<?xml version="1.0" encoding="UTF-8" ?> 
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom"> 
<channel> 
<title><![CDATA[Team IT Security - 🕵️ Sicherheitslücken]]></title> 
<link><![CDATA[https://tsecurity.de/feed.php?typ=9&q=]]></link> 
<description><![CDATA[Reverse Engineering ist die Kunst, technologische Produkte oder Systeme rückwärts zu analysieren, um ihre Funktionen, Komponenten und Herstellungsverfahren zu verstehen. Reverse Engineering kann sowohl für Innovation und Wettbewerb als auch für Sicherheit und Schutz eingesetzt werden. Auf tsecurity.de finden Sie aktuelle Informationen und Ressourcen zu Reverse Engineering, wie z. B.:  Die besten Reverse-Engineering-Tools für Sicherheitsexperten Die rechtlichen Aspekte von Reverse Engineering Die Anwendung von Reverse Engineering in verschiedenen Branchen und Disziplinen Die Vorteile und Herausforderungen von Reverse Engineering  Besuchen Sie tsecurity.de und lernen Sie, wie Sie Reverse Engineering effektiv nutzen können.]]></description>
<copyright>2026</copyright>
<atom:link href="https://tsecurity.de/feed.php?typ=9&amp;q=_" rel="self" type="application/rss+xml" />
<item> 
<title><![CDATA[CVE-2026-43115 | Linux Kernel up to 6.19.13 srcu_gp_start_if_needed use after free (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.19.13. It has been classified as critical. The affected element is the function srcu_gp_start_if_needed. This manipulation causes use after free.

This vulnerability is registered as CVE-2026-43115. The attack requires access to the local network. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3583129/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43115+%7C+Linux+Kernel+up+to+6.19.13+srcu_gp_start_if_needed+use+after+free+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583129/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43115+%7C+Linux+Kernel+up+to+6.19.13+srcu_gp_start_if_needed+use+after+free+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:28:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43118 | Linux Kernel up to 6.18.23/6.19.13 btrfs /mnt/dir overwrite_item privilege escalation (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Linux Kernel up to 6.18.23/6.19.13. This vulnerability affects the function overwrite_item of the file /mnt/dir of the component btrfs. This manipulation causes privilege escalation.

The identification of this vulnerability is CVE-2026-43118. The attack needs to be done within the local network. There is no exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3583128/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43118+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+btrfs+%2Fmnt%2Fdir+overwrite_item+privilege+escalation+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583128/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43118+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+btrfs+%2Fmnt%2Fdir+overwrite_item+privilege+escalation+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:28:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43116 | Linux Kernel up to 6.18.23/6.19.13 netfilter clean_from_lists deserialization (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.23/6.19.13. This affects the function clean_from_lists of the component netfilter. Performing a manipulation results in deserialization.

This vulnerability is identified as CVE-2026-43116. The attack can only be performed from the local network. There is not any exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3583127/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43116+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+netfilter+clean_from_lists+deserialization+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583127/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43116+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+netfilter+clean_from_lists+deserialization+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:28:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43119 | Linux Kernel up to 6.12.82/6.18.23/6.19.13 Bluetooth __hci_cmd_sync_sk privilege escalation (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in Linux Kernel up to 6.12.82/6.18.23/6.19.13. Affected by this issue is the function __hci_cmd_sync_sk of the component Bluetooth. Such manipulation leads to privilege escalation.

This vulnerability is referenced as CVE-2026-43119. The attack needs to be initiated within the local network. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3583126/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43119+%7C+Linux+Kernel+up+to+6.12.82%2F6.18.23%2F6.19.13+Bluetooth+__hci_cmd_sync_sk+privilege+escalation+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583126/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43119+%7C+Linux+Kernel+up+to+6.12.82%2F6.18.23%2F6.19.13+Bluetooth+__hci_cmd_sync_sk+privilege+escalation+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:28:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-38570 | bacnet_stack 1.3.1 bacnet_tag_number_decode out-of-bounds (ID 1270)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in bacnet_stack 1.3.1. The affected element is the function bacnet_tag_number_decode. Such manipulation leads to out-of-bounds read.

This vulnerability is documented as CVE-2026-38570. The attack requires being on the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3583125/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-38570+%7C+bacnet_stack+1.3.1+bacnet_tag_number_decode+out-of-bounds+%28ID+1270%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583125/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-38570+%7C+bacnet_stack+1.3.1+bacnet_tag_number_decode+out-of-bounds+%28ID+1270%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10863 | MISP up to 2.5.38 Correlations over-correlation Endpoint CorrelationsController.php overCorrelations input validation]]></title> 
<description><![CDATA[A vulnerability has been found in MISP up to 2.5.38 and classified as critical. This affects the function overCorrelations of the file app/Controller/CorrelationsController.php of the component Correlations over-correlation Endpoint. Performing a manipulation results in improper input validation.

This vulnerability was named CVE-2026-10863. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3583124/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10863+%7C+MISP+up+to+2.5.38+Correlations+over-correlation+Endpoint+CorrelationsController.php+overCorrelations+input+validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583124/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10863+%7C+MISP+up+to+2.5.38+Correlations+over-correlation+Endpoint+CorrelationsController.php+overCorrelations+input+validation/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-35904 | T3 T625Pro/T7281 Web Management Interface access control]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in T3 T625Pro and T7281. Impacted is an unknown function of the component Web Management Interface. The manipulation leads to improper access controls.

This vulnerability is documented as CVE-2026-35904. The attack can be initiated remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3583123/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35904+%7C+T3+T625Pro%2FT7281+Web+Management+Interface+access+control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583123/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35904+%7C+T3+T625Pro%2FT7281+Web+Management+Interface+access+control/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-36174 | GNCC GP5 7.1.76 Serial UART Interface missing encryption]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in GNCC GP5 7.1.76. This affects an unknown function of the component Serial UART Interface. Such manipulation leads to missing encryption of sensitive data.

This vulnerability is traded as CVE-2026-36174. The attack can be executed directly on the physical device. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3583122/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36174+%7C+GNCC+GP5+7.1.76+Serial+UART+Interface+missing+encryption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583122/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36174+%7C+GNCC+GP5+7.1.76+Serial+UART+Interface+missing+encryption/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45739 | strawberry-graphql strawberry up to 0.315.3 GraphQL /proxy/CDN information disclosure (ID 4398)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in strawberry-graphql strawberry up to 0.315.3. The impacted element is an unknown function of the file /proxy/CDN of the component GraphQL Handler. This manipulation causes information disclosure.

This vulnerability appears as CVE-2026-45739. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3583121/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45739+%7C+strawberry-graphql+strawberry+up+to+0.315.3+GraphQL+%2Fproxy%2FCDN+information+disclosure+%28ID+4398%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583121/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45739+%7C+strawberry-graphql+strawberry+up+to+0.315.3+GraphQL+%2Fproxy%2FCDN+information+disclosure+%28ID+4398%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-36182 | GNCC GP5 7.1.76 excessive authentication]]></title> 
<description><![CDATA[A vulnerability was found in GNCC GP5 7.1.76 and classified as problematic. This issue affects some unknown processing. Such manipulation leads to improper restriction of excessive authentication attempts.

This vulnerability is uniquely identified as CVE-2026-36182. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3583120/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36182+%7C+GNCC+GP5+7.1.76+excessive+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583120/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36182+%7C+GNCC+GP5+7.1.76+excessive+authentication/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-35905 | T3 T625Pro/T7281 hard-coded password]]></title> 
<description><![CDATA[A vulnerability was found in T3 T625Pro and T7281 and classified as critical. Affected by this issue is some unknown functionality. The manipulation results in use of hard-coded password.

This vulnerability was named CVE-2026-35905. The attack needs to be approached within the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3583119/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35905+%7C+T3+T625Pro%2FT7281+hard-coded+password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583119/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35905+%7C+T3+T625Pro%2FT7281+hard-coded+password/</guid>
<pubDate>Tue, 09 Jun 2026 00:40:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.10.7]]></title> 
<description><![CDATA[chore: bump version to 15.10.7 ]]></description>
<link>https://tsecurity.de/de/3583092/IT+Reverse+Engineering/Tools/v15.10.7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583092/IT+Reverse+Engineering/Tools/v15.10.7/</guid>
<pubDate>Tue, 09 Jun 2026 00:32:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43951 | Apache HTTP Server up to 2.4.67 merge_response_headers out-of-bounds (Nessus ID 319665)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in Apache HTTP Server up to 2.4.67. Affected is the function merge_response_headers. The manipulation leads to out-of-bounds read.

This vulnerability is listed as CVE-2026-43951. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3583075/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43951+%7C+Apache+HTTP+Server+up+to+2.4.67+merge_response_headers+out-of-bounds+%28Nessus+ID+319665%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583075/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43951+%7C+Apache+HTTP+Server+up+to+2.4.67+merge_response_headers+out-of-bounds+%28Nessus+ID+319665%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:05:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-44119 | Apache HTTP Server up to 2.4.67 htaccess information disclosure (Nessus ID 319665)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in Apache HTTP Server up to 2.4.67. Affected by this vulnerability is an unknown functionality of the component htaccess Handler. The manipulation results in information disclosure.

This vulnerability is cataloged as CVE-2026-44119. The attack must be initiated from a local position. There is no exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3583074/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44119+%7C+Apache+HTTP+Server+up+to+2.4.67+htaccess+information+disclosure+%28Nessus+ID+319665%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583074/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44119+%7C+Apache+HTTP+Server+up+to+2.4.67+htaccess+information+disclosure+%28Nessus+ID+319665%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:05:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43106 | Linux Kernel up to 6.19.13 cachefiles_cull reference count (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.19.13. The affected element is the function cachefiles_cull. Such manipulation leads to improper update of reference count.

This vulnerability is traded as CVE-2026-43106. Access to the local network is required for this attack to succeed. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3583073/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43106+%7C+Linux+Kernel+up+to+6.19.13+cachefiles_cull+reference+count+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583073/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43106+%7C+Linux+Kernel+up+to+6.19.13+cachefiles_cull+reference+count+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:13:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43107 | Linux Kernel up to 6.12.82/6.18.23/6.19.13 xfrm xfrm_get_ae allocation of resources (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.82/6.18.23/6.19.13. This affects the function xfrm_get_ae of the component xfrm. Executing a manipulation can lead to allocation of resources.

This vulnerability is handled as CVE-2026-43107. The attack can only be done within the local network. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3583072/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43107+%7C+Linux+Kernel+up+to+6.12.82%2F6.18.23%2F6.19.13+xfrm+xfrm_get_ae+allocation+of+resources+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583072/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43107+%7C+Linux+Kernel+up+to+6.12.82%2F6.18.23%2F6.19.13+xfrm+xfrm_get_ae+allocation+of+resources+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Tue, 09 Jun 2026 00:13:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50224 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 API Endpoint information disclosure]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. The affected element is an unknown function of the component API Endpoint. The manipulation leads to information disclosure.

This vulnerability is uniquely identified as CVE-2026-50224. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3583032/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50224+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+API+Endpoint+information+disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583032/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50224+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+API+Endpoint+information+disclosure/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2019-25731 | Zuz Music 2.1 Inbox Interface ___contact name/subject/message cross site scripting (Exploit 46420)]]></title> 
<description><![CDATA[A vulnerability was found in Zuz Music 2.1. It has been rated as problematic. The affected element is an unknown function of the file /gmusic/zuzconsole/___contact of the component Inbox Interface. Performing a manipulation of the argument name/subject/message results in cross site scripting.

This vulnerability is cataloged as CVE-2019-25731. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. ]]></description>
<link>https://tsecurity.de/de/3583031/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2019-25731+%7C+Zuz+Music+2.1+Inbox+Interface+___contact+name%2Fsubject%2Fmessage+cross+site+scripting+%28Exploit+46420%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583031/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2019-25731+%7C+Zuz+Music+2.1+Inbox+Interface+___contact+name%2Fsubject%2Fmessage+cross+site+scripting+%28Exploit+46420%29/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50225 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 Registration /v1/account/register missing authentication]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. The impacted element is an unknown function of the file /v1/account/register of the component Registration Handler. The manipulation results in missing authentication.

This vulnerability was named CVE-2026-50225. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3583030/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50225+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Registration+%2Fv1%2Faccount%2Fregister+missing+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583030/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50225+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Registration+%2Fv1%2Faccount%2Fregister+missing+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-62338 | HCL BigFix Cloud Lifecycle Management improper authorization (KB0130802)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in HCL BigFix Cloud Lifecycle Management. Affected by this vulnerability is an unknown functionality. This manipulation causes improper authorization.

This vulnerability is registered as CVE-2025-62338. The attack needs to be launched locally. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3583029/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-62338+%7C+HCL+BigFix+Cloud+Lifecycle+Management+improper+authorization+%28KB0130802%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583029/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-62338+%7C+HCL+BigFix+Cloud+Lifecycle+Management+improper+authorization+%28KB0130802%29/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50226 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 hard-coded key]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. Impacted is an unknown function. Executing a manipulation can lead to use of hard-coded cryptographic key
.

This vulnerability is handled as CVE-2026-50226. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3583028/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50226+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+hard-coded+key/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583028/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50226+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+hard-coded+key/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2019-25737 | Screets Live Chat Unlimited 2.8.3 cross site scripting (Exploit 47037)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in Screets Live Chat Unlimited 2.8.3. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting.

This vulnerability appears as CVE-2019-25737. The attack may be performed from remote. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3583027/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2019-25737+%7C+Screets+Live+Chat+Unlimited+2.8.3+cross+site+scripting+%28Exploit+47037%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583027/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2019-25737+%7C+Screets+Live+Chat+Unlimited+2.8.3+cross+site+scripting+%28Exploit+47037%29/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50214 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 Shared Global API /v1/Plan data authenticity]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. This issue affects some unknown processing of the file /v1/Plan of the component Shared Global API. Performing a manipulation results in insufficient verification of data authenticity.

This vulnerability is known as CVE-2026-50214. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3583026/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50214+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Shared+Global+API+%2Fv1%2FPlan+data+authenticity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583026/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50214+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Shared+Global+API+%2Fv1%2FPlan+data+authenticity/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10047 | Bitdefender Napoca bare-metal hypervisor 519 Real-mode Hook napoca/kernel/handler.c out-of-bounds write]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Bitdefender Napoca bare-metal hypervisor 519. Impacted is an unknown function of the file napoca/kernel/handler.c of the component Real-mode Hook Handler. Performing a manipulation results in out-of-bounds write. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is reported as CVE-2026-10047. The attack requires a local approach. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3583025/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10047+%7C+Bitdefender+Napoca+bare-metal+hypervisor+519+Real-mode+Hook+napoca%2Fkernel%2Fhandler.c+out-of-bounds+write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583025/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10047+%7C+Bitdefender+Napoca+bare-metal+hypervisor+519+Real-mode+Hook+napoca%2Fkernel%2Fhandler.c+out-of-bounds+write/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-36460 | Dovestones ADPhonebook prior 4.0.1.1 Configuration /Admin/Save cross site scripting]]></title> 
<description><![CDATA[A vulnerability was found in Dovestones ADPhonebook and classified as problematic. Affected by this issue is some unknown functionality of the file /Admin/Save of the component Configuration Handler. Such manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2026-36460. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3583024/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36460+%7C+Dovestones+ADPhonebook+prior+4.0.1.1+Configuration+%2FAdmin%2FSave+cross+site+scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583024/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36460+%7C+Dovestones+ADPhonebook+prior+4.0.1.1+Configuration+%2FAdmin%2FSave+cross+site+scripting/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-36574 | CactusViewer 2.3.0 uncontrolled search path]]></title> 
<description><![CDATA[A vulnerability has been found in CactusViewer 2.3.0 and classified as problematic. Affected is an unknown function. The manipulation leads to uncontrolled search path.

This vulnerability is uniquely identified as CVE-2026-36574. Local access is required to approach this attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3583023/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36574+%7C+CactusViewer+2.3.0+uncontrolled+search+path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583023/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36574+%7C+CactusViewer+2.3.0+uncontrolled+search+path/</guid>
<pubDate>Mon, 08 Jun 2026 23:22:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43100 | Linux Kernel up to 6.18.23/6.19.13 br_private.h br_vlan_group null pointer dereference (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.23/6.19.13 and classified as critical. Impacted is the function br_vlan_group in the library br_private.h. The manipulation results in null pointer dereference.

