RSS Feeds > Computer & Technik > Internet > Marketing > scip AG [Security - Consulting - Information - Process] | RSS Verzeichnis

scip AG [Security - Consulting - Information - Process]


Anzeigen einer beliebigen Anzahl von Sicherheitsl?cken aus der scip AG Datenbank.

Betreiber-URL: https://www.scip.ch
RSS-Feed-URL: https://www.scip.ch/alertRSS.xml
Die neuesten Einträge aus dem RSS-Feed von scip AG [Security - Consulting - Information - Process]:
CVE-2026-51667 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi getWiFiIpMacTable access control
31.08.2026 15:15
A vulnerability, which was classified as problematic, was found in TOTOLINK T6 4.1.5cu.748. Affected is the function getWiFiIpMacTable of the file /cgi-bin/cstecgi.cgi. The manipulation results in imp...
CVE-2026-51666 | TOTOLINK T6 4.1.5cu.748 Wizard Configuration /cgi-bin/cstecgi.cgi setWizardCfg access control
31.08.2026 15:15
A vulnerability, which was classified as very critical, has been found in TOTOLINK T6 4.1.5cu.748. This impacts the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component Wizard Confi...
CVE-2026-5956 | Ankara Hosting Site Management Panel up to 15062026 sql injection
31.08.2026 14:59
A vulnerability classified as critical was found in Ankara Hosting Site Management Panel up to 15062026. This affects an unknown function. Executing a manipulation can lead to sql injection. This vul...
CVE-2026-82957 | hyperledger-firefly up to 1.4.0 Webhook Subscription webhooks.go ValidateOptions url server-side request forgery
31.08.2026 14:48
A vulnerability classified as critical has been found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go ...
CVE-2026-74010 | John James Jacoby bbPress Plugin up to 2.6.14 on WordPress authorization
31.08.2026 14:44
A vulnerability described as problematic has been identified in John James Jacoby bbPress Plugin up to 2.6.14 on WordPress. The affected element is an unknown function. Such manipulation leads to miss...
CVE-2026-12894 | Red Hat Apache Camel ReflectionValueResolver privileges management
31.08.2026 14:44
A vulnerability marked as critical has been reported in Red Hat Apache Camel, JBoss Enterprise Application Platform Expansion Pack and Quarkus. Impacted is an unknown function of the component Reflect...
CVE-2026-82954 | Dokploy up to 0.29.7 Settings application.ts writeTraefikConfigInPath path path traversal
31.08.2026 14:32
A vulnerability labeled as very critical has been found in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts o...
CVE-2026-82922 | ShopEx ECShop up to 2.5.1 flow.php?step=update_cart flow_update_cart rec_id sql injection
31.08.2026 13:39
A vulnerability identified as critical has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation...
CVE-2026-82921 | ShopEx ECShop up to 2.5.1 admin/pack.php check_img_type pack_img unrestricted upload
31.08.2026 13:39
A vulnerability categorized as critical has been discovered in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument ...
CVE-2026-82797 | Samsung rlottie recursion (EUVD-2026-68482)
31.08.2026 13:36
A vulnerability was found in Samsung rlottie. It has been rated as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in uncontrolled recursion. This...
CVE-2026-82919 | cu silicon up to 0.1.5 edit Endpoint views.py create_app missing authentication
31.08.2026 13:21
A vulnerability was found in cu silicon up to 0.1.5. It has been declared as critical. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Su...
CVE-2026-82881 | apconw Aix-DB up to 1.2.4 cross site scripting
31.08.2026 13:08
A vulnerability was found in apconw Aix-DB up to 1.2.4. It has been classified as problematic. Affected is an unknown function. This manipulation causes cross site scripting. This vulnerability is tr...
CVE-2026-82880 | YaCy Search Server up to 1.941 SVG Parser/FreeMind Parser/OpenSearch Parser xml external entity reference
31.08.2026 13:08
A vulnerability was found in YaCy Search Server up to 1.941 and classified as critical. This impacts an unknown function of the component SVG Parser/FreeMind Parser/OpenSearch Parser. The manipulation...
CVE-2026-82879 | DataEase up to 2.10.25 Sharing Link /de2api/share/proxyInfo access control
31.08.2026 13:07
A vulnerability has been found in DataEase up to 2.10.25 and classified as critical. This affects an unknown function of the file /de2api/share/proxyInfo of the component Sharing Link Module. The mani...
