 18:24
A vulnerability was found in Open Source Point of Sale 3.4.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site sc...
CVE-2025-70093 | OpenSourcePOS 3.4.1 AJAX privilege escalation
13.02.2026 18:23
A vulnerability was found in OpenSourcePOS 3.4.1 and classified as problematic. Affected is an unknown function of the component AJAX Handler. Executing a manipulation can lead to privilege escalation...
CVE-2025-70091 | OpenSourcePOS 3.4.1 Phone Number cross site scripting
13.02.2026 18:22
A vulnerability has been found in OpenSourcePOS 3.4.1 and classified as problematic. This impacts an unknown function. Performing a manipulation of the argument Phone Number results in cross site scri...
CVE-2026-2026 | Tenable Agent up to 11.0.3/11.1.1 on Windows default permission (Nessus ID 298991)
13.02.2026 18:22
A vulnerability, which was classified as critical, was found in Tenable Agent up to 11.0.3/11.1.1 on Windows. This affects an unknown function. Such manipulation leads to incorrect default permissions...
CVE-2025-70094 | OpenSourcePOS 3.4.1 Generate Item Barcode Category cross site scripting
13.02.2026 18:22
A vulnerability, which was classified as problematic, has been found in OpenSourcePOS 3.4.1. The impacted element is an unknown function of the component Generate Item Barcode. This manipulation of th...
CVE-2025-70123 | Free5GC 4.0.1/29.244 PFCP Session Establishment Request denial of service
13.02.2026 18:21
A vulnerability classified as problematic was found in Free5GC 4.0.1/29.244. The affected element is an unknown function of the component PFCP Session Establishment Request Handler. The manipulation r...
CVE-2025-70122 | Free5GC 4.0.1 UPF sdf-filter.go SDFFilterFields.UnmarshalBinary heap-based overflow
13.02.2026 18:21
A vulnerability classified as critical has been found in Free5GC 4.0.1. Impacted is the function SDFFilterFields.UnmarshalBinary of the file sdf-filter.go of the component UPF. The manipulation leads ...
CVE-2025-70121 | Free5GC 4.0.1 AMF NAS_MobileIdentity5GS.go GetSUCI denial of service
13.02.2026 18:21
A vulnerability described as problematic has been identified in Free5GC 4.0.1. This issue affects the function GetSUCI of the file NAS_MobileIdentity5GS.go of the component AMF Component. Executing a ...
CVE-2026-26221 | Hyland OnBase Workflow Timer Service up to 17.0.x Hyland.Core.Workflow.NTService.exe deserialization
13.02.2026 18:20
A vulnerability marked as very critical has been reported in Hyland OnBase Workflow Timer Service up to 17.0.x. This vulnerability affects unknown code of the file Hyland.Core.Workflow.NTService.exe. ...
CVE-2025-14608 | WP Last Modified Info Plugin up to 1.9.5 on WordPress bulk_save post_ids resource injection
13.02.2026 16:33
A vulnerability labeled as problematic has been found in WP Last Modified Info Plugin up to 1.9.5 on WordPress. This affects the function bulk_save. Such manipulation of the argument post_ids leads to...
CVE-2025-14067 | Easy Form Builder Plugin up to 3.9.3 on WordPress authorization
13.02.2026 16:33
A vulnerability identified as problematic has been detected in Easy Form Builder Plugin up to 3.9.3 on WordPress. Affected by this issue is some unknown functionality. This manipulation causes missing...
CVE-2025-13973 | StickEasy Protected Contact Form Plugin up to 1.0.1/1.0.2 on WordPress spcf-log.txt information disclosure
13.02.2026 16:33
A vulnerability categorized as problematic has been discovered in StickEasy Protected Contact Form Plugin up to 1.0.1/1.0.2 on WordPress. Affected by this vulnerability is an unknown functionality of ...
CVE-2025-13681 | BFG Tools Plugin up to 1.0.7 on WordPress /wp-content/plugins/ zip first_file path traversal
13.02.2026 16:32
A vulnerability was found in BFG Tools Plugin up to 1.0.7 on WordPress. It has been rated as critical. Affected is the function zip of the file /wp-content/plugins/. The manipulation of the argument f...
CVE-2026-2034 | Santesoft Sante DICOM Viewer Pro 14.2.0 DCM File Parser buffer overflow
13.02.2026 16:32
A vulnerability was found in Santesoft Sante DICOM Viewer Pro 14.2.0. It has been declared as critical. This impacts an unknown function of the component DCM File Parser. Executing a manipulation can ...
