<?xml version="1.0" encoding="UTF-8" ?> 
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom"> 
<channel> 
<title><![CDATA[Team IT Security - 🕵️ Sicherheitslücken]]></title> 
<link><![CDATA[https://tsecurity.de/feed.php?typ=9&q=]]></link> 
<description><![CDATA[Reverse Engineering ist die Kunst, technologische Produkte oder Systeme rückwärts zu analysieren, um ihre Funktionen, Komponenten und Herstellungsverfahren zu verstehen. Reverse Engineering kann sowohl für Innovation und Wettbewerb als auch für Sicherheit und Schutz eingesetzt werden. Auf tsecurity.de finden Sie aktuelle Informationen und Ressourcen zu Reverse Engineering, wie z. B.:  Die besten Reverse-Engineering-Tools für Sicherheitsexperten Die rechtlichen Aspekte von Reverse Engineering Die Anwendung von Reverse Engineering in verschiedenen Branchen und Disziplinen Die Vorteile und Herausforderungen von Reverse Engineering  Besuchen Sie tsecurity.de und lernen Sie, wie Sie Reverse Engineering effektiv nutzen können.]]></description>
<copyright>2026</copyright>
<atom:link href="https://tsecurity.de/feed.php?typ=9&amp;q=_" rel="self" type="application/rss+xml" />
<item> 
<title><![CDATA[CVE-2025-15104 | Validator.nu Nu Html Checker 127.0.0.1 server-side request forgery (Nessus ID 320966)]]></title> 
<description><![CDATA[A vulnerability was found in Validator.nu Nu Html Checker 127.0.0.1. It has been declared as critical. This vulnerability affects unknown code. Such manipulation leads to server-side request forgery.

This vulnerability is traded as CVE-2025-15104. The attack may be launched remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3597002/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-15104+%7C+Validator.nu+Nu+Html+Checker+127.0.0.1+server-side+request+forgery+%28Nessus+ID+320966%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597002/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-15104+%7C+Validator.nu+Nu+Html+Checker+127.0.0.1+server-side+request+forgery+%28Nessus+ID+320966%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:22:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11679 | Google Chrome up to 149.0.7827.53 on Windows Codecs use after free (ID 516997 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Google Chrome on Windows. Affected is an unknown function of the component Codecs. Performing a manipulation results in use after free.

This vulnerability is reported as CVE-2026-11679. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3597001/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11679+%7C+Google+Chrome+up+to+149.0.7827.53+on+Windows+Codecs+use+after+free+%28ID+516997+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597001/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11679+%7C+Google+Chrome+up+to+149.0.7827.53+on+Windows+Codecs+use+after+free+%28ID+516997+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:22:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11678 | Google Chrome up to 149.0.7827.53 libyuv external control of assumed-immutable web parameter (ID 516986 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Google Chrome. This impacts an unknown function of the component libyuv. Such manipulation leads to external control of assumed-immutable web parameter.

This vulnerability is documented as CVE-2026-11678. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3597000/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11678+%7C+Google+Chrome+up+to+149.0.7827.53+libyuv+external+control+of+assumed-immutable+web+parameter+%28ID+516986+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597000/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11678+%7C+Google+Chrome+up+to+149.0.7827.53+libyuv+external+control+of+assumed-immutable+web+parameter+%28ID+516986+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:22:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-26125 | IObit Malware Fighter 12.1.0 IMFForceDelete Driver privilege escalation (EUVD-2025-6530)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in IObit Malware Fighter 12.1.0. This vulnerability affects unknown code of the component IMFForceDelete Driver. Executing a manipulation can lead to privilege escalation.

This vulnerability is tracked as CVE-2025-26125. The attack is only possible within the local network. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596999/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-26125+%7C+IObit+Malware+Fighter+12.1.0+IMFForceDelete+Driver+privilege+escalation+%28EUVD-2025-6530%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596999/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-26125+%7C+IObit+Malware+Fighter+12.1.0+IMFForceDelete+Driver+privilege+escalation+%28EUVD-2025-6530%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:48:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35052 | OTFCC 617837b otfccdump+0x6b84b1 heap-based overflow (EUVD-2022-37950)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in OTFCC 617837b. This affects an unknown function of the file /release-x64/otfccdump+0x6b84b1. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is handled as CVE-2022-35052. The attack can only be done within the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596969/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35052+%7C+OTFCC+617837b+otfccdump%2B0x6b84b1+heap-based+overflow+%28EUVD-2022-37950%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596969/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35052+%7C+OTFCC+617837b+otfccdump%2B0x6b84b1+heap-based+overflow+%28EUVD-2022-37950%29/</guid>
<pubDate>Sun, 14 Jun 2026 12:59:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35053 | OTFCC 617837b otfccdump+0x61731f heap-based overflow (EUVD-2022-37951)]]></title> 
<description><![CDATA[A vulnerability has been found in OTFCC 617837b and classified as critical. This impacts an unknown function of the file /release-x64/otfccdump+0x61731f. The manipulation leads to heap-based buffer overflow.