CVE-2026-82877 | ILIAS up to 9.21/10.9/11.2 SOAP Import addFile path traversal
31.08.2026 13:07
A vulnerability, which was classified as problematic, was found in ILIAS up to 9.21/10.9/11.2. The impacted element is the function addFile of the component SOAP Import. Executing a manipulation can l...
CVE-2026-82876 | Phison Electronics PS3111-S11 Controller SBFQT1.3 improper authentication
31.08.2026 13:06
A vulnerability, which was classified as problematic, has been found in Phison Electronics PS3111-S11 Controller SBFQT1.3. The affected element is an unknown function. Performing a manipulation result...
CVE-2026-82878 | DataEase up to 2.10.25 REST Endpoint improper authorization
31.08.2026 13:06
A vulnerability classified as critical was found in DataEase up to 2.10.25. Impacted is an unknown function of the component REST Endpoint. Such manipulation leads to improper authorization. This vul...
CVE-2026-54877 | oFono cbs_assembly_expire double free
31.08.2026 12:45
A vulnerability classified as very critical has been found in oFono. This issue affects the function cbs_assembly_expire. This manipulation causes double free. This vulnerability is handled as CVE-20...
CVE-2026-82914 | kishan0725 Hospital-Management-System 1.0 /search.php Contact sql injection
31.08.2026 12:33
A vulnerability described as critical has been identified in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argumen...
CVE-2026-19873 | HTML::FormFu up to 2.08 Repeatable process resource consumption
31.08.2026 12:21
A vulnerability marked as problematic has been reported in HTML::FormFu up to 2.08. This affects the function process of the component Repeatable. The manipulation leads to resource consumption. This...
CVE-2026-82909 | QuantumNous new-api up to 1.0.0-rc.15 Revoked API Token /api/usage/token/ session expiration
31.08.2026 12:16
A vulnerability labeled as problematic has been found in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revo...
CVE-2026-82908 | MSI Dragon Center up to 2.0.155.0 MMIO Write Path NTIOLib_X64.sys MmioWritePath count/elementSize integer overflow
31.08.2026 12:16
A vulnerability identified as critical has been detected in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the compon...
CVE-2026-49003 | ZTE ZXDU68 S202 Monitoring command injection (EUVD-2026-68455)
31.08.2026 12:04
A vulnerability categorized as very critical has been discovered in ZTE ZXDU68 S202. Affected is an unknown function of the component Monitoring Module. Such manipulation leads to command injection. ...
CVE-2026-82906 | sdcb chats up to 1.12.0 Signed File Download Endpoint FileController.cs DownloadPublic missing authentication
31.08.2026 11:51
A vulnerability was found in sdcb chats up to 1.12.0. It has been rated as problematic. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the...
CVE-2026-82905 | sdcb chats up to 1.12.0 fetch-tools Endpoint McpController.cs McpController server-side request forgery
31.08.2026 11:51
A vulnerability was found in sdcb chats up to 1.12.0. It has been declared as critical. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the co...
CVE-2026-82868 | pdfme up to 5.5.8 SVG schema plugin cross site scripting (EUVD-2026-68403)
31.08.2026 11:35
A vulnerability was found in pdfme up to 5.5.8. It has been classified as problematic. The impacted element is an unknown function of the component SVG schema plugin. The manipulation leads to cross s...
CVE-2026-82867 | pdfme schemas up to 5.5.8 Select schema plugin cross site scripting (EUVD-2026-68402)
31.08.2026 11:35
A vulnerability was found in pdfme schemas up to 5.5.8 and classified as problematic. The affected element is an unknown function of the component Select schema plugin. Executing a manipulation can le...
CVE-2026-82865 | pdfme up to 5.5.9 multiVariableText property panel labels cross site scripting
31.08.2026 11:34
A vulnerability has been found in pdfme up to 5.5.9 and classified as problematic. Impacted is an unknown function of the component multiVariableText property panel. Performing a manipulation of the a...
CVE-2026-82866 | pdfme up to 5.5.9 common getB64BasePdf basePdf server-side request forgery
31.08.2026 11:33
A vulnerability, which was classified as problematic, was found in pdfme up to 5.5.9. This issue affects the function getB64BasePdf of the component common. Such manipulation of the argument basePdf l...
