RSS Feeds > Computer & Technik > Internet > Marketing > scip AG [Security - Consulting - Information - Process] | RSS Verzeichnis

scip AG [Security - Consulting - Information - Process]


Anzeigen einer beliebigen Anzahl von Sicherheitsl?cken aus der scip AG Datenbank.

Betreiber-URL: https://www.scip.ch
RSS-Feed-URL: https://www.scip.ch/alertRSS.xml
Die neuesten Einträge aus dem RSS-Feed von scip AG [Security - Consulting - Information - Process]:
CVE-2026-9534 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWiFiWpsConfig PIN os command injection
25.05.2026 21:49
A vulnerability was found in Totolink CA750-PoE 6.2c.510. It has been declared as critical. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler...
CVE-2026-9533 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi recvUpgradeNewFw fwUrl/magicid os command injection
25.05.2026 21:49
A vulnerability was found in Totolink CA750-PoE 6.2c.510. It has been classified as critical. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Se...
CVE-2026-9532 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUploadUserData FileName os command injection
25.05.2026 21:49
A vulnerability was found in Totolink CA750-PoE 6.2c.510 and classified as critical. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Ha...
CVE-2026-9531 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUpgradeUboot FileName os command injection
25.05.2026 21:49
A vulnerability has been found in Totolink CA750-PoE 6.2c.510 and classified as critical. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Th...
CVE-2026-48842 | Roundcube Webmail up to 1.6.15/1.7.0 preg_replace sql injection
25.05.2026 21:47
A vulnerability, which was classified as critical, was found in Roundcube Webmail up to 1.6.15/1.7.0. This issue affects the function preg_replace. The manipulation results in sql injection. This vul...
CVE-2026-48847 | Roundcube Webmail up to 1.6.15/1.7.0 redis/memcache resource transfer
25.05.2026 21:47
A vulnerability, which was classified as problematic, has been found in Roundcube Webmail up to 1.6.15/1.7.0. This vulnerability affects unknown code of the component redis/memcache. The manipulation ...
CVE-2026-48843 | Roundcube Webmail up to 1.6.15/1.7.0 Mail Message server-side request forgery
25.05.2026 21:46
A vulnerability classified as critical was found in Roundcube Webmail up to 1.6.15/1.7.0. This affects an unknown part of the component Mail Message Handler. Executing a manipulation can lead to serve...
CVE-2026-48845 | Roundcube Webmail up to 1.6.15/1.7.0 Email Message resource transfer
25.05.2026 21:46
A vulnerability classified as critical has been found in Roundcube Webmail up to 1.6.15/1.7.0. Affected by this issue is some unknown functionality of the component Email Message Handler. Performing a...
CVE-2026-48848 | Roundcube Webmail up to 1.6.15/1.7.0 SVG Document attributeName cross site scripting
25.05.2026 21:46
A vulnerability described as problematic has been identified in Roundcube Webmail up to 1.6.15/1.7.0. Affected by this vulnerability is an unknown functionality of the component SVG Document Handler. ...
CVE-2026-48844 | Roundcube Webmail up to 1.6.15/1.7.0 LDAP control flow
25.05.2026 21:46
A vulnerability marked as problematic has been reported in Roundcube Webmail up to 1.6.15/1.7.0. Affected is an unknown function of the component LDAP. This manipulation causes incorrect control flow....
CVE-2026-24546 | Ruben Garcia GamiPress Plugin up to 7.6.3 on WordPress authorization
25.05.2026 21:46
A vulnerability labeled as problematic has been found in Ruben Garcia GamiPress Plugin up to 7.6.3 on WordPress. This impacts an unknown function. The manipulation results in missing authorization. T...
CVE-2026-48846 | Roundcube Webmail up to 1.6.15/1.7.0 CSS var resource transfer
25.05.2026 21:46
A vulnerability identified as critical has been detected in Roundcube Webmail up to 1.6.15/1.7.0. This affects the function var of the component CSS Handler. The manipulation leads to incorrect resour...