CVE-2026-2033 | MLflow Artifact path traversal
13.02.2026 16:32
A vulnerability was found in MLflow. It has been classified as critical. This affects an unknown function of the component Artifact Handler. Performing a manipulation results in path traversal. This ...
CVE-2026-1578 | HP App prior 26.0.0.6234 on Android cross site scripting
13.02.2026 16:31
A vulnerability was found in HP App on Android and classified as problematic. The impacted element is an unknown function. Such manipulation leads to cross site scripting. This vulnerability is uniqu...
CVE-2026-25531 | Kanboard up to 1.2.49 Incomplete Fix CVE-2023-33968 duplicateProjects authorization (GHSA-vrm3-3337-whp9)
13.02.2026 16:30
A vulnerability has been found in Kanboard up to 1.2.49 and classified as problematic. The affected element is the function TaskCreationController::duplicateProjects of the component Incomplete Fix CV...
CVE-2026-23111 | Linux Kernel up to 5.15.199/6.1.162/6.6.123/6.12.69/6.18.9 nf_tables nft_map_catchall_activate reference count (Nessus ID 299034)
13.02.2026 15:08
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.199/6.1.162/6.6.123/6.12.69/6.18.9. Impacted is the function nft_map_catchall_activate of the component nf_table...
CVE-2026-23112 | Linux Kernel up to 6.18.9 nvmet-tcp nvmet_tcp_build_pdu_iovec memory corruption
13.02.2026 15:08
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.9. This issue affects the function nvmet_tcp_build_pdu_iovec of the component nvmet-tcp. The manipulation l...
CVE-2026-1619 | Universal Software FlexCity/Kiosk up to 1.0.35 authorization
13.02.2026 15:07
A vulnerability classified as critical was found in Universal Software FlexCity and Kiosk up to 1.0.35. This vulnerability affects unknown code. Executing a manipulation can lead to authorization bypa...
CVE-2026-1618 | Universal Software FlexCity/Kiosk up to 1.0.35 authentication bypass
13.02.2026 15:06
A vulnerability classified as critical has been found in Universal Software FlexCity and Kiosk up to 1.0.35. This affects an unknown part. Performing a manipulation results in authentication bypass us...
CVE-2025-14349 | Universal Software FlexCity/Kiosk up to 1.0.35 privilege defined with unsafe actions
13.02.2026 15:06
A vulnerability described as very critical has been identified in Universal Software FlexCity and Kiosk up to 1.0.35. Affected by this issue is some unknown functionality. Such manipulation leads to p...
CVE-2026-1841 | PixelYourSite Plugin up to 11.2.0 on WordPress pys_landing_page pysTrafficSource cross site scripting
13.02.2026 13:27
A vulnerability marked as problematic has been reported in PixelYourSite Plugin up to 11.2.0 on WordPress. Affected by this vulnerability is the function pys_landing_page. This manipulation of the arg...
CVE-2026-1844 | PixelYourSite Pro Plugin up to 12.4.0.2 on WordPress pys_landing_page pysTrafficSource cross site scripting
13.02.2026 13:26
A vulnerability labeled as problematic has been found in PixelYourSite Pro Plugin up to 12.4.0.2 on WordPress. Affected is the function pys_landing_page. The manipulation of the argument pysTrafficSou...
CVE-2025-15157 | Starfish Review Generation & Marketing Plugin up to 3.1.19 on WordPress srm_restore_options_defaults improper authorization
13.02.2026 13:25
A vulnerability identified as critical has been detected in Starfish Review Generation & Marketing Plugin up to 3.1.19 on WordPress. This impacts the function srm_restore_options_defaults. The manipul...
CVE-2026-2443 | GNOME libsoup out-of-bounds (Nessus ID 299000)
13.02.2026 13:24
A vulnerability categorized as problematic has been discovered in GNOME libsoup. This affects an unknown function. Executing a manipulation can lead to out-of-bounds read. This vulnerability is track...
RSS Feed eintragen

Machen Sie Ihren RSS-Feed bekannt und erhöhen Sie die Sichtbarkeit Ihrer Website!

RSS-Feed eintragen
RSS-Reader
RSS-Reader finden Sie unter unsere Übersicht: RSS-Reader
Die neuesten Feeds
Die Top-Feeds
meist gelesenen Feeds