CVE-2026-82874 | ToolJet up to 3.16.207 Organization Validation organizationId privileges management (EUVD-2026-68409)
31.08.2026 11:32
A vulnerability, which was classified as critical, has been found in ToolJet up to 3.16.207. This vulnerability affects unknown code of the component Organization Validation. This manipulation of the ...
CVE-2026-82873 | ToolJet up to 3.0.0-ee-beta.2 Export Endpoint /api/v2/resources/export organization_id authorization (EUVD-2026-68408)
31.08.2026 11:32
A vulnerability classified as critical was found in ToolJet up to 3.0.0-ee-beta.2. This affects an unknown part of the file /api/v2/resources/export of the component Export Endpoint. The manipulation ...
CVE-2026-82875 | ToolJet up to 3.16.207 Controller organizationId authorization (EUVD-2026-68410)
31.08.2026 11:31
A vulnerability classified as critical has been found in ToolJet up to 3.16.207. Affected by this issue is some unknown functionality of the component Controller. The manipulation of the argument orga...
CVE-2026-82871 | ToolJet up to 3.16.207 Database Read Routes privileges management (EUVD-2026-68406)
31.08.2026 11:30
A vulnerability described as problematic has been identified in ToolJet up to 3.16.207. Affected by this vulnerability is an unknown functionality of the component Database Read Routes. Executing a ma...
CVE-2026-82870 | ToolJet up to 3.16.207 Database Write/Destroy Routes organizationId privileges management (EUVD-2026-68405)
31.08.2026 11:30
A vulnerability marked as problematic has been reported in ToolJet up to 3.16.207. Affected is an unknown function of the component Database Write/Destroy Routes. Performing a manipulation of the argu...
CVE-2026-82869 | ToolJet Database up to 3.16.43 Join Tables Endpoint privileges management (EUVD-2026-68404)
31.08.2026 11:29
A vulnerability labeled as problematic has been found in ToolJet Database up to 3.16.43. This impacts an unknown function of the component Join Tables Endpoint. Such manipulation leads to improper pri...
CVE-2026-82872 | ToolJet up to 3.16.207 Table Management organizationId access control (EUVD-2026-68407)
31.08.2026 11:28
A vulnerability identified as problematic has been detected in ToolJet up to 3.16.207. This affects an unknown function of the component Table Management. This manipulation of the argument organizatio...
CVE-2026-19410 | Google Cloud Cloud Build Trigger Comment Control improper authorization
31.08.2026 11:28
A vulnerability categorized as critical has been discovered in Google Cloud Cloud Build. The impacted element is an unknown function of the component Trigger Comment Control. The manipulation results ...
CVE-2026-82659 | Nodemailer up to 9.0.0 Raw Option path/href server-side request forgery
31.08.2026 11:27
A vulnerability was found in Nodemailer up to 9.0.0. It has been rated as critical. The affected element is an unknown function of the component Raw Option Handler. The manipulation of the argument pa...
CVE-2026-82862 | kerberosmansour Hulumi up to 1.3.1 Helper Script path traversal
31.08.2026 11:27
A vulnerability was found in kerberosmansour Hulumi up to 1.3.1. It has been declared as problematic. Impacted is an unknown function of the component Helper Script. Executing a manipulation can lead ...
CVE-2026-82660 | Nodemailer up to 8.0.8 jsonTransport path/href access control
31.08.2026 11:26
A vulnerability was found in Nodemailer up to 8.0.8. It has been classified as critical. This issue affects some unknown processing of the component jsonTransport. Performing a manipulation of the arg...
CVE-2026-82864 | pdfme pdf-lib up to 5.5.9 DecodeStream DecodeStream.ensureBuffer denial of service
31.08.2026 11:26
A vulnerability was found in pdfme pdf-lib up to 5.5.9 and classified as problematic. This vulnerability affects the function DecodeStream.ensureBuffer of the component DecodeStream. Such manipulation...
CVE-2026-82863 | hulumi up to 1.3.1 baseline insufficient logging
31.08.2026 11:25
A vulnerability has been found in hulumi up to 1.3.1 and classified as problematic. This affects an unknown part of the component baseline. This manipulation causes insufficient logging. This vulnera...