This vulnerability is cataloged as CVE-2026-43100. The attack must originate from the local network. There is no exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582956/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43100+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+br_private.h+br_vlan_group+null+pointer+dereference+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582956/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43100+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+br_private.h+br_vlan_group+null+pointer+dereference+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Mon, 08 Jun 2026 22:58:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43101 | Linux Kernel up to 6.18.23/6.19.13 ipv6 __ioam6_fill_trace_data null pointer dereference (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.23/6.19.13. It has been classified as critical. This vulnerability affects the function __ioam6_fill_trace_data of the component ipv6. The manipulation leads to null pointer dereference.

This vulnerability is documented as CVE-2026-43101. The attack requires being on the local network. There is not any exploit available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3582955/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43101+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+ipv6+__ioam6_fill_trace_data+null+pointer+dereference+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582955/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43101+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+ipv6+__ioam6_fill_trace_data+null+pointer+dereference+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Mon, 08 Jun 2026 22:58:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43102 | Linux Kernel up to 6.18.23/6.19.13 net airoha_qdma_rx_process memory leak (WID-SEC-2026-1385)]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.23/6.19.13. It has been classified as critical. Affected by this vulnerability is the function airoha_qdma_rx_process of the component net. Performing a manipulation results in memory leak.

This vulnerability is reported as CVE-2026-43102. The attacker must have access to the local network to execute the attack. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3582954/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43102+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+net+airoha_qdma_rx_process+memory+leak+%28WID-SEC-2026-1385%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582954/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43102+%7C+Linux+Kernel+up+to+6.18.23%2F6.19.13+net+airoha_qdma_rx_process+memory+leak+%28WID-SEC-2026-1385%29/</guid>
<pubDate>Mon, 08 Jun 2026 22:58:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-42965 | Red Hat OpenShift Container Platform 4 Cloud Metadata Endpoint server-side request forgery]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Red Hat OpenShift Container Platform 4. Impacted is an unknown function of the component Cloud Metadata Endpoint. The manipulation leads to server-side request forgery.

This vulnerability is listed as CVE-2026-42965. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582877/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42965+%7C+Red+Hat+OpenShift+Container+Platform+4+Cloud+Metadata+Endpoint+server-side+request+forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582877/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42965+%7C+Red+Hat+OpenShift+Container+Platform+4+Cloud+Metadata+Endpoint+server-side+request+forgery/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49121 | ROCm aiter up to 0.1.14 Writer XPUB Endpoint shm_broadcast.py MessageQueue.recv deserialization (Issue 3076)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in ROCm aiter up to 0.1.14. Impacted is the function MessageQueue.recv of the file shm_broadcast.py of the component Writer XPUB Endpoint. Such manipulation leads to deserialization.

This vulnerability is traded as CVE-2026-49121. The attack may be launched remotely. There is no exploit available.

It is advisable to implement a patch to correct this issue. ]]></description>
<link>https://tsecurity.de/de/3582876/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49121+%7C+ROCm+aiter+up+to+0.1.14+Writer+XPUB+Endpoint+shm_broadcast.py+MessageQueue.recv+deserialization+%28Issue+3076%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582876/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49121+%7C+ROCm+aiter+up+to+0.1.14+Writer+XPUB+Endpoint+shm_broadcast.py+MessageQueue.recv+deserialization+%28Issue+3076%29/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10046 | Bitdefender Napoca bare-metal hypervisor Malicious Guest Operatingreal Mode bios_handlers.c out-of-bounds write]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Bitdefender Napoca bare-metal hypervisor. The affected element is an unknown function of the file napoca/guests/bios_handlers.c of the component Malicious Guest Operatingreal Mode. Executing a manipulation can lead to out-of-bounds write. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability appears as CVE-2026-10046. The attack requires local access. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582875/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10046+%7C+Bitdefender+Napoca+bare-metal+hypervisor+Malicious+Guest+Operatingreal+Mode+bios_handlers.c+out-of-bounds+write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582875/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10046+%7C+Bitdefender+Napoca+bare-metal+hypervisor+Malicious+Guest+Operatingreal+Mode+bios_handlers.c+out-of-bounds+write/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49201 | Acer Wave 7 Router up to T7c_GBL_1.01.000055 upload.cgi hard-coded key]]></title> 
<description><![CDATA[A vulnerability has been found in Acer Wave 7 Router up to T7c_GBL_1.01.000055 and classified as critical. This impacts an unknown function of the file upload.cgi. Performing a manipulation results in use of hard-coded cryptographic key
.

This vulnerability is reported as CVE-2026-49201. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582874/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49201+%7C+Acer+Wave+7+Router+up+to+T7c_GBL_1.01.000055+upload.cgi+hard-coded+key/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582874/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49201+%7C+Acer+Wave+7+Router+up+to+T7c_GBL_1.01.000055+upload.cgi+hard-coded+key/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46579 | Red Hat OpenShift Container Platform 4 Transport Layer Security improper authentication]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Red Hat OpenShift Container Platform 4. This affects an unknown function of the component Transport Layer Security. Such manipulation leads to improper authentication.

This vulnerability is documented as CVE-2026-46579. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582873/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46579+%7C+Red+Hat+OpenShift+Container+Platform+4+Transport+Layer+Security+improper+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582873/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46579+%7C+Red+Hat+OpenShift+Container+Platform+4+Transport+Layer+Security+improper+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49195 | Acer Predator Connect W6x up to W6x_GBL_2.00.000005 Debug Service /sbin/mtk_dut missing authentication]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Acer Predator Connect W6x up to W6x_GBL_2.00.000005. This issue affects some unknown processing of the file /sbin/mtk_dut of the component Debug Service. Performing a manipulation results in missing authentication.

This vulnerability was named CVE-2026-49195. The attack needs to be approached within the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582872/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49195+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Debug+Service+%2Fsbin%2Fmtk_dut+missing+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582872/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49195+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Debug+Service+%2Fsbin%2Fmtk_dut+missing+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49196 | Acer Predator Connect W6x up to W6x_GBL_2.00.000005 Wi-Fi Device Blocking Feature command injection]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Acer Predator Connect W6x up to W6x_GBL_2.00.000005. Impacted is an unknown function of the component Wi-Fi Device Blocking Feature. Executing a manipulation can lead to command injection.

The identification of this vulnerability is CVE-2026-49196. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582871/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49196+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Wi-Fi+Device+Blocking+Feature+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582871/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49196+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Wi-Fi+Device+Blocking+Feature+command+injection/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49198 | Acer Predator Connect W6x up to W6x_GBL_2.00.000005 Subscription access control (EUVD-2026-33266)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Acer Predator Connect W6x up to W6x_GBL_2.00.000005. This vulnerability affects unknown code of the component Subscription Handler. Such manipulation leads to improper access controls.

This vulnerability is uniquely identified as CVE-2026-49198. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582870/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49198+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Subscription+access+control+%28EUVD-2026-33266%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582870/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49198+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Subscription+access+control+%28EUVD-2026-33266%29/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10533 | Red Hat OpenShift Container Platform 4 allocation of resources]]></title> 
<description><![CDATA[A vulnerability was found in Red Hat OpenShift Container Platform 4 and classified as problematic. Impacted is an unknown function. Such manipulation leads to allocation of resources.

This vulnerability is listed as CVE-2026-10533. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582869/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10533+%7C+Red+Hat+OpenShift+Container+Platform+4+allocation+of+resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582869/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10533+%7C+Red+Hat+OpenShift+Container+Platform+4+allocation+of+resources/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49197 | Acer Predator Connect W6x up to W6x_GBL_2.00.000005 Web Endpoint improper authentication]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Acer Predator Connect W6x up to W6x_GBL_2.00.000005. The affected element is an unknown function of the component Web Endpoint. The manipulation leads to improper authentication.

This vulnerability is referenced as CVE-2026-49197. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582868/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49197+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Web+Endpoint+improper+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582868/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49197+%7C+Acer+Predator+Connect+W6x+up+to+W6x_GBL_2.00.000005+Web+Endpoint+improper+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 22:33:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.10.6]]></title> 
<description><![CDATA[chore: bump version to 15.10.6 ]]></description>
<link>https://tsecurity.de/de/3582867/IT+Reverse+Engineering/Tools/v15.10.6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582867/IT+Reverse+Engineering/Tools/v15.10.6/</guid>
<pubDate>Mon, 08 Jun 2026 22:39:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-3907 | Clerk Plugin up to 3.x on WordPress API Request timing discrepancy]]></title> 
<description><![CDATA[A vulnerability has been found in Clerk Plugin up to 3.x on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component API Request Handler. This manipulation causes observable timing discrepancy.

The identification of this vulnerability is CVE-2022-3907. The attack needs to be done within the local network. There is no exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3582812/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-3907+%7C+Clerk+Plugin+up+to+3.x+on+WordPress+API+Request+timing+discrepancy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582812/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-3907+%7C+Clerk+Plugin+up+to+3.x+on+WordPress+API+Request+timing+discrepancy/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2017-7564 | ARM Trusted Firmware up to 1.3 Debug Interface input validation]]></title> 
<description><![CDATA[A vulnerability has been found in ARM Trusted Firmware up to 1.3 and classified as problematic. Impacted is an unknown function of the component Debug Interface. Performing a manipulation results in improper input validation.

This vulnerability was named CVE-2017-7564. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582811/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2017-7564+%7C+ARM+Trusted+Firmware+up+to+1.3+Debug+Interface+input+validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582811/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2017-7564+%7C+ARM+Trusted+Firmware+up+to+1.3+Debug+Interface+input+validation/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20027 | ZKTeco ZKBioSecurity 3.0.1.0_R_230 cross site scripting (ZSL-2016-5363 / EUVD-2016-10809)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in ZKTeco ZKBioSecurity 3.0.1.0_R_230. This vulnerability affects unknown code. Such manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2016-20027. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582810/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20027+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+cross+site+scripting+%28ZSL-2016-5363+%2F+EUVD-2016-10809%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582810/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20027+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+cross+site+scripting+%28ZSL-2016-5363+%2F+EUVD-2016-10809%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20028 | ZKTeco ZKBioSecurity 3.0.1.0_R_230 HTTP Request cross-site request forgery (ZSL-2016-5364 / EUVD-2016-10811)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in ZKTeco ZKBioSecurity 3.0.1.0_R_230. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation leads to cross-site request forgery.

This vulnerability is documented as CVE-2016-20028. The attack can be initiated remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582809/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20028+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+HTTP+Request+cross-site+request+forgery+%28ZSL-2016-5364+%2F+EUVD-2016-10811%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582809/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20028+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+HTTP+Request+cross-site+request+forgery+%28ZSL-2016-5364+%2F+EUVD-2016-10811%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20025 | ZKTeco ZKAccess Professional up to 3.5.3 File file access (ZSL-2016-5361 / EUVD-2016-10805)]]></title> 
<description><![CDATA[A vulnerability was found in ZKTeco ZKAccess Professional up to 3.5.3. It has been rated as problematic. The impacted element is an unknown function of the component File Handler. This manipulation causes files or directories accessible.

This vulnerability is tracked as CVE-2016-20025. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582808/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20025+%7C+ZKTeco+ZKAccess+Professional+up+to+3.5.3+File+file+access+%28ZSL-2016-5361+%2F+EUVD-2016-10805%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582808/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20025+%7C+ZKTeco+ZKAccess+Professional+up+to+3.5.3+File+file+access+%28ZSL-2016-5361+%2F+EUVD-2016-10805%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2021-32032 | Linaro Trusted Firmware-M up to 1.3.0 Cryptographic Library abort memory leak]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in Linaro Trusted Firmware-M up to 1.3.0. The impacted element is the function abort of the component Cryptographic Library. The manipulation leads to memory leak.

This vulnerability is uniquely identified as CVE-2021-32032. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to install a patch to address this issue. ]]></description>
<link>https://tsecurity.de/de/3582807/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-32032+%7C+Linaro+Trusted+Firmware-M+up+to+1.3.0+Cryptographic+Library+abort+memory+leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582807/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-32032+%7C+Linaro+Trusted+Firmware-M+up+to+1.3.0+Cryptographic+Library+abort+memory+leak/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2018-16988 | Open XDMoD up to 7.5.0 Password Reset pass_reset.php MD5 password recovery]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Open XDMoD up to 7.5.0. This vulnerability affects unknown code of the file pass_reset.php of the component Password Reset. Such manipulation leads to weak password recovery  (MD5).

This vulnerability is traded as CVE-2018-16988. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582806/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2018-16988+%7C+Open+XDMoD+up+to+7.5.0+Password+Reset+pass_reset.php+MD5+password+recovery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582806/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2018-16988+%7C+Open+XDMoD+up+to+7.5.0+Password+Reset+pass_reset.php+MD5+password+recovery/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3999 | Pointsharp ID Server up to 8.x Configuration authorization (psa-2026-001 / EUVD-2026-11772)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Pointsharp ID Server up to 8.x. This affects an unknown part of the component Configuration Handler. Executing a manipulation can lead to authorization bypass.

This vulnerability is handled as CVE-2026-3999. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3582805/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3999+%7C+Pointsharp+ID+Server+up+to+8.x+Configuration+authorization+%28psa-2026-001+%2F+EUVD-2026-11772%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582805/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3999+%7C+Pointsharp+ID+Server+up+to+8.x+Configuration+authorization+%28psa-2026-001+%2F+EUVD-2026-11772%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20026 | ZKTeco ZKBioSecurity 3.0.1.0_R_230 WAR Archive hard-coded credentials (ZSL-2016-5362 / EUVD-2016-10807)]]></title> 
<description><![CDATA[A vulnerability was found in ZKTeco ZKBioSecurity 3.0.1.0_R_230. It has been classified as critical. Impacted is an unknown function of the component WAR Archive Handler. The manipulation leads to hard-coded credentials.

This vulnerability is referenced as CVE-2016-20026. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582804/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20026+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+WAR+Archive+hard-coded+credentials+%28ZSL-2016-5362+%2F+EUVD-2016-10807%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582804/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20026+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+WAR+Archive+hard-coded+credentials+%28ZSL-2016-5362+%2F+EUVD-2016-10807%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2017-7563 | ARM Trusted Firmware 1.3 MT_EXECUTE_NEVER Protection access control]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in ARM Trusted Firmware 1.3. This issue affects some unknown processing of the component MT_EXECUTE_NEVER Protection. Such manipulation leads to improper access controls.

This vulnerability is uniquely identified as CVE-2017-7563. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582803/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2017-7563+%7C+ARM+Trusted+Firmware+1.3+MT_EXECUTE_NEVER+Protection+access+control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582803/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2017-7563+%7C+ARM+Trusted+Firmware+1.3+MT_EXECUTE_NEVER+Protection+access+control/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20024 | ZKTeco ZKTime 3.0.1.1 (160216)/3.0.1.5 (160622)/3.0.1.6 File file information disclosure (ZSL-2016-5360 / EUVD-2016-10803)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in ZKTeco ZKTime 3.0.1.1 (160216)/3.0.1.5 (160622)/3.0.1.6. This affects an unknown function of the component File Handler. Such manipulation leads to file and directory information exposure.

This vulnerability is listed as CVE-2016-20024. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582802/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20024+%7C+ZKTeco+ZKTime+3.0.1.1+%28160216%29%2F3.0.1.5+%28160622%29%2F3.0.1.6+File+file+information+disclosure+%28ZSL-2016-5360+%2F+EUVD-2016-10803%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582802/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20024+%7C+ZKTeco+ZKTime+3.0.1.1+%28160216%29%2F3.0.1.5+%28160622%29%2F3.0.1.6+File+file+information+disclosure+%28ZSL-2016-5360+%2F+EUVD-2016-10803%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:51:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20032 | ZKTeco ZKAccess Security System 5.3.12252 Request holiday_name/memo cross site scripting (ZSL-2016-5368 / EUVD-2016-10819)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in ZKTeco ZKAccess Security System 5.3.12252. Affected is an unknown function of the component Request Handler. Executing a manipulation of the argument holiday_name/memo can lead to cross site scripting.