CVE-2026-9530 | GNU LibreDWG up to 0.14 Dwgbmp Utility src/decode.c read_2004_compressed_section out-of-bounds (Issue 1248)
25.05.2026 21:44
A vulnerability categorized as problematic has been discovered in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component D...
CVE-2026-9529 | GNU LibreDWG up to 0.14 Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference (Issue 1247)
25.05.2026 21:44
A vulnerability was found in GNU LibreDWG up to 0.14. It has been rated as problematic. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. ...
CVE-2026-9528 | itsourcecode Electronic Judging System 1.0 /admin/delete_judge.php judge_id sql injection
25.05.2026 21:36
A vulnerability was found in itsourcecode Electronic Judging System 1.0. It has been declared as critical. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the...
CVE-2026-9527 | itsourcecode Electronic Judging System 1.0 /admin/judges.php fname cross site scripting
25.05.2026 21:36
A vulnerability was found in itsourcecode Electronic Judging System 1.0. It has been classified as problematic. This issue affects some unknown processing of the file /admin/judges.php. This manipulat...
CVE-2026-9526 | itsourcecode Electronic Judging System 1.0 /admin/edit_team.php num_id sql injection
25.05.2026 21:36
A vulnerability was found in itsourcecode Electronic Judging System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the ar...
CVE-2026-9525 | itsourcecode Electronic Judging System 1.0 /admin/edit_judge.php judge_id sql injection
25.05.2026 21:36
A vulnerability has been found in itsourcecode Electronic Judging System 1.0 and classified as critical. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argumen...
CVE-2026-9524 | xianrendzw EasyReport up to 2.0.17.0522_Beta REST Endpoint execute reportParams sql injection
25.05.2026 21:33
A vulnerability, which was classified as critical, was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a...
CVE-2026-9523 | Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection
25.05.2026 21:29
A vulnerability, which was classified as critical, has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unk...
CVE-2026-9521 | fraillt bitsery up to 5.2.4 std_smart_ptr.h loadFromSharedState improper validation of specified type of input
25.05.2026 21:22
A vulnerability classified as critical was found in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation lead...
CVE-2026-9520 | blitz-js blitz up to 3.0.2 on GitHub Sign-in LoginForm.tsx Next cross site scripting
25.05.2026 21:17
A vulnerability classified as problematic has been found in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/...
CVE-2026-9519 | stonith404 pingvin-share up to 1.13.0 Sign-in Auto-Redirect signIn.tsx getServerSideProps redirect cross site scripting
25.05.2026 21:15
A vulnerability described as problematic has been identified in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of th...
CVE-2026-9518 | hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent Name cross site scripting
25.05.2026 21:13
A vulnerability marked as problematic has been reported in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the componen...
CVE-2026-9517 | hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
25.05.2026 21:13
A vulnerability labeled as critical has been found in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the ...
CVE-2026-27768 | Genetec Security Center prior 5.12.2.17/5.13.3.5 sql injection (EUVD-2026-31705)
25.05.2026 21:08
A vulnerability identified as critical has been detected in Genetec Security Center. Impacted is an unknown function. Performing a manipulation results in sql injection. This vulnerability is known a...
CVE-2018-25361 | Soroush IM Desktop App 0.17.0 authentication spoofing (Exploit 45171 / EUVD-2018-21883)
25.05.2026 17:40
A vulnerability categorized as critical has been discovered in Soroush IM Desktop App 0.17.0. This issue affects some unknown processing. Such manipulation leads to authentication bypass by spoofing. ...
CVE-2026-47076 | benoitc hackney up to 4.0.0 interpretation conflict (GHSA-pj7v-xfvx-wmjq / EUVD-2026-31689)
25.05.2026 17:40
A vulnerability was found in benoitc hackney up to 4.0.0. It has been rated as problematic. This vulnerability affects unknown code. This manipulation causes interpretation conflict. This vulnerabili...