CVE-2026-82860 | kerberosmansour hulumi up to 1.3.1 policies privileges management
31.08.2026 11:25
A vulnerability, which was classified as critical, was found in kerberosmansour hulumi up to 1.3.1. Affected by this issue is some unknown functionality of the component policies. The manipulation res...
CVE-2026-82859 | kerberosmansour Hulumi up to 1.3.1 privileges management
31.08.2026 11:24
A vulnerability, which was classified as critical, has been found in kerberosmansour Hulumi up to 1.3.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper ...
CVE-2026-82854 | Nodemailer up to 8.0.3 Envelope Size sendMail envelope.size command injection
31.08.2026 11:24
A vulnerability classified as critical was found in Nodemailer up to 8.0.3. Affected is the function sendMail of the component Envelope Size. Executing a manipulation of the argument envelope.size can...
CVE-2026-82853 | Nodemailer up to 8.0.4 Transport Name Option command injection
31.08.2026 11:23
A vulnerability classified as problematic has been found in Nodemailer up to 8.0.4. This impacts an unknown function of the component Transport Name Option. Performing a manipulation of the argument N...
CVE-2026-82661 | Nodemailer up to 8.0.8 List Comment Sanitization crlf injection
31.08.2026 11:23
A vulnerability described as critical has been identified in Nodemailer up to 8.0.8. This affects an unknown function of the component List Comment Sanitization. Such manipulation of the argument Comm...
CVE-2024-58379 | Nodemailer up to 6.9.8 Email Parsing attachDataUrls redos
31.08.2026 11:22
A vulnerability marked as problematic has been reported in Nodemailer up to 6.9.8. The impacted element is an unknown function of the component Email Parsing. This manipulation of the argument attachD...
CVE-2026-82861 | Hulumi policies up to 1.3.1 Policy Evaluation data authenticity
31.08.2026 11:22
A vulnerability labeled as problematic has been found in Hulumi policies up to 1.3.1. The affected element is an unknown function of the component Policy Evaluation. The manipulation results in insuff...
CVE-2026-82858 | hulumi drift up to 1.3.1 input validation
31.08.2026 11:21
A vulnerability identified as critical has been detected in hulumi drift up to 1.3.1. Impacted is an unknown function. The manipulation leads to improper input validation. This vulnerability is trade...
CVE-2026-82857 | kerberosmansour Hulumi up to 1.3.1 Weekly Integration IAM Policy privileges management
31.08.2026 11:21
A vulnerability categorized as critical has been discovered in kerberosmansour Hulumi up to 1.3.1. This issue affects some unknown processing of the component Weekly Integration IAM Policy. Executing ...
CVE-2026-82856 | Hulumi prior 1.3.2 OIDC Trust Policy Validation input validation
31.08.2026 11:20
A vulnerability was found in Hulumi. It has been rated as critical. This vulnerability affects unknown code of the component OIDC Trust Policy Validation. Performing a manipulation results in improper...
CVE-2026-82855 | Hulumi policies up to 1.3.1 Validators privileges management
31.08.2026 11:20
A vulnerability was found in Hulumi policies up to 1.3.1. It has been declared as critical. This affects an unknown part of the component Validators. Such manipulation leads to improper privilege mana...
CVE-2026-82662 | Nodemailer up to 8.0.7 TLS Certificate Verification lib/fetch/index.js rejectUnauthorized certificate validation
31.08.2026 11:19
A vulnerability was found in Nodemailer up to 8.0.7. It has been classified as problematic. Affected by this issue is some unknown functionality of the file lib/fetch/index.js of the component TLS Cer...
CVE-2026-81624 | Red Hat Undertow WebSocket resource consumption (WID-SEC-2026-3099)
31.08.2026 11:19
A vulnerability was found in Red Hat Undertow and classified as problematic. Affected by this vulnerability is an unknown functionality of the component WebSocket. The manipulation results in resource...
CVE-2026-82838 | pretix Venueless SVG file cross site scripting (7dff888)
31.08.2026 10:24
A vulnerability has been found in pretix Venueless and classified as problematic. Affected is an unknown function of the component SVG file Handler. The manipulation leads to cross site scripting. Th...