This vulnerability is registered as CVE-2016-20032. It is possible to launch the attack remotely. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582801/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20032+%7C+ZKTeco+ZKAccess+Security+System+5.3.12252+Request+holiday_name%2Fmemo+cross+site+scripting+%28ZSL-2016-5368+%2F+EUVD-2016-10819%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582801/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20032+%7C+ZKTeco+ZKAccess+Security+System+5.3.12252+Request+holiday_name%2Fmemo+cross+site+scripting+%28ZSL-2016-5368+%2F+EUVD-2016-10819%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20029 | ZKTeco ZKBioSecurity 3.0.1.0_R_230 Configuration File default permission (ZSL-2016-5365 / EUVD-2016-10813)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in ZKTeco ZKBioSecurity 3.0.1.0_R_230. This impacts an unknown function of the component Configuration File Handler. Performing a manipulation results in incorrect default permissions.

This vulnerability is cataloged as CVE-2016-20029. The attack must be initiated from a local position. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582800/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20029+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+Configuration+File+default+permission+%28ZSL-2016-5365+%2F+EUVD-2016-10813%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582800/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20029+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+Configuration+File+default+permission+%28ZSL-2016-5365+%2F+EUVD-2016-10813%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20030 | ZKTeco ZKBioSecurity 3.0.1.0_R_230 User Account authLoginAction!login.do Username incorrect behavior order (ZSL-2016-5366 / EUVD-2016-10815)]]></title> 
<description><![CDATA[A vulnerability was found in ZKTeco ZKBioSecurity 3.0.1.0_R_230. It has been declared as critical. The affected element is an unknown function of the file authLoginAction!login.do of the component User Account Handler. The manipulation of the argument Username results in incorrect behavior order: authorization before parsing and canonicalization.

This vulnerability is identified as CVE-2016-20030. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582799/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20030+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+User+Account+authLoginAction%21login.do+Username+incorrect+behavior+order+%28ZSL-2016-5366+%2F+EUVD-2016-10815%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582799/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20030+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+User+Account+authLoginAction%21login.do+Username+incorrect+behavior+order+%28ZSL-2016-5366+%2F+EUVD-2016-10815%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2016-20031 | ZKTeco ZKBioSecurity 3.0.1.0_R_230 visLogin.jsp getClientIp hard-coded credentials (ZSL-2016-5367 / EUVD-2016-10817)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in ZKTeco ZKBioSecurity 3.0.1.0_R_230. Affected by this issue is the function getClientIp of the file visLogin.jsp. The manipulation results in hard-coded credentials.

This vulnerability is reported as CVE-2016-20031. The attack requires a local approach. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582798/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20031+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+visLogin.jsp+getClientIp+hard-coded+credentials+%28ZSL-2016-5367+%2F+EUVD-2016-10817%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582798/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2016-20031+%7C+ZKTeco+ZKBioSecurity+3.0.1.0_R_230+visLogin.jsp+getClientIp+hard-coded+credentials+%28ZSL-2016-5367+%2F+EUVD-2016-10817%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-31386 | LiteSpeed OpenLiteSpeed/LSWS Enterprise os command injection]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in LiteSpeed OpenLiteSpeed and LSWS Enterprise. This affects an unknown part. Such manipulation leads to os command injection.

This vulnerability is listed as CVE-2026-31386. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582797/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-31386+%7C+LiteSpeed+OpenLiteSpeed%2FLSWS+Enterprise+os+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582797/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-31386+%7C+LiteSpeed+OpenLiteSpeed%2FLSWS+Enterprise+os+command+injection/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-4255 | thermalright TR-VISION HOME up to 2.0.4 on Windows inclusion of functionality from untrusted control sphere (EUVD-2026-12363)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in thermalright TR-VISION HOME up to 2.0.4 on Windows. This impacts an unknown function. This manipulation causes inclusion of functionality from untrusted control sphere.

This vulnerability is tracked as CVE-2026-4255. The attack is restricted to local execution. No exploit exists.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582796/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4255+%7C+thermalright+TR-VISION+HOME+up+to+2.0.4+on+Windows+inclusion+of+functionality+from+untrusted+control+sphere+%28EUVD-2026-12363%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582796/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4255+%7C+thermalright+TR-VISION+HOME+up+to+2.0.4+on+Windows+inclusion+of+functionality+from+untrusted+control+sphere+%28EUVD-2026-12363%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3476 | Dassault Systèmes SOLIDWORKS Desktop 2025/2026 code injection]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Dassault Syst&egrave;mes SOLIDWORKS Desktop 2025/2026. This affects an unknown function. Such manipulation leads to code injection.

This vulnerability is referenced as CVE-2026-3476. It is possible to launch the attack remotely. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582795/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3476+%7C+Dassault+Syst%C3%A8mes+SOLIDWORKS+Desktop+2025%2F2026+code+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582795/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3476+%7C+Dassault+Syst%C3%A8mes+SOLIDWORKS+Desktop+2025%2F2026+code+injection/</guid>
<pubDate>Mon, 08 Jun 2026 21:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-42271 | BerriAI LiteLLM up to 1.83.6 Endpoint connection command/args/env command injection]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in BerriAI LiteLLM up to 1.83.6. Affected by this issue is some unknown functionality of the file /mcp-rest/test/connection of the component Endpoint. Such manipulation of the argument command/args/env leads to command injection.

This vulnerability is referenced as CVE-2026-42271. It is possible to launch the attack remotely. Furthermore, an exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582794/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42271+%7C+BerriAI+LiteLLM+up+to+1.83.6+Endpoint+connection+command%2Fargs%2Fenv+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582794/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42271+%7C+BerriAI+LiteLLM+up+to+1.83.6+Endpoint+connection+command%2Fargs%2Fenv+command+injection/</guid>
<pubDate>Mon, 08 Jun 2026 22:09:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Firefox Tooling Announcements: MozPhab 2.15.2 Released]]></title> 
<description><![CDATA[Bugs resolved in Moz-Phab 2.15.2:

bug 2004368 moz-phab patch -a here with jj says there is no source tree if jj config is broken
bug 2035900 Investigate setting up CodSpeed.io for moz-phab
bug 2044857 patch --raw leaks a global logger level, causing order-dependent test failures

Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
            1 post - 1 participant
            Read full topic ]]></description>
<link>https://tsecurity.de/de/3582774/IT+Reverse+Engineering/Tools/Firefox+Tooling+Announcements%3A+MozPhab+2.15.2+Released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582774/IT+Reverse+Engineering/Tools/Firefox+Tooling+Announcements%3A+MozPhab+2.15.2+Released/</guid>
<pubDate>Mon, 08 Jun 2026 20:41:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32946 | Apple iOS/iPadOS Core Bluetooth information disclosure (HT213489 / EUVD-2022-36012)]]></title> 
<description><![CDATA[A vulnerability was found in Apple iOS and iPadOS. It has been rated as problematic. This issue affects some unknown processing of the component Core Bluetooth. The manipulation leads to information disclosure.

This vulnerability is documented as CVE-2022-32946. The attack needs to be performed locally. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3582654/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32946+%7C+Apple+iOS%2FiPadOS+Core+Bluetooth+information+disclosure+%28HT213489+%2F+EUVD-2022-36012%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582654/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32946+%7C+Apple+iOS%2FiPadOS+Core+Bluetooth+information+disclosure+%28HT213489+%2F+EUVD-2022-36012%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:49:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32947 | Apple iOS/iPadOS GPU Drivers memory corruption (HT213489 / EUVD-2022-36013)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Apple iOS and iPadOS. Impacted is an unknown function of the component GPU Drivers. The manipulation results in memory corruption.

This vulnerability is reported as CVE-2022-32947. The attack requires a local approach. No exploit exists.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582653/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32947+%7C+Apple+iOS%2FiPadOS+GPU+Drivers+memory+corruption+%28HT213489+%2F+EUVD-2022-36013%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582653/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32947+%7C+Apple+iOS%2FiPadOS+GPU+Drivers+memory+corruption+%28HT213489+%2F+EUVD-2022-36013%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:49:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32947 | Apple watchOS up to 9.0.2 GPU Drivers memory corruption (HT213491 / EUVD-2022-36013)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Apple watchOS up to 9.0.2. This affects an unknown part of the component GPU Drivers. This manipulation causes memory corruption.

This vulnerability is handled as CVE-2022-32947. It is possible to launch the attack on the local host. There is not any exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582652/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32947+%7C+Apple+watchOS+up+to+9.0.2+GPU+Drivers+memory+corruption+%28HT213491+%2F+EUVD-2022-36013%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582652/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32947+%7C+Apple+watchOS+up+to+9.0.2+GPU+Drivers+memory+corruption+%28HT213491+%2F+EUVD-2022-36013%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:49:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32947 | Apple macOS GPU Drivers memory corruption (HT213488 / EUVD-2022-36013)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Apple macOS. Affected by this vulnerability is an unknown functionality of the component GPU Drivers. This manipulation causes memory corruption.

This vulnerability appears as CVE-2022-32947. The attack requires local access. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582651/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32947+%7C+Apple+macOS+GPU+Drivers+memory+corruption+%28HT213488+%2F+EUVD-2022-36013%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582651/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32947+%7C+Apple+macOS+GPU+Drivers+memory+corruption+%28HT213488+%2F+EUVD-2022-36013%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:49:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32948 | Apple iOS/iPadOS Kernel out-of-bounds (EUVD-2022-36014)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Apple iOS and iPadOS. Impacted is an unknown function of the component Kernel. Such manipulation leads to out-of-bounds read.

This vulnerability is traded as CVE-2022-32948. An attack has to be approached locally. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582650/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32948+%7C+Apple+iOS%2FiPadOS+Kernel+out-of-bounds+%28EUVD-2022-36014%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582650/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32948+%7C+Apple+iOS%2FiPadOS+Kernel+out-of-bounds+%28EUVD-2022-36014%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:49:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32948 | Apple macOS Kernel out-of-bounds (EUVD-2022-36014)]]></title> 
<description><![CDATA[A vulnerability has been found in Apple macOS and classified as critical. The affected element is an unknown function of the component Kernel. Performing a manipulation results in out-of-bounds read.

This vulnerability is known as CVE-2022-32948. Attacking locally is a requirement. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3582649/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32948+%7C+Apple+macOS+Kernel+out-of-bounds+%28EUVD-2022-36014%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582649/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32948+%7C+Apple+macOS+Kernel+out-of-bounds+%28EUVD-2022-36014%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:49:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32953 | InsydeH2O up to 5.5 SdHostDriver toctou (EUVD-2022-36019)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in InsydeH2O up to 5.5. Impacted is an unknown function of the component SdHostDriver. Performing a manipulation results in time-of-check time-of-use.

This vulnerability is identified as CVE-2022-32953. The attack can only be performed from the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582648/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32953+%7C+InsydeH2O+up+to+5.5+SdHostDriver+toctou+%28EUVD-2022-36019%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582648/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32953+%7C+InsydeH2O+up+to+5.5+SdHostDriver+toctou+%28EUVD-2022-36019%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32949 | Apple iOS/iPadOS up to 15.7.0 App Local Privilege Escalation (EUVD-2022-36015)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in Apple iOS and iPadOS up to 15.7.0. This affects an unknown part of the component App Handler. The manipulation leads to Local Privilege Escalation.

This vulnerability is uniquely identified as CVE-2022-32949. Local access is required to approach this attack. No exploit exists.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582647/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32949+%7C+Apple+iOS%2FiPadOS+up+to+15.7.0+App+Local+Privilege+Escalation+%28EUVD-2022-36015%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582647/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32949+%7C+Apple+iOS%2FiPadOS+up+to+15.7.0+App+Local+Privilege+Escalation+%28EUVD-2022-36015%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32949 | Apple tvOS up to 15.7.0 App Local Privilege Escalation (EUVD-2022-36015)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in Apple tvOS up to 15.7.0. This vulnerability affects unknown code of the component App Handler. The manipulation results in Local Privilege Escalation.

This vulnerability was named CVE-2022-32949. The attack needs to be approached locally. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3582646/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32949+%7C+Apple+tvOS+up+to+15.7.0+App+Local+Privilege+Escalation+%28EUVD-2022-36015%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582646/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32949+%7C+Apple+tvOS+up+to+15.7.0+App+Local+Privilege+Escalation+%28EUVD-2022-36015%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32984 | BTCPay Server up to 1.5.3 Point of Sale App information disclosure (EUVD-2022-36050)]]></title> 
<description><![CDATA[A vulnerability was found in BTCPay Server up to 1.5.3 and classified as problematic. The affected element is an unknown function of the component Point of Sale App. Executing a manipulation can lead to information disclosure.

The identification of this vulnerability is CVE-2022-32984. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582645/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32984+%7C+BTCPay+Server+up+to+1.5.3+Point+of+Sale+App+information+disclosure+%28EUVD-2022-36050%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582645/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32984+%7C+BTCPay+Server+up+to+1.5.3+Point+of+Sale+App+information+disclosure+%28EUVD-2022-36050%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32954 | InsydeH2O up to 5.5 SdMmcDevice toctou (EUVD-2022-36020)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in InsydeH2O up to 5.5. Affected by this vulnerability is an unknown functionality of the component SdMmcDevice. Executing a manipulation can lead to time-of-check time-of-use.

This vulnerability is handled as CVE-2022-32954. The attack can only be done within the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582644/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32954+%7C+InsydeH2O+up+to+5.5+SdMmcDevice+toctou+%28EUVD-2022-36020%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582644/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32954+%7C+InsydeH2O+up+to+5.5+SdMmcDevice+toctou+%28EUVD-2022-36020%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32955 | InsydeH2O up to 5.5 NvmExpressDxe toctou (EUVD-2022-36021)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in InsydeH2O up to 5.5. Affected by this issue is some unknown functionality of the component NvmExpressDxe. The manipulation leads to time-of-check time-of-use.

This vulnerability is uniquely identified as CVE-2022-32955. The attack can only be initiated within the local network. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582643/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32955+%7C+InsydeH2O+up+to+5.5+NvmExpressDxe+toctou+%28EUVD-2022-36021%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582643/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32955+%7C+InsydeH2O+up+to+5.5+NvmExpressDxe+toctou+%28EUVD-2022-36021%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32972 | Infoblox BloxOne Endpoint up to 2.2.7 on Windows injection (EUVD-2022-36038)]]></title> 
<description><![CDATA[A vulnerability was found in Infoblox BloxOne Endpoint up to 2.2.7 on Windows. It has been declared as problematic. This vulnerability affects unknown code. Such manipulation leads to injection.

This vulnerability is traded as CVE-2022-32972. An attack has to be approached locally. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582642/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32972+%7C+Infoblox+BloxOne+Endpoint+up+to+2.2.7+on+Windows+injection+%28EUVD-2022-36038%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582642/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32972+%7C+Infoblox+BloxOne+Endpoint+up+to+2.2.7+on+Windows+injection+%28EUVD-2022-36038%29/</guid>
<pubDate>Mon, 08 Jun 2026 21:03:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-25559 | openbullet2 up to 0.3.2 Wordlist Endpoint path traversal (EUVD-2026-35137)]]></title> 
<description><![CDATA[A vulnerability was found in openbullet2 up to 0.3.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Wordlist Endpoint. The manipulation results in path traversal.

This vulnerability is known as CVE-2026-25559. It is possible to launch the attack remotely. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582561/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25559+%7C+openbullet2+up+to+0.3.2+Wordlist+Endpoint+path+traversal+%28EUVD-2026-35137%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582561/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25559+%7C+openbullet2+up+to+0.3.2+Wordlist+Endpoint+path+traversal+%28EUVD-2026-35137%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-39908 | openbullet2 up to 0.3.2 on Windows insufficiently protected credentials (EUVD-2026-35133)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in openbullet2 up to 0.3.2 on Windows. This issue affects some unknown processing. Executing a manipulation can lead to insufficiently protected credentials.