CVE-2026-42797 | Apache Syncope up to 3.0.16/4.0.5/4.1.0 JEXL information exposure (EUVD-2026-31702)
25.05.2026 17:40
A vulnerability was found in Apache Syncope up to 3.0.16/4.0.5/4.1.0. It has been declared as problematic. This affects an unknown part of the component JEXL Handler. The manipulation results in expos...
CVE-2026-42782 | Apache Syncope up to 3.0.16/4.0.5/4.1.0 Groovy Code improper isolation or compartmentalization (EUVD-2026-31696)
25.05.2026 17:40
A vulnerability was found in Apache Syncope up to 3.0.16/4.0.5/4.1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Groovy Code Handler. ...
CVE-2026-9078 | Mozilla Firefox up to 151.0 on iOS RTL ui layer (EUVD-2026-31693)
25.05.2026 17:39
A vulnerability was found in Mozilla Firefox up to 151.0 on iOS and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RTL Handler. Executing a mani...
CVE-2018-25378 | Stokedonit Notebook Pro 2.0 memory allocation (Exploit 45420 / EUVD-2018-21898)
25.05.2026 17:38
A vulnerability has been found in Stokedonit Notebook Pro 2.0 and classified as problematic. Affected is an unknown function. Performing a manipulation results in uncontrolled memory allocation. This...
CVE-2018-25376 | SocuSoft 3GP Photo Slideshow 8.05 buffer overflow (Exploit 45352 / EUVD-2018-21900)
25.05.2026 17:38
A vulnerability, which was classified as critical, was found in SocuSoft 3GP Photo Slideshow 8.05. This impacts an unknown function. Such manipulation leads to buffer overflow. This vulnerability is ...
CVE-2018-25375 | SocuSoft iPod Photo Slideshow 8.05 stack-based overflow (Exploit 45350 / EUVD-2018-21896)
25.05.2026 17:33
A vulnerability, which was classified as critical, has been found in SocuSoft iPod Photo Slideshow 8.05. This affects an unknown function. This manipulation causes stack-based buffer overflow. This v...
CVE-2018-25377 | SocuSoft Flash Slideshow Maker Professional 5.20 buffer overflow (Exploit 45355 / EUVD-2018-21899)
25.05.2026 17:33
A vulnerability classified as critical was found in SocuSoft Flash Slideshow Maker Professional 5.20. The impacted element is an unknown function. The manipulation results in buffer overflow. This vu...
CVE-2018-25371 | Moosocial mooSocial Store Plugin 2.6 Product sql injection (Exploit 45330 / EUVD-2018-21892)
25.05.2026 17:32
A vulnerability classified as critical has been found in Moosocial mooSocial Store Plugin 2.6. The affected element is an unknown function. The manipulation of the argument Product leads to sql inject...
CVE-2018-25369 | scanwith Visual Ping 0.8.0.0 buffer overflow (Exploit 45316 / EUVD-2018-21890)
25.05.2026 17:32
A vulnerability described as critical has been identified in scanwith Visual Ping 0.8.0.0. Impacted is an unknown function. Executing a manipulation can lead to buffer overflow. The identification of...
CVE-2018-25367 | NASA openVSP 3.16.1 buffer overflow (Exploit 45281 / EUVD-2018-21888)
25.05.2026 17:32
A vulnerability marked as critical has been reported in NASA openVSP 3.16.1. This issue affects some unknown processing. Performing a manipulation results in buffer overflow. This vulnerability was n...
CVE-2018-25373 | SocuSoft DVD Photo Slideshow Professional 8.07 stack-based overflow (Exploit 45346 / EUVD-2018-21894)
25.05.2026 17:30
A vulnerability labeled as critical has been found in SocuSoft DVD Photo Slideshow Professional 8.07. This vulnerability affects unknown code. Such manipulation leads to stack-based buffer overflow. ...