CVE-2026-76984 | Apache Wicket MetaDataHeaderItem addTagAttribute cross site scripting (EUVD-2026-68490)
31.08.2026 09:54
A vulnerability, which was classified as problematic, was found in Apache Wicket. This impacts the function addTagAttribute of the component MetaDataHeaderItem. Executing a manipulation can lead to cr...
CVE-2026-76985 | Apache Wicket Palette getAdditionalAttributes cross site scripting
31.08.2026 09:53
A vulnerability, which was classified as problematic, has been found in Apache Wicket. This affects the function getAdditionalAttributes of the component Palette. Performing a manipulation results in ...
CVE-2026-76986 | Apache Wicket AbstractSingleSelectChoice getNullValidDisplayValue cross site scripting
31.08.2026 09:53
A vulnerability classified as problematic was found in Apache Wicket. The impacted element is the function getNullValidDisplayValue of the component AbstractSingleSelectChoice. Such manipulation leads...
CVE-2026-75802 | Apache Wicket AjaxEditableLabel cross site scripting (EUVD-2026-68488)
31.08.2026 09:52
A vulnerability classified as problematic has been found in Apache Wicket. The affected element is an unknown function of the component AjaxEditableLabel. This manipulation causes cross site scripting...
CVE-2026-76982 | Apache Wicket cross site scripting (EUVD-2026-68489)
31.08.2026 09:51
A vulnerability described as problematic has been identified in Apache Wicket. Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability was named CVE-2026...
CVE-2026-76983 | Apache Wicket AutoLabelTextResolver FormComponent.setLabel cross site scripting (EUVD-2026-68491)
31.08.2026 09:51
A vulnerability marked as problematic has been reported in Apache Wicket. This issue affects the function FormComponent.setLabel of the component AutoLabelTextResolver. The manipulation leads to cross...
CVE-2026-82835 | caoqianming django-vue-admin 1.0 /api/file/ file_id access control
31.08.2026 09:35
A vulnerability labeled as problematic has been found in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file...
CVE-2026-82834 | Doccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-Delete Endpoint category-types LabelList access control
31.08.2026 09:31
A vulnerability identified as problematic has been detected in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automati...
CVE-2026-82833 | Doccano Open Source Annotation Tools for Machine Learning Practitioners Project Example Detail Endpoint /v1/projects/1/examples/ ExampleDetail access control
31.08.2026 09:30
A vulnerability categorized as critical has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automati...
CVE-2026-82821 | FLVMeta up to 1.2.2 AMF Object Parsing src/amf.c amf_object_get null pointer dereference
31.08.2026 09:09
A vulnerability was found in FLVMeta up to 1.2.2. It has been rated as problematic. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Pars...
CVE-2026-82820 | FLVMeta up to 1.2.2 AMF String Processing src/amf.c amf_string_new length heap-based overflow (Issue 27)
31.08.2026 09:09
A vulnerability was found in FLVMeta up to 1.2.2. It has been declared as problematic. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipul...
CVE-2026-40465 | Nokia NSP up to 25.11-SP4 URL/redirect (EUVD-2026-68374)
31.08.2026 08:50
A vulnerability was found in Nokia NSP up to 25.11-SP4. It has been classified as problematic. This impacts an unknown function. The manipulation of the argument URL/redirect leads to open redirect. ...
CVE-2026-68951 | GROWI up to 8.0.0 improper authorization (EUVD-2026-68370)
31.08.2026 08:49
A vulnerability was found in GROWI up to 8.0.0 and classified as problematic. This affects an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability is regi...
CVE-2026-40464 | Nokia NSP up to 25.11-SP4 cross site scripting (EUVD-2026-68373)
31.08.2026 08:49
A vulnerability has been found in Nokia NSP up to 25.11-SP4 and classified as problematic. The impacted element is an unknown function. Performing a manipulation results in cross site scripting. This...
CVE-2026-58574 | Dell PowerStore Restricted Management Interface missing authentication
31.08.2026 08:48
A vulnerability, which was classified as very critical, was found in Dell PowerStore. The affected element is an unknown function of the component Restricted Management Interface. Such manipulation le...
CVE-2026-40463 | Nokia WaveSuite up to 23.6/24.6/24.12/25.6 CPB Log Files privileges management (EUVD-2026-68372)
31.08.2026 08:48
A vulnerability, which was classified as critical, has been found in Nokia WaveSuite up to 23.6/24.6/24.12/25.6. Impacted is an unknown function of the component CPB Log Files. This manipulation cause...