The identification of this vulnerability is CVE-2026-39908. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582560/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-39908+%7C+openbullet2+up+to+0.3.2+on+Windows+insufficiently+protected+credentials+%28EUVD-2026-35133%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582560/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-39908+%7C+openbullet2+up+to+0.3.2+on+Windows+insufficiently+protected+credentials+%28EUVD-2026-35133%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-25555 | openbullet2 up to 0.3. API Endpoint authentication bypass (EUVD-2026-35138)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in openbullet2 up to 0.3.. The impacted element is an unknown function of the component API Endpoint. This manipulation causes authentication bypass by primary weakness.

This vulnerability is tracked as CVE-2026-25555. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582559/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25555+%7C+openbullet2+up+to+0.3.+API+Endpoint+authentication+bypass+%28EUVD-2026-35138%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582559/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25555+%7C+openbullet2+up+to+0.3.+API+Endpoint+authentication+bypass+%28EUVD-2026-35138%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11534 | imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46 /add.php name/address/fname cross site scripting (EUVD-2026-35132)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting.

This vulnerability is known as CVE-2026-11534. It is possible to launch the attack remotely. Furthermore, an exploit is available.

This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

The project was informed of the problem early through an issue report but has not responded yet. ]]></description>
<link>https://tsecurity.de/de/3582558/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11534+%7C+imvks786+student_management_system+up+to+9599b560ad3c3b83e75d328b76bedcd489ef1f46+%2Fadd.php+name%2Faddress%2Ffname+cross+site+scripting+%28EUVD-2026-35132%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582558/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11534+%7C+imvks786+student_management_system+up+to+9599b560ad3c3b83e75d328b76bedcd489ef1f46+%2Fadd.php+name%2Faddress%2Ffname+cross+site+scripting+%28EUVD-2026-35132%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-25856 | openbullet2 up to 0.3.2 code injection (EUVD-2026-35135)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in openbullet2 up to 0.3.2. Impacted is an unknown function. The manipulation leads to code injection.

This vulnerability is referenced as CVE-2026-25856. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582557/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25856+%7C+openbullet2+up+to+0.3.2+code+injection+%28EUVD-2026-35135%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582557/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25856+%7C+openbullet2+up+to+0.3.2+code+injection+%28EUVD-2026-35135%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-25855 | openbullet2 up to 0.3.2 FileProxySource Proxy Loading Feature bat.ps1.sh os command injection (EUVD-2026-35134)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in openbullet2 up to 0.3.2. This vulnerability affects unknown code of the file bat.ps1.sh of the component FileProxySource Proxy Loading Feature. Performing a manipulation results in os command injection.

This vulnerability was named CVE-2026-25855. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582556/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25855+%7C+openbullet2+up+to+0.3.2+FileProxySource+Proxy+Loading+Feature+bat.ps1.sh+os+command+injection+%28EUVD-2026-35134%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582556/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25855+%7C+openbullet2+up+to+0.3.2+FileProxySource+Proxy+Loading+Feature+bat.ps1.sh+os+command+injection+%28EUVD-2026-35134%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43966 | ninenines cowlib 2.9.0 Matching Parser response splitting (EUVD-2026-35131)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in ninenines cowlib 2.9.0. The affected element is an unknown function of the component Matching Parser. The manipulation results in http response splitting.

This vulnerability is identified as CVE-2026-43966. The attack can be executed remotely. There is not any exploit available.

It is advisable to implement a patch to correct this issue. ]]></description>
<link>https://tsecurity.de/de/3582555/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43966+%7C+ninenines+cowlib+2.9.0+Matching+Parser+response+splitting+%28EUVD-2026-35131%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582555/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43966+%7C+ninenines+cowlib+2.9.0+Matching+Parser+response+splitting+%28EUVD-2026-35131%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11464 | JeecgBoot up to 3.9.2 User List Endpoint SysUserController.java queryPageList salt information disclosure (Issue 9648 / EUVD-2026-34995)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt leads to information disclosure.

This vulnerability is listed as CVE-2026-11464. The attack may be initiated remotely. In addition, an exploit is available.

A fix is planned for the upcoming release. ]]></description>
<link>https://tsecurity.de/de/3582554/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11464+%7C+JeecgBoot+up+to+3.9.2+User+List+Endpoint+SysUserController.java+queryPageList+salt+information+disclosure+%28Issue+9648+%2F+EUVD-2026-34995%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582554/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11464+%7C+JeecgBoot+up+to+3.9.2+User+List+Endpoint+SysUserController.java+queryPageList+salt+information+disclosure+%28Issue+9648+%2F+EUVD-2026-34995%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11523 | Tenda W20E 15.11.0.6 Web Management Interface /goform/PortalAuth formPortalAuth gotoUrl stack-based overflow (EUVD-2026-35080)]]></title> 
<description><![CDATA[A vulnerability was found in Tenda W20E 15.11.0.6 and classified as critical. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow.

This vulnerability is tracked as CVE-2026-11523. The attack can be launched remotely. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3582553/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11523+%7C+Tenda+W20E+15.11.0.6+Web+Management+Interface+%2Fgoform%2FPortalAuth+formPortalAuth+gotoUrl+stack-based+overflow+%28EUVD-2026-35080%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582553/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11523+%7C+Tenda+W20E+15.11.0.6+Web+Management+Interface+%2Fgoform%2FPortalAuth+formPortalAuth+gotoUrl+stack-based+overflow+%28EUVD-2026-35080%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2021-47982 | maxfoundry WP-Paginate 2.1.3 on WordPress Setting preset cross site scripting (Exploit 49355 / EUVD-2021-34848)]]></title> 
<description><![CDATA[A vulnerability was found in maxfoundry WP-Paginate 2.1.3 on WordPress. It has been rated as problematic. Affected is an unknown function of the component Setting Handler. Performing a manipulation of the argument preset results in cross site scripting.

This vulnerability is cataloged as CVE-2021-47982. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. ]]></description>
<link>https://tsecurity.de/de/3582552/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-47982+%7C+maxfoundry+WP-Paginate+2.1.3+on+WordPress+Setting+preset+cross+site+scripting+%28Exploit+49355+%2F+EUVD-2021-34848%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582552/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-47982+%7C+maxfoundry+WP-Paginate+2.1.3+on+WordPress+Setting+preset+cross+site+scripting+%28Exploit+49355+%2F+EUVD-2021-34848%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11480 | Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22 Admin Design Builder Endpoint admin.php settings.value sql injection (EUVD-2026-35011)]]></title> 
<description><![CDATA[A vulnerability has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22 and classified as critical. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.value results in sql injection.

This vulnerability is cataloged as CVE-2026-11480. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

To fix this issue, it is recommended to deploy a patch. ]]></description>
<link>https://tsecurity.de/de/3582551/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11480+%7C+Chengdu+Everbrite+Network+Technology+BeikeShop+up+to+1.6.0.22+Admin+Design+Builder+Endpoint+admin.php+settings.value+sql+injection+%28EUVD-2026-35011%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582551/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11480+%7C+Chengdu+Everbrite+Network+Technology+BeikeShop+up+to+1.6.0.22+Admin+Design+Builder+Endpoint+admin.php+settings.value+sql+injection+%28EUVD-2026-35011%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2023-54352 | WP Travel Kit Travelscape 1.0.3 mar.php missing authentication (Exploit 51789 / EUVD-2023-60583)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in WP Travel Kit Travelscape 1.0.3. This affects an unknown part of the file /wp-content/themes/seotheme/mar.php. This manipulation causes missing authentication.

This vulnerability is handled as CVE-2023-54352. The attack can be initiated remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582550/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2023-54352+%7C+WP+Travel+Kit+Travelscape+1.0.3+mar.php+missing+authentication+%28Exploit+51789+%2F+EUVD-2023-60583%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582550/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2023-54352+%7C+WP+Travel+Kit+Travelscape+1.0.3+mar.php+missing+authentication+%28Exploit+51789+%2F+EUVD-2023-60583%29/</guid>
<pubDate>Mon, 08 Jun 2026 20:32:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49232 | NLnet Labs Routinator exceptional condition (EUVD-2026-35062)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in NLnet Labs Routinator. Affected by this vulnerability is an unknown functionality. This manipulation causes handling of exceptional conditions.

This vulnerability appears as CVE-2026-49232. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582369/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49232+%7C+NLnet+Labs+Routinator+exceptional+condition+%28EUVD-2026-35062%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582369/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49232+%7C+NLnet+Labs+Routinator+exceptional+condition+%28EUVD-2026-35062%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49233 | NLnet Labs Routinator path traversal (EUVD-2026-35063)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in NLnet Labs Routinator. Affected by this issue is some unknown functionality. Such manipulation leads to path traversal.

This vulnerability is traded as CVE-2026-49233. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3582368/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49233+%7C+NLnet+Labs+Routinator+path+traversal+%28EUVD-2026-35063%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582368/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49233+%7C+NLnet+Labs+Routinator+path+traversal+%28EUVD-2026-35063%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49234 | NLnet Labs Routinator Query Parameter /api/v1/origins denial of service (EUVD-2026-35064)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in NLnet Labs Routinator. This affects an unknown part of the file /api/v1/origins of the component Query Parameter Handler. Performing a manipulation results in denial of service.

This vulnerability is known as CVE-2026-49234. Attacking locally is a requirement. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582367/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49234+%7C+NLnet+Labs+Routinator+Query+Parameter+%2Fapi%2Fv1%2Forigins+denial+of+service+%28EUVD-2026-35064%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582367/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49234+%7C+NLnet+Labs+Routinator+Query+Parameter+%2Fapi%2Fv1%2Forigins+denial+of+service+%28EUVD-2026-35064%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49235 | NLnet Labs Routinator RRDP exceptional condition (EUVD-2026-35065)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in NLnet Labs Routinator. This vulnerability affects unknown code of the component RRDP. Executing a manipulation can lead to handling of exceptional conditions.

This vulnerability is handled as CVE-2026-49235. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582366/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49235+%7C+NLnet+Labs+Routinator+RRDP+exceptional+condition+%28EUVD-2026-35065%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582366/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49235+%7C+NLnet+Labs+Routinator+RRDP+exceptional+condition+%28EUVD-2026-35065%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11529 | designcomputer mysql-mcp-server up to 0.2.2 mysql URI server.py read_resource uri_str sql injection (Issue 89 / EUVD-2026-35108)]]></title> 
<description><![CDATA[A vulnerability was found in designcomputer mysql-mcp-server up to 0.2.2. It has been rated as critical. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection.

This vulnerability is registered as CVE-2026-11529. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3582365/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11529+%7C+designcomputer+mysql-mcp-server+up+to+0.2.2+mysql+URI+server.py+read_resource+uri_str+sql+injection+%28Issue+89+%2F+EUVD-2026-35108%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582365/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11529+%7C+designcomputer+mysql-mcp-server+up+to+0.2.2+mysql+URI+server.py+read_resource+uri_str+sql+injection+%28Issue+89+%2F+EUVD-2026-35108%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-48913 | Apache HTTP Server up to 2.4.67 mod_http2 memory corruption (EUVD-2026-35101)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Apache HTTP Server up to 2.4.67. This issue affects some unknown processing of the component mod_http2. Executing a manipulation can lead to memory corruption.

This vulnerability appears as CVE-2026-48913. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3582364/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48913+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_http2+memory+corruption+%28EUVD-2026-35101%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582364/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48913+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_http2+memory+corruption+%28EUVD-2026-35101%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-34355 | Apache HTTP Server up to 2.4.67 mod_proxy_html buffer overflow (EUVD-2026-35097)]]></title> 
<description><![CDATA[A vulnerability was found in Apache HTTP Server up to 2.4.67. It has been classified as critical. The affected element is an unknown function of the component mod_proxy_html. This manipulation causes buffer overflow.

The identification of this vulnerability is CVE-2026-34355. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3582363/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-34355+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_proxy_html+buffer+overflow+%28EUVD-2026-35097%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582363/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-34355+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_proxy_html+buffer+overflow+%28EUVD-2026-35097%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-44185 | Apache HTTP Server up to 2.4.67 mod_ssl send_request stack-based overflow (EUVD-2026-35099)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Apache HTTP Server up to 2.4.67. Affected by this issue is the function send_request of the component mod_ssl. This manipulation causes stack-based buffer overflow.

This vulnerability is registered as CVE-2026-44185. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582362/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44185+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_ssl+send_request+stack-based+overflow+%28EUVD-2026-35099%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582362/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44185+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_ssl+send_request+stack-based+overflow+%28EUVD-2026-35099%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-42536 | Apache HTTP Server up to 2.4.67 mod_xml2enc heap-based overflow (EUVD-2026-35100)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Apache HTTP Server up to 2.4.67. This impacts an unknown function of the component mod_xml2enc. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is tracked as CVE-2026-42536. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582361/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42536+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_xml2enc+heap-based+overflow+%28EUVD-2026-35100%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582361/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42536+%7C+Apache+HTTP+Server+up+to+2.4.67+mod_xml2enc+heap-based+overflow+%28EUVD-2026-35100%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49755 | wojtekmach req up to 0.6.0 lib/req/steps.ex data amplification (EUVD-2026-35098)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in wojtekmach req up to 0.6.0. The affected element is an unknown function in the library lib/req/steps.ex. Executing a manipulation can lead to highly compressed data.

This vulnerability is tracked as CVE-2026-49755. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3582360/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49755+%7C+wojtekmach+req+up+to+0.6.0+lib%2Freq%2Fsteps.ex+data+amplification+%28EUVD-2026-35098%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582360/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49755+%7C+wojtekmach+req+up+to+0.6.0+lib%2Freq%2Fsteps.ex+data+amplification+%28EUVD-2026-35098%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-44631 | Apache HTTP Server up to 2.4.67 ap_regname heap-based overflow (EUVD-2026-35095)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Apache HTTP Server up to 2.4.67. This vulnerability affects the function ap_regname. Performing a manipulation results in heap-based buffer overflow.

This vulnerability is reported as CVE-2026-44631. The attack requires a local approach. No exploit exists.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582359/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44631+%7C+Apache+HTTP+Server+up+to+2.4.67+ap_regname+heap-based+overflow+%28EUVD-2026-35095%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582359/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44631+%7C+Apache+HTTP+Server+up+to+2.4.67+ap_regname+heap-based+overflow+%28EUVD-2026-35095%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49756 | wojtekmach req up to 0.5.x lib/req/utils.ex crlf injection (EUVD-2026-35096)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in wojtekmach req up to 0.5.x. The impacted element is an unknown function in the library lib/req/utils.ex. The manipulation leads to crlf injection.

This vulnerability is listed as CVE-2026-49756. The attack must be carried out locally. There is no available exploit.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582358/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49756+%7C+wojtekmach+req+up+to+0.5.x+lib%2Freq%2Futils.ex+crlf+injection+%28EUVD-2026-35096%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582358/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49756+%7C+wojtekmach+req+up+to+0.5.x+lib%2Freq%2Futils.ex+crlf+injection+%28EUVD-2026-35096%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2024-58348 | background-image-cropper Background Image Cropper 1.2 PHP File ups.php unrestricted upload (Exploit 51998 / EUVD-2024-55614)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in background-image-cropper Background Image Cropper 1.2. This issue affects some unknown processing of the file ups.php of the component PHP File Handler. Performing a manipulation results in unrestricted upload.

This vulnerability was named CVE-2024-58348. The attack may be initiated remotely. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582259/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-58348+%7C+background-image-cropper+Background+Image+Cropper+1.2+PHP+File+ups.php+unrestricted+upload+%28Exploit+51998+%2F+EUVD-2024-55614%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582259/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-58348+%7C+background-image-cropper+Background+Image+Cropper+1.2+PHP+File+ups.php+unrestricted+upload+%28Exploit+51998+%2F+EUVD-2024-55614%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11488 | code-projects Simple Flight Ticket Booking System 1.0 POST Parameter checkUser.php Username sql injection (EUVD-2026-35019)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-11488. The attack is possible to be carried out remotely. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3582258/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11488+%7C+code-projects+Simple+Flight+Ticket+Booking+System+1.0+POST+Parameter+checkUser.php+Username+sql+injection+%28EUVD-2026-35019%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582258/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11488+%7C+code-projects+Simple+Flight+Ticket+Booking+System+1.0+POST+Parameter+checkUser.php+Username+sql+injection+%28EUVD-2026-35019%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11493 | Tenda AC15 15.03.05.19 Samba /etc_ro/smb.conf weak password (EUVD-2026-35024)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements.