CVE-2026-47072 | benoitc hackney up to 4.0.0 URL src/hackney_ws.erl crlf injection (EUVD-2026-31690)
25.05.2026 17:30
A vulnerability identified as problematic has been detected in benoitc hackney up to 4.0.0. This affects an unknown part of the file src/hackney_ws.erl of the component URL Handler. This manipulation ...
CVE-2026-47070 | benoitc hackney up to 4.0.0 src/hackney_h3.erl redirect (EUVD-2026-31692)
25.05.2026 17:30
A vulnerability categorized as problematic has been discovered in benoitc hackney up to 4.0.0. Affected by this issue is some unknown functionality of the file src/hackney_h3.erl. The manipulation res...
CVE-2026-47069 | benoitc hackney up to 4.0.0 HTTP Response src/hackney_cookie.erl crlf injection
25.05.2026 17:30
A vulnerability was found in benoitc hackney up to 4.0.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the file src/hackney_cookie.erl of the compone...
CVE-2026-47066 | benoitc hackney up to 4.0.0 Alt-Svc Response Header Parser src/hackney_altsvc.erl infinite loop
25.05.2026 17:29
A vulnerability was found in benoitc hackney up to 4.0.0. It has been declared as problematic. Affected is an unknown function of the file src/hackney_altsvc.erl of the component Alt-Svc Response Head...
CVE-2018-25379 | Ourenergy Collectric CMU 1.0 login lang sql injection (Exploit 45446 / EUVD-2018-21902)
25.05.2026 17:29
A vulnerability was found in Ourenergy Collectric CMU 1.0. It has been classified as critical. This impacts the function Login. Performing a manipulation of the argument lang results in sql injection....
CVE-2026-47075 | benoitc hackney up to 4.0.0 URL Query crlf injection (EUVD-2026-31687)
25.05.2026 17:29
A vulnerability was found in benoitc hackney up to 4.0.0 and classified as problematic. This affects an unknown function of the component URL Query. Such manipulation leads to crlf injection. This vu...
CVE-2026-47071 | benoitc hackney up to 4.0.0 src/hackney_socks5.erl Timeout resource consumption
25.05.2026 17:29
A vulnerability has been found in benoitc hackney up to 4.0.0 and classified as problematic. The impacted element is an unknown function of the file src/hackney_socks5.erl. This manipulation of the ar...
CVE-2026-9515 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUnloadUserData plugin_version os command injection
25.05.2026 17:14
A vulnerability, which was classified as critical, was found in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Se...
CVE-2026-9514 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setNetworkDiag os command injection
25.05.2026 17:14
A vulnerability, which was classified as critical, has been found in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Hand...
CVE-2026-9513 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi NTPSyncWithHost host_time os command injection
25.05.2026 17:14
A vulnerability classified as critical was found in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Exec...
CVE-2026-9512 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setPasswordCfg admuser/admpass os command injection
25.05.2026 17:14
A vulnerability classified as critical has been found in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting H...
CVE-2026-9511 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWebWlanIdx webWlanIdx os command injection
25.05.2026 17:14
A vulnerability described as critical has been identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Suc...
CVE-2018-25381 | Extro Responsive Portfolio 1.6.1 on Joomla POST Request filter_type_id/filter_pid_id/filter_search sql injection (Exploit 45491 / EUVD-2018-21903)
25.05.2026 17:13
A vulnerability marked as critical has been reported in Extro Responsive Portfolio 1.6.1 on Joomla. Affected by this issue is some unknown functionality of the component POST Request Handler. This man...
CVE-2026-47077 | benoitc hackney up to 4.0.0 Housekeeping Message resource consumption (EUVD-2026-31688)
25.05.2026 17:13
A vulnerability labeled as problematic has been found in benoitc hackney up to 4.0.0. Affected by this vulnerability is an unknown functionality of the component Housekeeping Message Handler. The mani...