CVE-2026-53620 | GROWI up to 8.0.0 Bookmark Folder APIs key authorization (EUVD-2026-68371)
31.08.2026 08:47
A vulnerability classified as critical was found in GROWI up to 8.0.0. This issue affects some unknown processing of the component Bookmark Folder APIs. The manipulation of the argument key results in...
CVE-2026-77013 | 爱采集数据采集和发布插件 Plugin up to 1.0.0 on WordPress authorization
31.08.2026 08:47
A vulnerability classified as problematic has been found in 爱采集数据采集和发布插件 Plugin up to 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to mis...
CVE-2026-82818 | dibo-software diboot 3.8.0 Tenant Resource Assignment /api/iam/tenant/resource tenantId access control
31.08.2026 07:38
A vulnerability described as critical has been identified in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment H...
CVE-2026-82817 | dibo-software diboot 3.8.0 Tenant Administrator Management API /admin/ tenantId access control
31.08.2026 07:38
A vulnerability marked as critical has been reported in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Manag...
CVE-2026-82816 | dibo-software diboot 3.8.0 AI Session Endpoint /api/ai-session/ authorization
31.08.2026 07:38
A vulnerability labeled as critical has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session En...
CVE-2026-82815 | MegaEase EaseProbe up to 2.3.0 Middleware web/server.go realIP X-Forwarded-For/X-Real-IP/True-Client-IP access control
31.08.2026 07:27
A vulnerability identified as critical has been detected in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of ...
CVE-2026-82813 | BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome tubebuddymaster1.js TBGlobal.GetToken t/c/r data authenticity
31.08.2026 07:21
A vulnerability categorized as problematic has been discovered in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymast...
CVE-2026-82811 | Toggl OÜ Toggl Track Extension 4.11.16 postMessage origin validation
31.08.2026 07:15
A vulnerability was found in Toggl OÜ Toggl Track Extension 4.11.16. It has been rated as problematic. This affects an unknown function of the component postMessage Handler. The manipulation leads to...
CVE-2026-82810 | extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome Background Service Worker chrome.runtime.onMessageExternal.addListener sender.id information disclosure
31.08.2026 07:08
A vulnerability was found in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. It has been declared as problematic. The impacted element is the function chrome.runtime.onMessageExternal.addL...
CVE-2026-82809 | vidIQ Vision for YouTube Extension 3.199.0 on Chrome postMessage window.addEventListener vidiqEvent information disclosure
31.08.2026 07:00
A vulnerability was found in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. It has been classified as problematic. The affected element is the function window.addEventListener of the component ...
CVE-2026-82808 | Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials
31.08.2026 06:53
A vulnerability was found in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome and classified as critical. Impacted is an unknown function of the file dist/service-worker.production-esm.js o...
CVE-2026-82807 | ieungSoft Ultra RAMDisk Pro 1.82 Kernel Driver URDSCSI.sys privileges management
31.08.2026 06:42
A vulnerability has been found in ieungSoft Ultra RAMDisk Pro 1.82 and classified as critical. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. Thi...
CVE-2026-82805 | Typora up to 1.13.8/1.14.6 Mermaid Rendering Engine classDef/style cross site scripting
31.08.2026 06:35
A vulnerability, which was classified as problematic, was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of th...
CVE-2026-82803 | armink struct2json 1.0 JSON Deserialization struct2json/inc/s2jdef.h S2J_STRUCT_GET_string_ELEMENT valuestring null pointer dereference
31.08.2026 06:30
A vulnerability, which was classified as problematic, has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s2jdef.h of the c...
CVE-2026-82802 | NASA earthdata-search 1.0.0 granules Endpoint handler.js OpenSearchGranuleSearchLambda openSearchOsdd server-side request forgery
31.08.2026 06:27
A vulnerability classified as problematic was found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSea...
CVE-2026-82801 | NASA earthdata-search 1.0.0 scale Endpoint handler.js scaleImage server-side request forgery
31.08.2026 06:26
A vulnerability classified as critical has been found in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the ...
CVE-2026-82727 | ash-project ash_phoenix up to 2.3.24 Error Message Generation inspect _union_type/password information disclosure
31.08.2026 05:49
A vulnerability described as problematic has been identified in ash-project ash_phoenix up to 2.3.24. Affected is the function inspect of the component Error Message Generation. Such manipulation of t...