This vulnerability is tracked as CVE-2026-11493. The attack is only possible within the local network. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3582257/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11493+%7C+Tenda+AC15+15.03.05.19+Samba+%2Fetc_ro%2Fsmb.conf+weak+password+%28EUVD-2026-35024%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582257/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11493+%7C+Tenda+AC15+15.03.05.19+Samba+%2Fetc_ro%2Fsmb.conf+weak+password+%28EUVD-2026-35024%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11465 | songquanpeng one-api up to 0.6.11-preview.7 Redemption Code Top-Up Endpoint model/redemption.go Redeem logic error (Issue 2397 / EUVD-2026-34996)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors.

This vulnerability is cataloged as CVE-2026-11465. The attack may be launched remotely. Furthermore, there is an exploit available.

The pull request to fix this issue awaits acceptance. ]]></description>
<link>https://tsecurity.de/de/3582256/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11465+%7C+songquanpeng+one-api+up+to+0.6.11-preview.7+Redemption+Code+Top-Up+Endpoint+model%2Fredemption.go+Redeem+logic+error+%28Issue+2397+%2F+EUVD-2026-34996%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582256/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11465+%7C+songquanpeng+one-api+up+to+0.6.11-preview.7+Redemption+Code+Top-Up+Endpoint+model%2Fredemption.go+Redeem+logic+error+%28Issue+2397+%2F+EUVD-2026-34996%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11517 | UTT HiPER 2610G up to 3.0.0-171107 formConfigDnsFilterGlobal strcpy GroupName buffer overflow (EUVD-2026-35067)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the argument GroupName can lead to buffer overflow.

This vulnerability is handled as CVE-2026-11517. The attack can be executed remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582255/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11517+%7C+UTT+HiPER+2610G+up+to+3.0.0-171107+formConfigDnsFilterGlobal+strcpy+GroupName+buffer+overflow+%28EUVD-2026-35067%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582255/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11517+%7C+UTT+HiPER+2610G+up+to+3.0.0-171107+formConfigDnsFilterGlobal+strcpy+GroupName+buffer+overflow+%28EUVD-2026-35067%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11518 | SourceCodester Inventory System 1.0 User Management Page /users.php fullname/username cross site scripting (EUVD-2026-35068)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument fullname/username leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-11518. The attack is possible to be carried out remotely. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3582254/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11518+%7C+SourceCodester+Inventory+System+1.0+User+Management+Page+%2Fusers.php+fullname%2Fusername+cross+site+scripting+%28EUVD-2026-35068%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582254/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11518+%7C+SourceCodester+Inventory+System+1.0+User+Management+Page+%2Fusers.php+fullname%2Fusername+cross+site+scripting+%28EUVD-2026-35068%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11481 | yoanbernabeu grepai up to 0.35.0 Postgres Embedding Cache indexer/chunker.go PostgresStore.LookupByContentHash content_hash weak hash (Issue 249 / EUVD-2026-35012)]]></title> 
<description><![CDATA[A vulnerability was found in yoanbernabeu grepai up to 0.35.0 and classified as problematic. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash.

This vulnerability is registered as CVE-2026-11481. The attack needs to be launched locally. Furthermore, an exploit is available.

The pull request to fix this issue awaits acceptance. ]]></description>
<link>https://tsecurity.de/de/3582253/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11481+%7C+yoanbernabeu+grepai+up+to+0.35.0+Postgres+Embedding+Cache+indexer%2Fchunker.go+PostgresStore.LookupByContentHash+content_hash+weak+hash+%28Issue+249+%2F+EUVD-2026-35012%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582253/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11481+%7C+yoanbernabeu+grepai+up+to+0.35.0+Postgres+Embedding+Cache+indexer%2Fchunker.go+PostgresStore.LookupByContentHash+content_hash+weak+hash+%28Issue+249+%2F+EUVD-2026-35012%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11492 | D-Link DIR-823G 1.0.2B05 vsftpd /etc/vsftpd.conf least privilege violation (EUVD-2026-35023)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation.

This vulnerability is identified as CVE-2026-11492. The attack can be initiated remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582252/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11492+%7C+D-Link+DIR-823G+1.0.2B05+vsftpd+%2Fetc%2Fvsftpd.conf+least+privilege+violation+%28EUVD-2026-35023%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582252/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11492+%7C+D-Link+DIR-823G+1.0.2B05+vsftpd+%2Fetc%2Fvsftpd.conf+least+privilege+violation+%28EUVD-2026-35023%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11487 | Neovim up to 0.12.2 View Branch secure.lua M.read path command injection (Issue 39914 / EUVD-2026-35018)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection.

This vulnerability is handled as CVE-2026-11487. It is possible to launch the attack on the local host. Additionally, an exploit exists.

A patch should be applied to remediate this issue. ]]></description>
<link>https://tsecurity.de/de/3582251/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11487+%7C+Neovim+up+to+0.12.2+View+Branch+secure.lua+M.read+path+command+injection+%28Issue+39914+%2F+EUVD-2026-35018%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582251/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11487+%7C+Neovim+up+to+0.12.2+View+Branch+secure.lua+M.read+path+command+injection+%28Issue+39914+%2F+EUVD-2026-35018%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11516 | UTT HiPER 2610G up to 3.0.0-171107 /goform/formNatStaticMap strcpy NatBinds buffer overflow (EUVD-2026-35066)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBinds results in buffer overflow.

This vulnerability is known as CVE-2026-11516. Access to the local network is required for this attack. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582250/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11516+%7C+UTT+HiPER+2610G+up+to+3.0.0-171107+%2Fgoform%2FformNatStaticMap+strcpy+NatBinds+buffer+overflow+%28EUVD-2026-35066%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582250/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11516+%7C+UTT+HiPER+2610G+up+to+3.0.0-171107+%2Fgoform%2FformNatStaticMap+strcpy+NatBinds+buffer+overflow+%28EUVD-2026-35066%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2024-58349 | WP Travel Kit Travelscape 1.0.3 on WordPress unrestricted upload (Exploit 51969 / EUVD-2024-55615)]]></title> 
<description><![CDATA[A vulnerability was found in WP Travel Kit Travelscape 1.0.3 on WordPress. It has been declared as critical. This impacts an unknown function. Such manipulation leads to unrestricted upload.

This vulnerability is listed as CVE-2024-58349. The attack may be performed from remote. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582249/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-58349+%7C+WP+Travel+Kit+Travelscape+1.0.3+on+WordPress+unrestricted+upload+%28Exploit+51969+%2F+EUVD-2024-55615%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582249/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-58349+%7C+WP+Travel+Kit+Travelscape+1.0.3+on+WordPress+unrestricted+upload+%28Exploit+51969+%2F+EUVD-2024-55615%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:52:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.10.5]]></title> 
<description><![CDATA[chore: bump version to 15.10.5 ]]></description>
<link>https://tsecurity.de/de/3582248/IT+Reverse+Engineering/Tools/v15.10.5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582248/IT+Reverse+Engineering/Tools/v15.10.5/</guid>
<pubDate>Mon, 08 Jun 2026 19:11:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ich habs mal für euch ausprobiert... #tech #chatgpt #ai]]></title> 
<description><![CDATA[Author: The Morpheus - Bewertung: 19x - Views:447  ]]></description>
<link>https://tsecurity.de/de/3582208/IT+Reverse+Engineering/Video/Ich+habs+mal+f%C3%BCr+euch+ausprobiert...+%23tech+%23chatgpt+%23ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582208/IT+Reverse+Engineering/Video/Ich+habs+mal+f%C3%BCr+euch+ausprobiert...+%23tech+%23chatgpt+%23ai/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical Zcash Vulnerability Found and Fixed]]></title> 
<description><![CDATA[If you&rsquo;re a user&mdash;owner?&mdash;of this cryptocurrency, this is important:
On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind of issue. He found one fast enough to be embarrassing.
The Orchard pool is the newest and most advanced shielded transaction system in the cryptocurrency Zcash. Introduced in 2022, it allows users to send and receive ZEC while keeping transaction details private. It uses zero-knowledge proofs to validate transactions without revealing amounts or participants. The bug: a specific check that was supposed to validate transaction inputs wasn&rsquo;t actually enforcing the rules it appeared to enforce. An attacker could have exploited the flaw to feed false inputs into that check and generate ZEC from nothing, with the zero-knowledge proof system blessing the fraudulent transaction as valid... ]]></description>
<link>https://tsecurity.de/de/3582207/IT+Reverse+Engineering/Critical+Zcash+Vulnerability+Found+and+Fixed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582207/IT+Reverse+Engineering/Critical+Zcash+Vulnerability+Found+and+Fixed/</guid>
<pubDate>Mon, 08 Jun 2026 19:06:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43973 | ninenines gun up to 2.3.x allocation of resources (EUVD-2026-35074)]]></title> 
<description><![CDATA[A vulnerability was found in ninenines gun up to 2.3.x. It has been rated as problematic. Impacted is an unknown function. This manipulation causes allocation of resources.

This vulnerability is tracked as CVE-2026-43973. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3582173/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43973+%7C+ninenines+gun+up+to+2.3.x+allocation+of+resources+%28EUVD-2026-35074%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582173/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43973+%7C+ninenines+gun+up+to+2.3.x+allocation+of+resources+%28EUVD-2026-35074%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43972 | ninenines gun up to 2.3.x origin validation (EUVD-2026-35073)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in ninenines gun up to 2.3.x. The impacted element is an unknown function. Performing a manipulation results in origin validation error.

This vulnerability is cataloged as CVE-2026-43972. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3582172/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43972+%7C+ninenines+gun+up+to+2.3.x+origin+validation+%28EUVD-2026-35073%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582172/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43972+%7C+ninenines+gun+up+to+2.3.x+origin+validation+%28EUVD-2026-35073%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11467 | jishenghua jshERP up to 3.6 addAccountHeadAndDetail Endpoint AccountHeadService.java fileName path traversal (Issue 154 / EUVD-2026-34998)]]></title> 
<description><![CDATA[A vulnerability was found in jishenghua jshERP up to 3.6 and classified as critical. This vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. Such manipulation of the argument fileName leads to path traversal.

This vulnerability is documented as CVE-2026-11467. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet. ]]></description>
<link>https://tsecurity.de/de/3582171/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11467+%7C+jishenghua+jshERP+up+to+3.6+addAccountHeadAndDetail+Endpoint+AccountHeadService.java+fileName+path+traversal+%28Issue+154+%2F+EUVD-2026-34998%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582171/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11467+%7C+jishenghua+jshERP+up+to+3.6+addAccountHeadAndDetail+Endpoint+AccountHeadService.java+fileName+path+traversal+%28Issue+154+%2F+EUVD-2026-34998%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11521 | Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948 Transaction Endpoint TransactionController.java improper authorization (EUVD-2026-35075)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction Endpoint. Such manipulation leads to improper authorization.

This vulnerability is referenced as CVE-2026-11521. It is possible to launch the attack remotely. Furthermore, an exploit is available.

This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

The project was informed of the problem early through an issue report but has not responded yet. ]]></description>
<link>https://tsecurity.de/de/3582170/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11521+%7C+Mohammed-eid35+bank-management-system-springboot+up+to+7b9bcc65ad7df3db29af71aed9bb500e5f24d948+Transaction+Endpoint+TransactionController.java+improper+authorization+%28EUVD-2026-35075%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582170/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11521+%7C+Mohammed-eid35+bank-management-system-springboot+up+to+7b9bcc65ad7df3db29af71aed9bb500e5f24d948+Transaction+Endpoint+TransactionController.java+improper+authorization+%28EUVD-2026-35075%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-36789 | Tenda AC1206 15.03.06.23 HTTP fromGstDhcpSetSer Password stack-based overflow (EUVD-2026-35076)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Tenda AC1206 15.03.06.23. The affected element is the function fromGstDhcpSetSer of the component HTTP Handler. Such manipulation of the argument Password leads to stack-based buffer overflow.

This vulnerability is listed as CVE-2026-36789. The attack must be carried out from within the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3582169/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36789+%7C+Tenda+AC1206+15.03.06.23+HTTP+fromGstDhcpSetSer+Password+stack-based+overflow+%28EUVD-2026-35076%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582169/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-36789+%7C+Tenda+AC1206+15.03.06.23+HTTP+fromGstDhcpSetSer+Password+stack-based+overflow+%28EUVD-2026-35076%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-43974 | ninenines gun up to 2.3.x reference behavioral workflow (EUVD-2026-35072)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in ninenines gun up to 2.3.x. Affected is the function reference. The manipulation results in enforcement of behavioral workflow.

This vulnerability is reported as CVE-2026-43974. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3582168/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43974+%7C+ninenines+gun+up+to+2.3.x+reference+behavioral+workflow+%28EUVD-2026-35072%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582168/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-43974+%7C+ninenines+gun+up+to+2.3.x+reference+behavioral+workflow+%28EUVD-2026-35072%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11466 | zilliztech deep-searcher up to 0.0.2 collection_router.py CollectionRouter.invoke kwargs access control (Issue 267 / EUVD-2026-34997)]]></title> 
<description><![CDATA[A vulnerability has been found in zilliztech deep-searcher up to 0.0.2 and classified as problematic. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls.

This vulnerability is registered as CVE-2026-11466. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The pull request to fix this issue awaits acceptance. ]]></description>
<link>https://tsecurity.de/de/3582167/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11466+%7C+zilliztech+deep-searcher+up+to+0.0.2+collection_router.py+CollectionRouter.invoke+kwargs+access+control+%28Issue+267+%2F+EUVD-2026-34997%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582167/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11466+%7C+zilliztech+deep-searcher+up+to+0.0.2+collection_router.py+CollectionRouter.invoke+kwargs+access+control+%28Issue+267+%2F+EUVD-2026-34997%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11507 | CodeAstro Leave Management System 1.0 delete_leave_type.php leave_type sql injection (EUVD-2026-35043)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection.

This vulnerability is identified as CVE-2026-11507. The attack can be executed remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582166/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11507+%7C+CodeAstro+Leave+Management+System+1.0+delete_leave_type.php+leave_type+sql+injection+%28EUVD-2026-35043%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582166/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11507+%7C+CodeAstro+Leave+Management+System+1.0+delete_leave_type.php+leave_type+sql+injection+%28EUVD-2026-35043%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11519 | SourceCodester Inventory System 1.0 Account Creation users_handler.php ROLE improper authorization (EUVD-2026-35069)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manipulation of the argument ROLE results in improper authorization.

This vulnerability was named CVE-2026-11519. The attack may be performed from remote. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582165/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11519+%7C+SourceCodester+Inventory+System+1.0+Account+Creation+users_handler.php+ROLE+improper+authorization+%28EUVD-2026-35069%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582165/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11519+%7C+SourceCodester+Inventory+System+1.0+Account+Creation+users_handler.php+ROLE+improper+authorization+%28EUVD-2026-35069%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-25558 | QloApps QloApps/within SVG files uploaded up to 1.7.0 SVG File cross site scripting (EUVD-2026-35071)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in QloApps QloApps and within SVG files uploaded up to 1.7.0. This impacts an unknown function of the component SVG File Handler. The manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2026-25558. The attack can be initiated remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3582164/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25558+%7C+QloApps+QloApps%2Fwithin+SVG+files+uploaded+up+to+1.7.0+SVG+File+cross+site+scripting+%28EUVD-2026-35071%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582164/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25558+%7C+QloApps+QloApps%2Fwithin+SVG+files+uploaded+up+to+1.7.0+SVG+File+cross+site+scripting+%28EUVD-2026-35071%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11520 | SourceCodester Inventory System 1.0 header.php cross site scripting (EUVD-2026-35070)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting.

The identification of this vulnerability is CVE-2026-11520. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

Multiple parameters might be affected. ]]></description>
<link>https://tsecurity.de/de/3582163/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11520+%7C+SourceCodester+Inventory+System+1.0+header.php+cross+site+scripting+%28EUVD-2026-35070%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582163/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11520+%7C+SourceCodester+Inventory+System+1.0+header.php+cross+site+scripting+%28EUVD-2026-35070%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11482 | SourceCodester Class and Exam Timetabling System 1.0 /archive5.php sy sql injection (EUVD-2026-35013)]]></title> 
<description><![CDATA[A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. It has been classified as critical. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection.