CVE-2026-47073 | benoitc hackney up to 4.0.0 src/hackney_ws.erl frag_buffer resource consumption (EUVD-2026-31694)
25.05.2026 17:12
A vulnerability identified as problematic has been detected in benoitc hackney up to 4.0.0. Affected is an unknown function of the file src/hackney_ws.erl. The manipulation of the argument frag_buffer...
CVE-2026-47067 | benoitc hackney up to 4.0.0 URL Parser src/hackney_url.erl allocation of resources (EUVD-2026-31691)
25.05.2026 17:12
A vulnerability categorized as problematic has been discovered in benoitc hackney up to 4.0.0. This impacts an unknown function of the file src/hackney_url.erl of the component URL Parser. Executing a...
CVE-2018-25380 | Extro eXtroForms 2.1.5 on Joomla filter_type_id/filter_pid_id/filter_search sql injection (Exploit 45472 / EUVD-2018-21901)
25.05.2026 17:12
A vulnerability was found in Extro eXtroForms 2.1.5 on Joomla. It has been rated as critical. This affects an unknown function. Performing a manipulation of the argument filter_type_id/filter_pid_id/f...
CVE-2018-25370 | Admidio 3.3.5 roles_function.php rol_assign_roles/rol_approve_users/rol_edit_user cross-site request forgery (Exploit 45322 / EUVD-2018-21893)
25.05.2026 17:12
A vulnerability was found in Admidio 3.3.5. It has been declared as problematic. The impacted element is an unknown function of the file roles_function.php. Such manipulation of the argument rol_assig...
CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 nocache.php path path traversal (Exploit 45347 / EUVD-2018-21897)
25.05.2026 17:12
A vulnerability was found in Softneta MedDream PACS Server Premium 6.7.1.1. It has been classified as critical. The affected element is an unknown function of the file nocache.php. This manipulation o...
CVE-2018-25372 | Softneta MedDream PACS Server Premium 6.7.1.1 POST userSignup.php email sql injection (Exploit 45344 / EUVD-2018-21895)
25.05.2026 17:12
A vulnerability was found in Softneta MedDream PACS Server Premium 6.7.1.1 and classified as critical. Impacted is an unknown function of the file userSignup.php of the component POST Handler. The man...
CVE-2018-25368 | NordVPN up to 6.14.31 Password memory allocation (Exploit 45304 / EUVD-2018-21891)
25.05.2026 17:10
A vulnerability has been found in NordVPN up to 6.14.31 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument Password leads to uncontrolled memor...
CVE-2018-25359 | Splinterware System Scheduler Pro 5.12 WService.exe default permission (Exploit 45072 / EUVD-2018-21881)
25.05.2026 17:10
A vulnerability, which was classified as critical, was found in Splinterware System Scheduler Pro 5.12. This vulnerability affects unknown code of the file WService.exe. Executing a manipulation can l...
CVE-2018-25366 | Globalscape CuteFTP 5.0.4 buffer overflow (Exploit 45259 / EUVD-2018-21889)
25.05.2026 17:10
A vulnerability, which was classified as critical, has been found in Globalscape CuteFTP 5.0.4. This affects an unknown part. Performing a manipulation results in buffer overflow. This vulnerability ...
CVE-2018-25360 | Agatasoft Auto PingMaster 1.5 stack-based overflow (Exploit 45151 / EUVD-2018-21884)
25.05.2026 17:09
A vulnerability classified as critical was found in Agatasoft Auto PingMaster 1.5. Affected by this issue is some unknown functionality. Such manipulation leads to stack-based buffer overflow. This v...
CVE-2018-25365 | Softpedia PCViewer t1000 path traversal (Exploit 45248 / EUVD-2018-21885)
25.05.2026 17:07
A vulnerability classified as critical has been found in Softpedia PCViewer t1000. Affected by this vulnerability is an unknown functionality. This manipulation causes path traversal. This vulnerabil...