CVE-2026-82724 | ash-project ash_phoenix up to 2.3.24 SubdomainHook AshPhoenix.LiveView.SubdomainHook.on_mount improper authorization
31.08.2026 05:49
A vulnerability marked as problematic has been reported in ash-project ash_phoenix up to 2.3.24. This impacts the function AshPhoenix.LiveView.SubdomainHook.on_mount of the component SubdomainHook. Th...
CVE-2026-82726 | ash-project ash_phoenix up to 2.3.24 Helpers AshPhoenix.Helpers.get_subdomain host incorrect regex
31.08.2026 05:47
A vulnerability labeled as critical has been found in ash-project ash_phoenix up to 2.3.24. This affects the function AshPhoenix.Helpers.get_subdomain of the component Helpers. The manipulation of the...
CVE-2026-82725 | ash-project ash_phoenix up to 2.3.24 Filter Ash.Resource.Info.related Field authorization
31.08.2026 05:47
A vulnerability identified as problematic has been detected in ash-project ash_phoenix up to 2.3.24. The impacted element is the function Ash.Resource.Info.related of the component Filter. The manipul...
CVE-2026-82673 | ash-project ash_admin 0.13.7/1.3.0 File Upload client_name path traversal (EUVD-2026-68331)
31.08.2026 05:02
A vulnerability categorized as problematic has been discovered in ash-project ash_admin 0.13.7/1.3.0. The affected element is the function AshAdmin.Components.Resource.Form.consume_file_uploads of the...
CVE-2026-81853 | ash-project ash_admin up to 1.3.0 Helpers AshAdmin.Helpers.decode_primary_key authorization (EUVD-2026-68330)
31.08.2026 05:01
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been rated as problematic. Impacted is the function AshAdmin.Helpers.decode_primary_key of the component Helpers. Performing a ma...
CVE-2026-77850 | ash-project ash_admin up to 1.3.0 Typeahead Phoenix.HTML.raw cross site scripting (EUVD-2026-68326)
31.08.2026 04:49
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been declared as problematic. This issue affects the function Phoenix.HTML.raw of the component Typeahead. Such manipulation lead...
CVE-2026-81852 | ash-project ash_admin up to 1.3.0 CSP Nonce Generation AshAdmin.Router.ash_admin csp_nonce_assign_key random values (EUVD-2026-68328)
31.08.2026 04:48
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been classified as problematic. This vulnerability affects the function AshAdmin.Router.ash_admin of the component CSP Nonce Gene...
CVE-2026-82681 | ash-project ash_admin up to 1.3.0 Table/DataTable/Show injection (EUVD-2026-68327)
31.08.2026 04:48
A vulnerability was found in ash-project ash_admin up to 1.3.0 and classified as problematic. This affects an unknown part of the component Table/DataTable/Show. The manipulation results in injection....
CVE-2026-75757 | ash-project ash_admin up to 1.3.0 Cookie improper authorization (EUVD-2026-68324)
31.08.2026 04:47
A vulnerability has been found in ash-project ash_admin up to 1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie. The manipulation leads ...
CVE-2026-82722 | ash-project ash_admin up to 1.3.0 LiveView Event AshAdmin.Components.Resource.Show Module.concat/String.to_atom allocation of resources (EUVD-2026-68325)
31.08.2026 04:46
A vulnerability, which was classified as problematic, was found in ash-project ash_admin up to 1.3.0. Affected by this vulnerability is the function Module.concat/String.to_atom of the file AshAdmin.P...
CVE-2026-82579 | ash-project ash_ai up to 0.9.x Tool Loop AshAi.ToolLoop infinite loop
31.08.2026 03:48
A vulnerability, which was classified as problematic, has been found in ash-project ash_ai up to 0.9.x. Affected is the function AshAi.ToolLoop of the component Tool Loop. Performing a manipulation re...
RSS Feed eintragen

Machen Sie Ihren RSS-Feed bekannt und erhöhen Sie die Sichtbarkeit Ihrer Website!

RSS-Feed eintragen
RSS-Reader
RSS-Reader finden Sie unter unsere Übersicht: RSS-Reader
Die neuesten Feeds
Die Top-Feeds
meist gelesenen Feeds