This vulnerability is documented as CVE-2026-11482. The attack can be initiated remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3582162/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11482+%7C+SourceCodester+Class+and+Exam+Timetabling+System+1.0+%2Farchive5.php+sy+sql+injection+%28EUVD-2026-35013%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582162/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11482+%7C+SourceCodester+Class+and+Exam+Timetabling+System+1.0+%2Farchive5.php+sy+sql+injection+%28EUVD-2026-35013%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2021-47984 | WP24 Domain Check 1.6.2 on WordPress options.php fieldnameDomain cross site scripting (Exploit 49377 / EUVD-2021-34850)]]></title> 
<description><![CDATA[A vulnerability has been found in WP24 Domain Check 1.6.2 on WordPress and classified as problematic. The affected element is an unknown function of the file options.php. The manipulation of the argument fieldnameDomain leads to cross site scripting.

This vulnerability is referenced as CVE-2021-47984. Remote exploitation of the attack is possible. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3582161/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-47984+%7C+WP24+Domain+Check+1.6.2+on+WordPress+options.php+fieldnameDomain+cross+site+scripting+%28Exploit+49377+%2F+EUVD-2021-34850%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582161/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2021-47984+%7C+WP24+Domain+Check+1.6.2+on+WordPress+options.php+fieldnameDomain+cross+site+scripting+%28Exploit+49377+%2F+EUVD-2021-34850%29/</guid>
<pubDate>Mon, 08 Jun 2026 18:38:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Make Firefox your World Cup sidekick this summer]]></title> 
<description><![CDATA[Your browser tabs say a lot about your life: work projects, vacation plans, shopping carts and all the rabbit holes in between. Add the world&rsquo;s biggest soccer tournament to the mix, and your browser is suddenly juggling scores to check, streams to watch, lineups to scan and group chats to keep up with. And since [&hellip;]
The post Make Firefox your World Cup sidekick this summer appeared first on The Mozilla Blog. ]]></description>
<link>https://tsecurity.de/de/3582038/IT+Reverse+Engineering/Tools/Make+Firefox+your+World+Cup+sidekick+this+summer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582038/IT+Reverse+Engineering/Tools/Make+Firefox+your+World+Cup+sidekick+this+summer/</guid>
<pubDate>Mon, 08 Jun 2026 17:59:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11514 | itsourcecode Hospital Management System 1.0 /addpatient.php admissiontme sql injection (EUVD-2026-35056)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection.

This vulnerability appears as CVE-2026-11514. The attack may be initiated remotely. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3581967/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11514+%7C+itsourcecode+Hospital+Management+System+1.0+%2Faddpatient.php+admissiontme+sql+injection+%28EUVD-2026-35056%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581967/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11514+%7C+itsourcecode+Hospital+Management+System+1.0+%2Faddpatient.php+admissiontme+sql+injection+%28EUVD-2026-35056%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11462 | Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22 Stripe Plugin StripeController.php callback Request improper authorization (EUVD-2026-34993)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization.

This vulnerability is identified as CVE-2026-11462. The attack can be initiated remotely. Additionally, an exploit exists.

It is suggested to install a patch to address this issue. ]]></description>
<link>https://tsecurity.de/de/3581966/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11462+%7C+Chengdu+Everbrite+Network+Technology+BeikeShop+up+to+1.6.0.22+Stripe+Plugin+StripeController.php+callback+Request+improper+authorization+%28EUVD-2026-34993%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581966/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11462+%7C+Chengdu+Everbrite+Network+Technology+BeikeShop+up+to+1.6.0.22+Stripe+Plugin+StripeController.php+callback+Request+improper+authorization+%28EUVD-2026-34993%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11513 | itsourcecode Hospital Management System 1.0 /adminaccount.php Date sql injection (EUVD-2026-35055)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection.

This vulnerability is reported as CVE-2026-11513. The attack can be launched remotely. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3581965/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11513+%7C+itsourcecode+Hospital+Management+System+1.0+%2Fadminaccount.php+Date+sql+injection+%28EUVD-2026-35055%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581965/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11513+%7C+itsourcecode+Hospital+Management+System+1.0+%2Fadminaccount.php+Date+sql+injection+%28EUVD-2026-35055%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8833 | Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4 URL Validation cross site scripting (EUVD-2026-35053)]]></title> 
<description><![CDATA[A vulnerability was found in Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4. It has been declared as problematic. This issue affects some unknown processing of the component URL Validation Handler. The manipulation results in cross site scripting.

This vulnerability is identified as CVE-2026-8833. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581964/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8833+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+URL+Validation+cross+site+scripting+%28EUVD-2026-35053%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581964/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8833+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+URL+Validation+cross+site+scripting+%28EUVD-2026-35053%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9549 | Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4 Service Discovery cross site scripting (EUVD-2026-35054)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4. This affects an unknown function of the component Service Discovery. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as CVE-2026-9549. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3581963/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9549+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+Service+Discovery+cross+site+scripting+%28EUVD-2026-35054%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581963/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9549+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+Service+Discovery+cross+site+scripting+%28EUVD-2026-35054%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11512 | itsourcecode Hospital Management System 1.0 /billing.php patientid cross site scripting (EUVD-2026-35060)]]></title> 
<description><![CDATA[A vulnerability was found in itsourcecode Hospital Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting.

This vulnerability is documented as CVE-2026-11512. The attack can be initiated remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3581962/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11512+%7C+itsourcecode+Hospital+Management+System+1.0+%2Fbilling.php+patientid+cross+site+scripting+%28EUVD-2026-35060%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581962/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11512+%7C+itsourcecode+Hospital+Management+System+1.0+%2Fbilling.php+patientid+cross+site+scripting+%28EUVD-2026-35060%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-7765 | Checkmk up to 2.5.0p4 authorization (EUVD-2026-35051)]]></title> 
<description><![CDATA[A vulnerability has been found in Checkmk up to 2.5.0p4 and classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in incorrect authorization.

This vulnerability was named CVE-2026-7765. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3581961/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-7765+%7C+Checkmk+up+to+2.5.0p4+authorization+%28EUVD-2026-35051%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581961/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-7765+%7C+Checkmk+up+to+2.5.0p4+authorization+%28EUVD-2026-35051%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-7186 | Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4 URL Dashboard Widget cross site scripting (EUVD-2026-35061)]]></title> 
<description><![CDATA[A vulnerability was found in Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4 and classified as problematic. This affects an unknown part of the component URL Dashboard Widget. Executing a manipulation can lead to cross site scripting.

The identification of this vulnerability is CVE-2026-7186. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581960/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-7186+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+URL+Dashboard+Widget+cross+site+scripting+%28EUVD-2026-35061%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581960/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-7186+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+URL+Dashboard+Widget+cross+site+scripting+%28EUVD-2026-35061%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8078 | Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4 Activate Changes Page cross site scripting (EUVD-2026-35052)]]></title> 
<description><![CDATA[A vulnerability was found in Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4. It has been classified as problematic. This vulnerability affects unknown code of the component Activate Changes Page. The manipulation leads to cross site scripting.

This vulnerability is referenced as CVE-2026-8078. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581959/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8078+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+Activate+Changes+Page+cross+site+scripting+%28EUVD-2026-35052%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581959/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8078+%7C+Checkmk+up+to+2.2.0%2F2.3.0p47%2F2.4.0p30%2F2.5.0p4+Activate+Changes+Page+cross+site+scripting+%28EUVD-2026-35052%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11577 | Keycloak on Red Hat partialImport authorization (EUVD-2026-35058)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Keycloak on Red Hat. Affected by this vulnerability is an unknown functionality of the file /admin/realms/{realm}/partialImport. Such manipulation leads to incorrect authorization.

This vulnerability is uniquely identified as CVE-2026-11577. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3581958/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11577+%7C+Keycloak+on+Red+Hat+partialImport+authorization+%28EUVD-2026-35058%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581958/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11577+%7C+Keycloak+on+Red+Hat+partialImport+authorization+%28EUVD-2026-35058%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3011 | wpzoom Recipe Card Blocks Lite Plugin up to 3.4.13 on WordPress deserialize_block_attributes summary/notes cross site scripting (EUVD-2026-35049)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in wpzoom Recipe Card Blocks Lite Plugin up to 3.4.13 on WordPress. This vulnerability affects the function WPZOOM_Helpers::deserialize_block_attributes. The manipulation of the argument summary/notes results in cross site scripting.

This vulnerability is cataloged as CVE-2026-3011. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3581957/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3011+%7C+wpzoom+Recipe+Card+Blocks+Lite+Plugin+up+to+3.4.13+on+WordPress+deserialize_block_attributes+summary%2Fnotes+cross+site+scripting+%28EUVD-2026-35049%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581957/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3011+%7C+wpzoom+Recipe+Card+Blocks+Lite+Plugin+up+to+3.4.13+on+WordPress+deserialize_block_attributes+summary%2Fnotes+cross+site+scripting+%28EUVD-2026-35049%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11511 | Bolt CMS up to 3.7.5 HTML Attribute TextType.php style HTML injection (EUVD-2026-35059)]]></title> 
<description><![CDATA[A vulnerability was found in Bolt CMS up to 3.7.5. It has been declared as problematic. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is registered as CVE-2026-11511. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The GitHub repository was archived by the owner and is now read-only. ]]></description>
<link>https://tsecurity.de/de/3581956/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11511+%7C+Bolt+CMS+up+to+3.7.5+HTML+Attribute+TextType.php+style+HTML+injection+%28EUVD-2026-35059%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581956/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11511+%7C+Bolt+CMS+up+to+3.7.5+HTML+Attribute+TextType.php+style+HTML+injection+%28EUVD-2026-35059%29/</guid>
<pubDate>Mon, 08 Jun 2026 17:31:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11515 | SourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded password (EUVD-2026-35057)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password with the input password123 leads to use of hard-coded password.

This vulnerability is traded as CVE-2026-11515. The attack may be launched remotely. Furthermore, there is an exploit available. ]]></description>
<link>https://tsecurity.de/de/3581905/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11515+%7C+SourceCodester+Barangay+Resident+Profiling+and+Information+Management+System+Password+Reset+passsword_reset.php+hard-coded+password+%28EUVD-2026-35057%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581905/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11515+%7C+SourceCodester+Barangay+Resident+Profiling+and+Information+Management+System+Password+Reset+passsword_reset.php+hard-coded+password+%28EUVD-2026-35057%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11499 | Tenda HG7HG9/HG10 300001138_en_xpon /boaform/formDOMAINBLK blkDomain stack-based overflow (EUVD-2026-35029)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK. Executing a manipulation of the argument blkDomain can lead to stack-based buffer overflow.

This vulnerability appears as CVE-2026-11499. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3581904/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11499+%7C+Tenda+HG7HG9%2FHG10+300001138_en_xpon+%2Fboaform%2FformDOMAINBLK+blkDomain+stack-based+overflow+%28EUVD-2026-35029%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581904/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11499+%7C+Tenda+HG7HG9%2FHG10+300001138_en_xpon+%2Fboaform%2FformDOMAINBLK+blkDomain+stack-based+overflow+%28EUVD-2026-35029%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11506 | CodeAstro Leave Management System 1.0 search_staff_for_deletion.php Name sql injection (EUVD-2026-35042)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection.

This vulnerability is referenced as CVE-2026-11506. Remote exploitation of the attack is possible. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3581903/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11506+%7C+CodeAstro+Leave+Management+System+1.0+search_staff_for_deletion.php+Name+sql+injection+%28EUVD-2026-35042%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581903/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11506+%7C+CodeAstro+Leave+Management+System+1.0+search_staff_for_deletion.php+Name+sql+injection+%28EUVD-2026-35042%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11509 | CodeAstro Leave Management System 1.0 search_staff_for_updation.php Name sql injection (EUVD-2026-35048)]]></title> 
<description><![CDATA[A vulnerability was found in CodeAstro Leave Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection.

This vulnerability is listed as CVE-2026-11509. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3581902/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11509+%7C+CodeAstro+Leave+Management+System+1.0+search_staff_for_updation.php+Name+sql+injection+%28EUVD-2026-35048%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581902/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11509+%7C+CodeAstro+Leave+Management+System+1.0+search_staff_for_updation.php+Name+sql+injection+%28EUVD-2026-35048%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11510 | CodeAstro Leave Management System 1.0 /admin/add_leave.php type_of_leave sql injection (EUVD-2026-35050)]]></title> 
<description><![CDATA[A vulnerability was found in CodeAstro Leave Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection.

This vulnerability is cataloged as CVE-2026-11510. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. ]]></description>
<link>https://tsecurity.de/de/3581901/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11510+%7C+CodeAstro+Leave+Management+System+1.0+%2Fadmin%2Fadd_leave.php+type_of_leave+sql+injection+%28EUVD-2026-35050%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581901/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11510+%7C+CodeAstro+Leave+Management+System+1.0+%2Fadmin%2Fadd_leave.php+type_of_leave+sql+injection+%28EUVD-2026-35050%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47430 | Apache Cordova Plugin InAppBrowser up to 6.0.0 on iOS (EUVD-2026-35041)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Apache Cordova Plugin InAppBrowser up to 6.0.0 on iOS. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to an unknown weakness.

This vulnerability is registered as CVE-2026-47430. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581900/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47430+%7C+Apache+Cordova+Plugin+InAppBrowser+up+to+6.0.0+on+iOS+%28EUVD-2026-35041%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581900/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47430+%7C+Apache+Cordova+Plugin+InAppBrowser+up+to+6.0.0+on+iOS+%28EUVD-2026-35041%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11505 | GL.iNet XE3000 4.8.x glnassys hard-coded key (EUVD-2026-35040)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key
.

The identification of this vulnerability is CVE-2026-11505. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3581899/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11505+%7C+GL.iNet+XE3000+4.8.x+glnassys+hard-coded+key+%28EUVD-2026-35040%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581899/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11505+%7C+GL.iNet+XE3000+4.8.x+glnassys+hard-coded+key+%28EUVD-2026-35040%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50751 | Check Point Quantum Security Gateway/Spark Firewalls IKEv1 Key Exchange improper authentication (EUVD-2026-35047)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Check Point Quantum Security Gateway and Spark Firewalls. Impacted is an unknown function of the component IKEv1 Key Exchange Handler. Such manipulation leads to improper authentication.

This vulnerability is documented as CVE-2026-50751. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3581898/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50751+%7C+Check+Point+Quantum+Security+Gateway%2FSpark+Firewalls+IKEv1+Key+Exchange+improper+authentication+%28EUVD-2026-35047%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581898/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50751+%7C+Check+Point+Quantum+Security+Gateway%2FSpark+Firewalls+IKEv1+Key+Exchange+improper+authentication+%28EUVD-2026-35047%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50752 | Check Point Quantum Security Gateway/Spark Firewalls certificate validation (EUVD-2026-35046)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Check Point Quantum Security Gateway and Spark Firewalls. The affected element is an unknown function. Performing a manipulation results in improper certificate validation.

This vulnerability is reported as CVE-2026-50752. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3581897/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50752+%7C+Check+Point+Quantum+Security+Gateway%2FSpark+Firewalls+certificate+validation+%28EUVD-2026-35046%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581897/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50752+%7C+Check+Point+Quantum+Security+Gateway%2FSpark+Firewalls+certificate+validation+%28EUVD-2026-35046%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11502 | JeecgBoot up to 3.9.2 Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect state redirect (Issue 9639 / EUVD-2026-35037)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This manipulation of the argument state causes open redirect.

This vulnerability is handled as CVE-2026-11502. The attack can be initiated remotely. Additionally, an exploit exists.

The project replied: &quot;After evaluation, this vulnerability has low exploitability in real-world scenarios: 1) Exploiting this vulnerability requires attackers to use social engineering techniques to induce victims to actively click on an OAuth login link constructed by the attacker; it cannot be triggered passively. 2) Third-party login (DingTalk/WeChat, etc.) is an optional feature and may not be enabled in most projects.&quot; ]]></description>
<link>https://tsecurity.de/de/3581896/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11502+%7C+JeecgBoot+up+to+3.9.2+Third-Party+Login+ThirdLoginController.java+HttpServletResponse.sendRedirect+state+redirect+%28Issue+9639+%2F+EUVD-2026-35037%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581896/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11502+%7C+JeecgBoot+up+to+3.9.2+Third-Party+Login+ThirdLoginController.java+HttpServletResponse.sendRedirect+state+redirect+%28Issue+9639+%2F+EUVD-2026-35037%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11504 | Tenda CX12L 16.03.53.12 Wi-Fi Schedule Configuration Endpoint /goform/openSchedWifi setSchedWifi schedStartTime/schedEndTime stack-based overflow (EUVD-2026-35039)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer overflow.