CVE-2018-25363 | Fyffe PHP-Twitter-Clone 1.0 tweetdel.php cross-site request forgery (Exploit 45232 / EUVD-2018-21887)
25.05.2026 17:07
A vulnerability described as problematic has been identified in Fyffe PHP-Twitter-Clone 1.0. Affected is an unknown function of the file tweetdel.php. The manipulation results in cross-site request fo...
CVE-2018-25364 | Fyffe PHP-Twitter-Clone 1.0 search.php Name sql injection (Exploit 45247 / EUVD-2018-21886)
25.05.2026 17:07
A vulnerability marked as critical has been reported in Fyffe PHP-Twitter-Clone 1.0. This impacts an unknown function of the file search.php. The manipulation of the argument Name leads to sql injecti...
CVE-2018-25362 | Fyffe PHP-Twitter-Clone 1.0 follow.php userid sql injection (Exploit 45230 / EUVD-2018-21882)
25.05.2026 17:02
A vulnerability labeled as critical has been found in Fyffe PHP-Twitter-Clone 1.0. This affects an unknown function of the file follow.php. Executing a manipulation of the argument userid can lead to ...
CVE-2026-9058 | Krajowa Izba Rozliczeniowa Szafir SDK up to 462 Certificate Chain unnecessary complexity in protection mechanism
25.05.2026 16:05
A vulnerability identified as critical has been detected in Krajowa Izba Rozliczeniowa Szafir SDK up to 462. The impacted element is an unknown function of the component Certificate Chain Handler. Per...
CVE-2026-7766 | Kenik KG-5260xxxx-IL- 2 prior 2025-04-21 path traversal (EUVD-2026-31672)
25.05.2026 14:49
A vulnerability categorized as critical has been discovered in Kenik KG-5230TAS-IL-3, KG-5230TAS-IL-G3, KG-5230DAS-IL-G3, KG-5260TZAS-IL-3, KG-5260DZAS-IL-3, KG-5260TZAS-IL-G3, KG-5260DZAS-IL-G3 and K...
CVE-2026-40127 | OutSystems Lifetime prior 11.28.2.3955 authorization (EUVD-2026-31662)
25.05.2026 14:25
A vulnerability was found in OutSystems Lifetime. It has been rated as problematic. Impacted is an unknown function. This manipulation causes authorization bypass. This vulnerability is handled as CV...
CVE-2026-46745 | Apache Airflow FAB provider up to 3.6.3 ldap injection (EUVD-2026-31669)
25.05.2026 14:25
A vulnerability was found in Apache Airflow FAB provider up to 3.6.3. It has been declared as critical. This issue affects some unknown processing. The manipulation results in ldap injection. This vu...
CVE-2026-9274 | CP Plus CP-E38Q UART Interface cleartext storage (CIVN-2026-0266 / EUVD-2026-31661)
25.05.2026 12:13
A vulnerability was found in CP Plus CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q and CP-Z45Q. It has ...
CVE-2026-5222 | rust-lang Cargo up to 1.95.x non-canonical url paths for authorization decisions (EUVD-2026-31654)
25.05.2026 12:13
A vulnerability was found in rust-lang Cargo up to 1.95.x and classified as problematic. This affects an unknown part. Executing a manipulation can lead to use of non-canonical url paths for authoriza...
CVE-2026-5223 | rust-lang Cargo up to 1.95.x symlink (EUVD-2026-31658)
25.05.2026 12:12
A vulnerability has been found in rust-lang Cargo up to 1.95.x and classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in symlink following....
CVE-2026-45361 | Apache Airflow Google Provider up to 21.x SSH Host-Key Verification key exchange without entity authentication (EUVD-2026-31659)
25.05.2026 12:12
A vulnerability, which was classified as problematic, was found in Apache Airflow Google Provider up to 21.x. Affected by this vulnerability is an unknown functionality of the component SSH Host-Key V...