This vulnerability was named CVE-2026-11504. The attack may be initiated remotely. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3581895/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11504+%7C+Tenda+CX12L+16.03.53.12+Wi-Fi+Schedule+Configuration+Endpoint+%2Fgoform%2FopenSchedWifi+setSchedWifi+schedStartTime%2FschedEndTime+stack-based+overflow+%28EUVD-2026-35039%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581895/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11504+%7C+Tenda+CX12L+16.03.53.12+Wi-Fi+Schedule+Configuration+Endpoint+%2Fgoform%2FopenSchedWifi+setSchedWifi+schedStartTime%2FschedEndTime+stack-based+overflow+%28EUVD-2026-35039%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11508 | CodeAstro Leave Management System 1.0 search_staff_to_assign_pc.php Name sql injection (EUVD-2026-35045)]]></title> 
<description><![CDATA[A vulnerability has been found in CodeAstro Leave Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection.

This vulnerability is tracked as CVE-2026-11508. The attack is possible to be carried out remotely. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3581894/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11508+%7C+CodeAstro+Leave+Management+System+1.0+search_staff_to_assign_pc.php+Name+sql+injection+%28EUVD-2026-35045%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581894/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11508+%7C+CodeAstro+Leave+Management+System+1.0+search_staff_to_assign_pc.php+Name+sql+injection+%28EUVD-2026-35045%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9506 | Webkul Bagisto 2.4.1 ImageCacheController filename path traversal (CIVN-2026-0292 / EUVD-2026-35036)]]></title> 
<description><![CDATA[A vulnerability was found in Webkul Bagisto 2.4.1. It has been rated as critical. This affects an unknown part of the component ImageCacheController. The manipulation of the argument filename leads to path traversal.

This vulnerability is listed as CVE-2026-9506. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3581893/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9506+%7C+Webkul+Bagisto+2.4.1+ImageCacheController+filename+path+traversal+%28CIVN-2026-0292+%2F+EUVD-2026-35036%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581893/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9506+%7C+Webkul+Bagisto+2.4.1+ImageCacheController+filename+path+traversal+%28CIVN-2026-0292+%2F+EUVD-2026-35036%29/</guid>
<pubDate>Mon, 08 Jun 2026 16:50:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[[webapps] OpenEMR 7.0.2 - Arbitrary File Read]]></title> 
<description><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read ]]></description>
<link>https://tsecurity.de/de/3581651/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/Proof+of+Concept/%5Bwebapps%5D+OpenEMR+7.0.2+-+Arbitrary+File+Read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581651/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/Proof+of+Concept/%5Bwebapps%5D+OpenEMR+7.0.2+-+Arbitrary+File+Read/</guid>
<pubDate>Mon, 08 Jun 2026 02:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11569 | Red Hat Quay 3 Filedrop Endpoint cross site scripting (WID-SEC-2026-1816)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in Red Hat Quay 3. This issue affects some unknown processing of the component Filedrop Endpoint. This manipulation causes cross site scripting.

This vulnerability is registered as CVE-2026-11569. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3581574/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11569+%7C+Red+Hat+Quay+3+Filedrop+Endpoint+cross+site+scripting+%28WID-SEC-2026-1816%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581574/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11569+%7C+Red+Hat+Quay+3+Filedrop+Endpoint+cross+site+scripting+%28WID-SEC-2026-1816%29/</guid>
<pubDate>Mon, 08 Jun 2026 14:51:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3109 | Mattermost Plugins up to 10.11.11/11.4.x Webhook Request unusual condition]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in Mattermost Plugins up to 10.11.11/11.4.x. Affected by this issue is some unknown functionality of the component Webhook Request Handler. This manipulation causes improper check for unusual conditions.

This vulnerability is registered as CVE-2026-3109. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581490/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3109+%7C+Mattermost+Plugins+up+to+10.11.11%2F11.4.x+Webhook+Request+unusual+condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581490/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3109+%7C+Mattermost+Plugins+up+to+10.11.11%2F11.4.x+Webhook+Request+unusual+condition/</guid>
<pubDate>Mon, 08 Jun 2026 14:35:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49200 | Acer Wave 7 Router up to T7c_GBL_1.01.000055 Web Interface acer_cgi.log log file (EUVD-2026-33270)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Acer Wave 7 Router up to T7c_GBL_1.01.000055. The impacted element is an unknown function of the file acer_cgi.log of the component Web Interface. This manipulation causes sensitive information in log files.

This vulnerability is registered as CVE-2026-49200. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3581489/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49200+%7C+Acer+Wave+7+Router+up+to+T7c_GBL_1.01.000055+Web+Interface+acer_cgi.log+log+file+%28EUVD-2026-33270%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581489/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49200+%7C+Acer+Wave+7+Router+up+to+T7c_GBL_1.01.000055+Web+Interface+acer_cgi.log+log+file+%28EUVD-2026-33270%29/</guid>
<pubDate>Mon, 08 Jun 2026 14:35:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-4482 | Rapid7 Insight Agent up to 3.3.0 on Windows Certificate …/bootstrap/common/ssl permission assignment]]></title> 
<description><![CDATA[A vulnerability was found in Rapid7 Insight Agent up to 3.3.0 on Windows. It has been classified as problematic. Affected is an unknown function of the file &hellip;/bootstrap/common/ssl of the component Certificate Handler. The manipulation leads to incorrect permission assignment.

This vulnerability is referenced as CVE-2026-4482. The attack can only be performed from a local environment. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581488/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4482+%7C+Rapid7+Insight+Agent+up+to+3.3.0+on+Windows+Certificate+%E2%80%A6%2Fbootstrap%2Fcommon%2Fssl+permission+assignment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581488/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4482+%7C+Rapid7+Insight+Agent+up+to+3.3.0+on+Windows+Certificate+%E2%80%A6%2Fbootstrap%2Fcommon%2Fssl+permission+assignment/</guid>
<pubDate>Mon, 08 Jun 2026 14:35:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10800 | PaddlePaddle FastDeploy up to 2.4.1 MultimodalHasher hasher.py hash_features weak hash (Issue 7196)]]></title> 
<description><![CDATA[A vulnerability was found in PaddlePaddle FastDeploy up to 2.4.1. It has been declared as problematic. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash.

This vulnerability appears as CVE-2026-10800. The attack requires local access. There is no available exploit.

Applying a patch is advised to resolve this issue. ]]></description>
<link>https://tsecurity.de/de/3581487/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10800+%7C+PaddlePaddle+FastDeploy+up+to+2.4.1+MultimodalHasher+hasher.py+hash_features+weak+hash+%28Issue+7196%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581487/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10800+%7C+PaddlePaddle+FastDeploy+up+to+2.4.1+MultimodalHasher+hasher.py+hash_features+weak+hash+%28Issue+7196%29/</guid>
<pubDate>Mon, 08 Jun 2026 14:35:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3116 | Mattermost Plugins up to 11.4.x Webhook Endpoint resource consumption]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in Mattermost Plugins up to 11.4.x. Affected by this vulnerability is an unknown functionality of the component Webhook Endpoint. The manipulation results in resource consumption.

This vulnerability is cataloged as CVE-2026-3116. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581486/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3116+%7C+Mattermost+Plugins+up+to+11.4.x+Webhook+Endpoint+resource+consumption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581486/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3116+%7C+Mattermost+Plugins+up+to+11.4.x+Webhook+Endpoint+resource+consumption/</guid>
<pubDate>Mon, 08 Jun 2026 14:35:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-37459 | FRRouting FRR 10.0/10.6 BGP integer underflow (Nessus ID 319644)]]></title> 
<description><![CDATA[A vulnerability was found in FRRouting FRR 10.0/10.6. It has been declared as critical. This affects an unknown part of the component BGP Handler. Executing a manipulation can lead to integer underflow.

This vulnerability is handled as CVE-2026-37459. The attack can be executed remotely. There is not any exploit available.

A patch should be applied to remediate this issue. ]]></description>
<link>https://tsecurity.de/de/3581423/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-37459+%7C+FRRouting+FRR+10.0%2F10.6+BGP+integer+underflow+%28Nessus+ID+319644%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581423/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-37459+%7C+FRRouting+FRR+10.0%2F10.6+BGP+integer+underflow+%28Nessus+ID+319644%29/</guid>
<pubDate>Mon, 08 Jun 2026 14:10:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32941 | Apple iOS/iPadOS buffer overflow (EUVD-2022-36007)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Apple iOS and iPadOS. This vulnerability affects unknown code. The manipulation leads to buffer overflow.

This vulnerability is traded as CVE-2022-32941. Access to the local network is required for this attack to succeed. There is no exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581251/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32941+%7C+Apple+iOS%2FiPadOS+buffer+overflow+%28EUVD-2022-36007%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581251/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32941+%7C+Apple+iOS%2FiPadOS+buffer+overflow+%28EUVD-2022-36007%29/</guid>
<pubDate>Mon, 08 Jun 2026 12:59:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32941 | Apple macOS buffer overflow (EUVD-2022-36007)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in Apple macOS. This issue affects some unknown processing. The manipulation results in buffer overflow.

This vulnerability is known as CVE-2022-32941. Access to the local network is required for this attack. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581250/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32941+%7C+Apple+macOS+buffer+overflow+%28EUVD-2022-36007%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581250/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32941+%7C+Apple+macOS+buffer+overflow+%28EUVD-2022-36007%29/</guid>
<pubDate>Mon, 08 Jun 2026 12:59:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32942 | Apple macOS up to 13.0 DriverKit memory corruption (HT213532 / EUVD-2022-36008)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Apple macOS. Affected by this vulnerability is an unknown functionality of the component DriverKit. The manipulation results in memory corruption.

This vulnerability is cataloged as CVE-2022-32942. The attack must be initiated from a local position. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3581249/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32942+%7C+Apple+macOS+up+to+13.0+DriverKit+memory+corruption+%28HT213532+%2F+EUVD-2022-36008%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581249/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32942+%7C+Apple+macOS+up+to+13.0+DriverKit+memory+corruption+%28HT213532+%2F+EUVD-2022-36008%29/</guid>
<pubDate>Mon, 08 Jun 2026 12:59:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32943 | Apple macOS up to 13.0 Photos memory corruption (HT213532 / EUVD-2022-36009)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Apple macOS. Affected by this vulnerability is an unknown functionality of the component Photos. The manipulation leads to memory corruption.

This vulnerability is referenced as CVE-2022-32943. It is possible to launch the attack on the physical device. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581248/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32943+%7C+Apple+macOS+up+to+13.0+Photos+memory+corruption+%28HT213532+%2F+EUVD-2022-36009%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581248/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32943+%7C+Apple+macOS+up+to+13.0+Photos+memory+corruption+%28HT213532+%2F+EUVD-2022-36009%29/</guid>
<pubDate>Mon, 08 Jun 2026 12:59:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32943 | Apple iOS/iPadOS up to 16.1.2 Photos information disclosure (HT213530 / EUVD-2022-36009)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in Apple iOS and iPadOS up to 16.1.2. This affects an unknown part of the component Photos. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as CVE-2022-32943. The attack may be carried out on the physical device. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581247/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32943+%7C+Apple+iOS%2FiPadOS+up+to+16.1.2+Photos+information+disclosure+%28HT213530+%2F+EUVD-2022-36009%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581247/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32943+%7C+Apple+iOS%2FiPadOS+up+to+16.1.2+Photos+information+disclosure+%28HT213530+%2F+EUVD-2022-36009%29/</guid>
<pubDate>Mon, 08 Jun 2026 12:59:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2014-3604 | Not Yet Commons SSL up to 0.3.14 X.509 Certificates.java cryptographic issue (RHSA-2015:1888 / EUVD-2022-3600)]]></title> 
<description><![CDATA[A vulnerability was found in Not Yet Commons SSL up to 0.3.14. It has been classified as critical. Impacted is an unknown function of the file Certificates.java of the component X.509 Certificate Handler. Performing a manipulation results in cryptographic issues.

This vulnerability was named CVE-2014-3604. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581246/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2014-3604+%7C+Not+Yet+Commons+SSL+up+to+0.3.14+X.509+Certificates.java+cryptographic+issue+%28RHSA-2015%3A1888+%2F+EUVD-2022-3600%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581246/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2014-3604+%7C+Not+Yet+Commons+SSL+up+to+0.3.14+X.509+Certificates.java+cryptographic+issue+%28RHSA-2015%3A1888+%2F+EUVD-2022-3600%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:06:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32944 | Apple iOS/iPadOS Kernel memory corruption (EUVD-2022-36010)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Apple iOS and iPadOS. This vulnerability affects unknown code of the component Kernel. This manipulation causes memory corruption.

This vulnerability appears as CVE-2022-32944. The attack requires local access. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581245/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+iOS%2FiPadOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581245/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+iOS%2FiPadOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:06:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32944 | Apple tvOS Kernel memory corruption (EUVD-2022-36010)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Apple tvOS. This issue affects some unknown processing of the component Kernel. Such manipulation leads to memory corruption.

This vulnerability is traded as CVE-2022-32944. An attack has to be approached locally. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3581244/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+tvOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581244/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+tvOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:06:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32944 | Apple watchOS Kernel memory corruption (EUVD-2022-36010)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Apple watchOS. Impacted is an unknown function of the component Kernel. Performing a manipulation results in memory corruption.

This vulnerability is known as CVE-2022-32944. Attacking locally is a requirement. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581243/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+watchOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581243/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+watchOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:06:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32944 | Apple macOS Kernel memory corruption (EUVD-2022-36010)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Apple macOS. The affected element is an unknown function of the component Kernel. Executing a manipulation can lead to memory corruption.

This vulnerability is handled as CVE-2022-32944. It is possible to launch the attack on the local host. There is not any exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581242/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+macOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581242/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32944+%7C+Apple+macOS+Kernel+memory+corruption+%28EUVD-2022-36010%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:06:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-32945 | Apple macOS App access control (HT213488 / EUVD-2022-36011)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Apple macOS. This affects an unknown function of the component App Handler. Executing a manipulation can lead to improper access controls.

This vulnerability appears as CVE-2022-32945. The attack requires local access. There is no available exploit.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3581241/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32945+%7C+Apple+macOS+App+access+control+%28HT213488+%2F+EUVD-2022-36011%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581241/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-32945+%7C+Apple+macOS+App+access+control+%28HT213488+%2F+EUVD-2022-36011%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:06:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.10.4]]></title> 
<description><![CDATA[chore: bump version to 15.10.4 ]]></description>
<link>https://tsecurity.de/de/3581143/IT+Reverse+Engineering/Tools/v15.10.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581143/IT+Reverse+Engineering/Tools/v15.10.4/</guid>
<pubDate>Mon, 08 Jun 2026 12:27:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11286 | Google Chrome up to 148.0.7778.216 Wallet clickjacking (ID 502110 / Nessus ID 319276)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Wallet. The manipulation results in clickjacking.

This vulnerability was named CVE-2026-11286. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581025/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11286+%7C+Google+Chrome+up+to+148.0.7778.216+Wallet+clickjacking+%28ID+502110+%2F+Nessus+ID+319276%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581025/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11286+%7C+Google+Chrome+up+to+148.0.7778.216+Wallet+clickjacking+%28ID+502110+%2F+Nessus+ID+319276%29/</guid>
<pubDate>Mon, 08 Jun 2026 11:24:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11224 | Google Chrome up to 148.0.7778.216 on Linux Chromoting use after free (ID 502461 / Nessus ID 319274)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Google Chrome on Linux. The impacted element is an unknown function of the component Chromoting. The manipulation results in use after free.