CVE-2026-9504 | GNU LibreDWG up to 0.14 Dwggrep Utility programs/dwggrep.c bit_convert_TU out-of-bounds (Issue 1246)
25.05.2026 12:10
A vulnerability, which was classified as problematic, has been found in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/dwggrep.c of the component Dwggrep Utility...
CVE-2026-9503 | GNU LibreDWG up to 0.14 DWG File src/decode.c dwg_next_entity null pointer dereference (Issue 1245)
25.05.2026 12:10
A vulnerability classified as problematic was found in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation r...
CVE-2026-9502 | GNU LibreDWG up to 0.14 Dwgread Utility src/decode.c decompress_R2004_section heap-based overflow (Issue 1243)
25.05.2026 12:09
A vulnerability classified as critical has been found in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The mani...
CVE-2026-9501 | GNU LibreDWG up to 0.14 Dwgread Utility src/decode.c decompress_R2004_section assertion (Issue 1242)
25.05.2026 12:09
A vulnerability described as problematic has been identified in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread...
CVE-2026-9500 | GNU LibreDWG up to 0.14 Dwgread Utility src/decode.c read_2004_compressed_section heap-based overflow (Issue 1241)
25.05.2026 12:09
A vulnerability marked as critical has been reported in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Uti...
CVE-2026-9498 | Dromara lamp-cloud up to 5.6.2 Message Template GroovyClassLoader.parseClass DefMsgTemplate.content special elements used in a template engine
25.05.2026 11:58
A vulnerability labeled as critical has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation...
CVE-2026-9497 | changmingxie tcc-transaction up to 2.1.0 Fastjson AutoType REST API Fastjson.parseObject deserialization
25.05.2026 11:42
A vulnerability identified as critical has been detected in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. ...
CVE-2026-9490 | Acer Care Center up to 4.00.3058 ACCSvc Service privileges management (EUVD-2026-31648)
25.05.2026 11:36
A vulnerability categorized as critical has been discovered in Acer Care Center up to 4.00.3058. This vulnerability affects unknown code of the component ACCSvc Service. The manipulation results in im...
CVE-2026-45249 | Apache ECharts up to 6.0.x Lines Series Tooltip Rendering cross site scripting (EUVD-2026-31650)
25.05.2026 11:35
A vulnerability was found in Apache ECharts up to 6.0.x. It has been rated as problematic. This affects an unknown part of the component Lines Series Tooltip Rendering. The manipulation leads to cross...
CVE-2026-4915 | Mattermost up to 10.11.14/11.4.4/11.5.3/11.6.0 Webhook Attachment unusual condition (EUVD-2026-31646)
25.05.2026 11:24
A vulnerability was found in Mattermost up to 10.11.14/11.4.4/11.5.3/11.6.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Webhook Attachme...
CVE-2026-41863 | Vmware Spring AI up to 1.1.6 Anthropic Skills API Path.resolve path traversal (EUVD-2026-31638)
25.05.2026 11:23
A vulnerability was found in Vmware Spring AI up to 1.1.6. It has been classified as critical. Affected by this vulnerability is the function Path.resolve of the component Anthropic Skills API Handler...
CVE-2026-25193 | Gallagher Command Centre Server log file (EUVD-2026-31636)
25.05.2026 11:23
A vulnerability was found in Gallagher Command Centre Server, Active Directory Sync, Cardholder Sync Utility, Diagnostics Service, Elevator Service, Encoding Kiosk Application, Entra ID Sync, Event Sy...
CVE-2026-2651 | MLflow up to 3.9.x Multipart Upload /mlflow-artifacts/mpu/ authorization (EUVD-2026-31642)
25.05.2026 09:28
A vulnerability has been found in MLflow up to 3.9.x and classified as critical. This impacts an unknown function of the file /mlflow-artifacts/mpu/ of the component Multipart Upload Handler. This man...
CVE-2026-6059 | NEC Platforms Aterm WX1800HP Web Management Interface cross site scripting (EUVD-2026-31623)
25.05.2026 05:44
A vulnerability, which was classified as problematic, was found in NEC Platforms Aterm WX1800HP, Aterm WX5400HP, Aterm WX7800T8, Aterm WX11000T12, Aterm WX3000HP2, Aterm WX4200D5, Aterm GX621A1, Aterm...
CVE-2026-8652 | NEC Platforms Aterm MR51FN/Aterm CM51FD os command injection (EUVD-2026-31620)
25.05.2026 05:43
A vulnerability, which was classified as critical, has been found in NEC Platforms Aterm MR51FN and Aterm CM51FD. The impacted element is an unknown function. The manipulation leads to os command inje...
CVE-2026-9489 | Acer NitrorSense up to 3.01.3052 path traversal (EUVD-2026-31619)
25.05.2026 05:42
A vulnerability classified as critical was found in Acer NitrorSense up to 3.01.3052. The affected element is an unknown function. Executing a manipulation can lead to path traversal. This vulnerabil...
CVE-2026-48832 | SPIP up to 4.4.14 ecrire action/cookie.php redirect (EUVD-2026-31601)
25.05.2026 05:42
A vulnerability classified as problematic has been found in SPIP up to 4.4.14. Impacted is an unknown function of the file action/cookie.php of the component ecrire. Performing a manipulation results ...
CVE-2026-48831 | WineHQ Wine up to 11.0 MIME resource transfer (EUVD-2026-31599)
25.05.2026 05:42
A vulnerability described as critical has been identified in WineHQ Wine up to 11.0. This issue affects some unknown processing of the component MIME Handler. Such manipulation leads to incorrect reso...
CVE-2026-4372 | huggingface transformers up to 5.2.x config.json AutoModelForCausalLM.from_pretrained _attn_implementation_internal missing serialization control element (EUVD-2026-31598)
25.05.2026 05:42
A vulnerability marked as problematic has been reported in huggingface transformers up to 5.2.x. This vulnerability affects the function AutoModelForCausalLM.from_pretrained of the file config.json. T...
CVE-2026-9486 | SourceCodester Student Grades Management System 1.0 cross-site request forgery
24.05.2026 11:31
A vulnerability labeled as problematic has been found in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. Thi...
CVE-2026-9485 | SourceCodester Student Grades Management System 1.0 students.php Remarks cross site scripting
24.05.2026 11:31
A vulnerability identified as problematic has been detected in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The m...
CVE-2026-9484 | SourceCodester Student Grades Management System 1.0 classroom.php getClassroomStudents/removeStudentFromClassroom classroom_id improper authorization
24.05.2026 11:31
A vulnerability categorized as critical has been discovered in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFro...
CVE-2026-9483 | SourceCodester Student Grades Management System 1.0 grades.php student_id improper authorization
24.05.2026 11:31
A vulnerability was found in SourceCodester Student Grades Management System 1.0. It has been rated as critical. Affected is an unknown function of the file grades.php. Performing a manipulation of th...
CVE-2026-9482 | Edimax EW-7438RPn 1.31 /goform/formSDHCP submit-url stack-based overflow
24.05.2026 11:23
A vulnerability was found in Edimax EW-7438RPn 1.31. It has been declared as critical. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url l...
CVE-2026-9481 | Edimax EW-7438RPn 1.31 /goform/formStats submit-url stack-based overflow
24.05.2026 11:23
A vulnerability was found in Edimax EW-7438RPn 1.31. It has been classified as critical. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url...
RSS Feed eintragen

Machen Sie Ihren RSS-Feed bekannt und erhöhen Sie die Sichtbarkeit Ihrer Website!

RSS-Feed eintragen
RSS-Reader
RSS-Reader finden Sie unter unsere Übersicht: RSS-Reader
Die neuesten Feeds
Die Top-Feeds
meist gelesenen Feeds