This vulnerability is known as CVE-2026-11224. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3581024/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11224+%7C+Google+Chrome+up+to+148.0.7778.216+on+Linux+Chromoting+use+after+free+%28ID+502461+%2F+Nessus+ID+319274%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581024/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11224+%7C+Google+Chrome+up+to+148.0.7778.216+on+Linux+Chromoting+use+after+free+%28ID+502461+%2F+Nessus+ID+319274%29/</guid>
<pubDate>Mon, 08 Jun 2026 11:24:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50206 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 Config os command injection]]></title> 
<description><![CDATA[A vulnerability was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. It has been rated as critical. This affects an unknown function of the component Config Handler. Performing a manipulation results in os command injection.

This vulnerability is reported as CVE-2026-50206. The attacker must have access to the local network to execute the attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3581023/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50206+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Config+os+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581023/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50206+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Config+os+command+injection/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49191 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 improper authentication]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. Affected by this vulnerability is an unknown functionality. This manipulation causes improper authentication.

The identification of this vulnerability is CVE-2026-49191. It is possible to initiate the attack remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3581022/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49191+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+improper+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581022/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49191+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+improper+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49190 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 os command injection]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. Affected is an unknown function. The manipulation results in os command injection.

This vulnerability was named CVE-2026-49190. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3581021/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49190+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+os+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581021/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49190+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+os+command+injection/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49203 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 API Endpoint improper authentication]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. This affects an unknown part of the component API Endpoint. Performing a manipulation results in improper authentication.

This vulnerability is identified as CVE-2026-49203. The attack can only be performed from the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3581020/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49203+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+API+Endpoint+improper+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581020/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49203+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+API+Endpoint+improper+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49193 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 Setting information disclosure]]></title> 
<description><![CDATA[A vulnerability has been found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 and classified as critical. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to information disclosure.

This vulnerability is listed as CVE-2026-49193. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3581019/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49193+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Setting+information+disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581019/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49193+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Setting+information+disclosure/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49202 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 improper authentication]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. Affected by this issue is some unknown functionality. Such manipulation leads to improper authentication.

This vulnerability is referenced as CVE-2026-49202. It is possible to launch the attack remotely. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3581018/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49202+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+improper+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581018/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49202+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+improper+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49194 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 improper authentication]]></title> 
<description><![CDATA[A vulnerability was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 and classified as critical. Impacted is an unknown function. The manipulation results in improper authentication.

This vulnerability is cataloged as CVE-2026-49194. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3581017/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49194+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+improper+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581017/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49194+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+improper+authentication/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49192 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 Summary Service Endpoint authorization]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. This vulnerability affects unknown code of the component Summary Service Endpoint. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as CVE-2026-49192. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3581016/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49192+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Summary+Service+Endpoint+authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581016/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49192+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+Summary+Service+Endpoint+authorization/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50205 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 log file]]></title> 
<description><![CDATA[A vulnerability was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. It has been declared as critical. The impacted element is an unknown function. Such manipulation leads to sensitive information in log files.

This vulnerability is documented as CVE-2026-50205. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3581015/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50205+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+log+file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581015/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-50205+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+log+file/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49204 | Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019 hard-coded credentials]]></title> 
<description><![CDATA[A vulnerability was found in Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019. It has been classified as critical. The affected element is an unknown function. This manipulation causes hard-coded credentials.

This vulnerability is registered as CVE-2026-49204. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3581014/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49204+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+hard-coded+credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581014/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49204+%7C+Acer+Connect+M6E+5G+Portable+WiFi+Router+up+to+M6E_AI_1.00.000019+hard-coded+credentials/</guid>
<pubDate>Mon, 08 Jun 2026 11:40:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11500 | Weaviate up to 1.37.7 Static API Key client.go validateConfig StaticApiKey authorization (Issue 11392)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass.

This vulnerability is traded as CVE-2026-11500. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3580953/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11500+%7C+Weaviate+up+to+1.37.7+Static+API+Key+client.go+validateConfig+StaticApiKey+authorization+%28Issue+11392%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580953/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11500+%7C+Weaviate+up+to+1.37.7+Static+API+Key+client.go+validateConfig+StaticApiKey+authorization+%28Issue+11392%29/</guid>
<pubDate>Mon, 08 Jun 2026 10:55:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8889 | Securly Chrome Extension up to 3.0.7 weak hash]]></title> 
<description><![CDATA[A vulnerability has been found in Securly Chrome Extension up to 3.0.7 and classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in use of weak hash.

This vulnerability is reported as CVE-2026-8889. The attacker must have access to the local network to execute the attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3580776/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8889+%7C+Securly+Chrome+Extension+up+to+3.0.7+weak+hash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580776/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8889+%7C+Securly+Chrome+Extension+up+to+3.0.7+weak+hash/</guid>
<pubDate>Mon, 08 Jun 2026 09:57:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8888 | Securly Chrome Extension up to 3.0.7 Regular Expression RegExp redos]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in Securly Chrome Extension up to 3.0.7. Affected is the function RegExp of the component Regular Expression Handler. The manipulation leads to inefficient regular expression complexity.

This vulnerability is listed as CVE-2026-8888. The attack must be carried out from within the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3580775/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8888+%7C+Securly+Chrome+Extension+up+to+3.0.7+Regular+Expression+RegExp+redos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580775/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8888+%7C+Securly+Chrome+Extension+up+to+3.0.7+Regular+Expression+RegExp+redos/</guid>
<pubDate>Mon, 08 Jun 2026 09:57:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-40495 | FOSSBilling up to 0.7.x API Endpoint hide_version_public information disclosure (GHSA-gqcp-g7rm-p5v6)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in FOSSBilling up to 0.7.x. This impacts an unknown function of the component API Endpoint. Performing a manipulation of the argument hide_version_public results in information disclosure.

This vulnerability was named CVE-2026-40495. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3580774/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-40495+%7C+FOSSBilling+up+to+0.7.x+API+Endpoint+hide_version_public+information+disclosure+%28GHSA-gqcp-g7rm-p5v6%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580774/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-40495+%7C+FOSSBilling+up+to+0.7.x+API+Endpoint+hide_version_public+information+disclosure+%28GHSA-gqcp-g7rm-p5v6%29/</guid>
<pubDate>Mon, 08 Jun 2026 09:57:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10766 | mlrun up to 1.12.0-rc3 DataFrame Hash mlrun/utils/helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash (Issue 9691)]]></title> 
<description><![CDATA[A vulnerability was found in mlrun up to 1.12.0-rc3. It has been classified as problematic. This impacts the function mlrun.utils.helpers.calculate_dataframe_hash of the file mlrun/utils/helpers.py of the component DataFrame Hash Handler. The manipulation leads to use of weak hash.

This vulnerability is referenced as CVE-2026-10766. The attack can only be performed from a local environment. Furthermore, an exploit is available.

The pull request to fix this issue awaits acceptance. ]]></description>
<link>https://tsecurity.de/de/3580773/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10766+%7C+mlrun+up+to+1.12.0-rc3+DataFrame+Hash+mlrun%2Futils%2Fhelpers.py+mlrun.utils.helpers.calculate_dataframe_hash+weak+hash+%28Issue+9691%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580773/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10766+%7C+mlrun+up+to+1.12.0-rc3+DataFrame+Hash+mlrun%2Futils%2Fhelpers.py+mlrun.utils.helpers.calculate_dataframe_hash+weak+hash+%28Issue+9691%29/</guid>
<pubDate>Mon, 08 Jun 2026 09:57:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[/r/ReverseEngineering's Weekly Questions Thread]]></title> 
<description><![CDATA[To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the Reverse Engineering StackExchange. See also /r/AskReverseEngineering.    submitted by    /u/AutoModerator   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3580772/IT+Reverse+Engineering/%2Fr%2FReverseEngineering%27s+Weekly+Questions+Thread/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580772/IT+Reverse+Engineering/%2Fr%2FReverseEngineering%27s+Weekly+Questions+Thread/</guid>
<pubDate>Mon, 08 Jun 2026 09:00:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.10.3]]></title> 
<description><![CDATA[test(coding-agent): realigned stale tests with intentional behavior c&hellip; ]]></description>
<link>https://tsecurity.de/de/3580498/IT+Reverse+Engineering/Tools/v15.10.3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580498/IT+Reverse+Engineering/Tools/v15.10.3/</guid>
<pubDate>Mon, 08 Jun 2026 07:17:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8874 | Securly Chrome Extension up to 3.0.6 Fetch API cleartext transmission]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Securly Chrome Extension up to 3.0.6. This impacts an unknown function of the component Fetch API. The manipulation leads to cleartext transmission of sensitive information.

This vulnerability is documented as CVE-2026-8874. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3580420/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8874+%7C+Securly+Chrome+Extension+up+to+3.0.6+Fetch+API+cleartext+transmission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580420/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8874+%7C+Securly+Chrome+Extension+up+to+3.0.6+Fetch+API+cleartext+transmission/</guid>
<pubDate>Mon, 08 Jun 2026 05:45:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45702 | OP-TEE optee_os up to 4.10.x type confusion (GHSA-86pj-8xgw-66p5)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in OP-TEE optee_os up to 4.10.x. This affects an unknown part. Executing a manipulation can lead to type confusion.

The identification of this vulnerability is CVE-2026-45702. The attack can only be executed locally. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3580419/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45702+%7C+OP-TEE+optee_os+up+to+4.10.x+type+confusion+%28GHSA-86pj-8xgw-66p5%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580419/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45702+%7C+OP-TEE+optee_os+up+to+4.10.x+type+confusion+%28GHSA-86pj-8xgw-66p5%29/</guid>
<pubDate>Mon, 08 Jun 2026 05:45:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-26378 | Koha up to 25.11 Invoice Feature cross site scripting]]></title> 
<description><![CDATA[A vulnerability was found in Koha up to 25.11. It has been classified as problematic. Impacted is an unknown function of the component Invoice Feature. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2026-26378. It is possible to initiate the attack remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3580418/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-26378+%7C+Koha+up+to+25.11+Invoice+Feature+cross+site+scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580418/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-26378+%7C+Koha+up+to+25.11+Invoice+Feature+cross+site+scripting/</guid>
<pubDate>Mon, 08 Jun 2026 05:45:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-26379 | Koha up to 25.11 Configuration server-side request forgery]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Koha up to 25.11. Impacted is an unknown function of the component Configuration Handler. The manipulation results in server-side request forgery.

This vulnerability was named CVE-2026-26379. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3580417/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-26379+%7C+Koha+up+to+25.11+Configuration+server-side+request+forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580417/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-26379+%7C+Koha+up+to+25.11+Configuration+server-side+request+forgery/</guid>
<pubDate>Mon, 08 Jun 2026 05:45:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8881 | Securly Chrome Extension up to 3.0.7 weak password hash]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Securly Chrome Extension up to 3.0.7. This affects an unknown function. Performing a manipulation results in password hash with insufficient computational effort.

This vulnerability is identified as CVE-2026-8881. The attack can only be performed from the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3580416/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8881+%7C+Securly+Chrome+Extension+up+to+3.0.7+weak+password+hash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580416/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8881+%7C+Securly+Chrome+Extension+up+to+3.0.7+weak+password+hash/</guid>
<pubDate>Mon, 08 Jun 2026 05:45:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8879 | Securly Chrome Extension up to 3.0.7 content13.min.js chrome.scripting.registerContentScripts inclusion of functionality from untrusted control sphere]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Securly Chrome Extension up to 3.0.7. Affected by this issue is the function chrome.scripting.registerContentScripts of the file content13.min.js. This manipulation causes inclusion of functionality from untrusted control sphere.

This vulnerability is registered as CVE-2026-8879. The attack requires access to the local network. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3580415/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8879+%7C+Securly+Chrome+Extension+up+to+3.0.7+content13.min.js+chrome.scripting.registerContentScripts+inclusion+of+functionality+from+untrusted+control+sphere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580415/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8879+%7C+Securly+Chrome+Extension+up+to+3.0.7+content13.min.js+chrome.scripting.registerContentScripts+inclusion+of+functionality+from+untrusted+control+sphere/</guid>
<pubDate>Mon, 08 Jun 2026 05:45:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11476 | Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a Profile Update Endpoint AdminController.php edit-admin isadmin improper authorization (EUVD-2026-35007)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The manipulation of the argument isadmin leads to improper authorization.

This vulnerability is referenced as CVE-2026-11476. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

The project was informed of the problem early through an issue report but has not responded yet. ]]></description>
<link>https://tsecurity.de/de/3580381/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11476+%7C+Kushan2k+student-management-system+up+to+f16a4ceaddd6729c4b306ed4641cda3176c1ef2a+Profile+Update+Endpoint+AdminController.php+edit-admin+isadmin+improper+authorization+%28EUVD-2026-35007%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580381/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11476+%7C+Kushan2k+student-management-system+up+to+f16a4ceaddd6729c4b306ed4641cda3176c1ef2a+Profile+Update+Endpoint+AdminController.php+edit-admin+isadmin+improper+authorization+%28EUVD-2026-35007%29/</guid>
<pubDate>Mon, 08 Jun 2026 05:23:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11477 | hs-web hsweb-framework up to 5.0.1 OAuth2 Client OAuth2Client.java OAuth2Client redirect (Issue 354 / EUVD-2026-35008)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open redirect.

This vulnerability is identified as CVE-2026-11477. The attack can be executed remotely. Additionally, an exploit exists.

Applying a patch is advised to resolve this issue. ]]></description>
<link>https://tsecurity.de/de/3580380/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11477+%7C+hs-web+hsweb-framework+up+to+5.0.1+OAuth2+Client+OAuth2Client.java+OAuth2Client+redirect+%28Issue+354+%2F+EUVD-2026-35008%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580380/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11477+%7C+hs-web+hsweb-framework+up+to+5.0.1+OAuth2+Client+OAuth2Client.java+OAuth2Client+redirect+%28Issue+354+%2F+EUVD-2026-35008%29/</guid>
<pubDate>Mon, 08 Jun 2026 05:23:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11471 | SourceCodester Class and Exam Timetabling System 1.0 /index2.php Password sql injection (EUVD-2026-35002)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection.

This vulnerability is known as CVE-2026-11471. It is possible to launch the attack remotely. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3580379/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11471+%7C+SourceCodester+Class+and+Exam+Timetabling+System+1.0+%2Findex2.php+Password+sql+injection+%28EUVD-2026-35002%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580379/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11471+%7C+SourceCodester+Class+and+Exam+Timetabling+System+1.0+%2Findex2.php+Password+sql+injection+%28EUVD-2026-35002%29/</guid>
<pubDate>Mon, 08 Jun 2026 05:23:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11472 | SourceCodester Class and Exam Timetabling System 1.0 /index1.php Password sql injection (EUVD-2026-35003)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection.

This vulnerability is handled as CVE-2026-11472. The attack can be initiated remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3580378/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11472+%7C+SourceCodester+Class+and+Exam+Timetabling+System+1.0+%2Findex1.php+Password+sql+injection+%28EUVD-2026-35003%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580378/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11472+%7C+SourceCodester+Class+and+Exam+Timetabling+System+1.0+%2Findex1.php+Password+sql+injection+%28EUVD-2026-35003%29/</guid>
<pubDate>Mon, 08 Jun 2026 05:23:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11473 | jflyfox jfinal_cms up to 5.1.0 AdvicefeedbackController.java list orderBy sql injection (Issue 62 / EUVD-2026-35004)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in jflyfox jfinal_cms up to 5.1.0. This impacts the function list of the file AdvicefeedbackController.java. Such manipulation of the argument orderBy leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-11473. The attack can be launched remotely. No exploit exists.

The project was informed of the problem early through an issue report but has not responded yet. ]]></description>
<link>https://tsecurity.de/de/3580377/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11473+%7C+jflyfox+jfinal_cms+up+to+5.1.0+AdvicefeedbackController.java+list+orderBy+sql+injection+%28Issue+62+%2F+EUVD-2026-35004%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580377/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11473+%7C+jflyfox+jfinal_cms+up+to+5.1.0+AdvicefeedbackController.java+list+orderBy+sql+injection+%28Issue+62+%2F+EUVD-2026-35004%29/</guid>
<pubDate>Mon, 08 Jun 2026 05:23:20 +0200</pubDate>
</item>
</channel> 
</rss>
<!-- Generated in 0,44ms -->