This vulnerability is uniquely identified as CVE-2022-35053. The attack can only be initiated within the local network. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596968/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35053+%7C+OTFCC+617837b+otfccdump%2B0x61731f+heap-based+overflow+%28EUVD-2022-37951%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596968/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35053+%7C+OTFCC+617837b+otfccdump%2B0x61731f+heap-based+overflow+%28EUVD-2022-37951%29/</guid>
<pubDate>Sun, 14 Jun 2026 12:59:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35054 | OTFCC 617837b otfccdump+0x6171b2 heap-based overflow (EUVD-2022-37952)]]></title> 
<description><![CDATA[A vulnerability was found in OTFCC 617837b and classified as critical. Affected is an unknown function of the file /release-x64/otfccdump+0x6171b2. The manipulation results in heap-based buffer overflow.

This vulnerability was named CVE-2022-35054. The attack needs to be approached within the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596967/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35054+%7C+OTFCC+617837b+otfccdump%2B0x6171b2+heap-based+overflow+%28EUVD-2022-37952%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596967/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35054+%7C+OTFCC+617837b+otfccdump%2B0x6171b2+heap-based+overflow+%28EUVD-2022-37952%29/</guid>
<pubDate>Sun, 14 Jun 2026 12:59:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35055 | OTFCC 617837b otfccdump+0x6c0473 heap-based overflow (EUVD-2022-37953)]]></title> 
<description><![CDATA[A vulnerability was found in OTFCC 617837b. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /release-x64/otfccdump+0x6c0473. This manipulation causes heap-based buffer overflow.

The identification of this vulnerability is CVE-2022-35055. The attack needs to be done within the local network. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596966/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35055+%7C+OTFCC+617837b+otfccdump%2B0x6c0473+heap-based+overflow+%28EUVD-2022-37953%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596966/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35055+%7C+OTFCC+617837b+otfccdump%2B0x6c0473+heap-based+overflow+%28EUVD-2022-37953%29/</guid>
<pubDate>Sun, 14 Jun 2026 12:59:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35056 | OTFCC 617837b otfccdump+0x6b0478 heap-based overflow (EUVD-2022-37954)]]></title> 
<description><![CDATA[A vulnerability was found in OTFCC 617837b. It has been declared as critical. Affected by this issue is some unknown functionality of the file /release-x64/otfccdump+0x6b0478. Such manipulation leads to heap-based buffer overflow.

This vulnerability is referenced as CVE-2022-35056. The attack needs to be initiated within the local network. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596965/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35056+%7C+OTFCC+617837b+otfccdump%2B0x6b0478+heap-based+overflow+%28EUVD-2022-37954%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596965/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35056+%7C+OTFCC+617837b+otfccdump%2B0x6b0478+heap-based+overflow+%28EUVD-2022-37954%29/</guid>
<pubDate>Sun, 14 Jun 2026 12:59:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35058 | OTFCC 617837b otfccdump+0x6b05ce heap-based overflow (EUVD-2022-37956 / Nessus ID 259362)]]></title> 
<description><![CDATA[A vulnerability was found in OTFCC 617837b. It has been rated as critical. This affects an unknown part of the file /release-x64/otfccdump+0x6b05ce. Performing a manipulation results in heap-based buffer overflow.

This vulnerability is identified as CVE-2022-35058. The attack can only be performed from the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596964/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35058+%7C+OTFCC+617837b+otfccdump%2B0x6b05ce+heap-based+overflow+%28EUVD-2022-37956+%2F+Nessus+ID+259362%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596964/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35058+%7C+OTFCC+617837b+otfccdump%2B0x6b05ce+heap-based+overflow+%28EUVD-2022-37956+%2F+Nessus+ID+259362%29/</guid>
<pubDate>Sun, 14 Jun 2026 12:59:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35081 | SWFTools 772e55a2 /src/png2swf.c png_read_header heap-based overflow (Issue 183 / EUVD-2022-37979)]]></title> 
<description><![CDATA[A vulnerability was found in SWFTools 772e55a2. It has been declared as critical. Impacted is the function png_read_header of the file /src/png2swf.c. Such manipulation leads to heap-based buffer overflow.

This vulnerability is documented as CVE-2022-35081. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596963/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35081+%7C+SWFTools+772e55a2+%2Fsrc%2Fpng2swf.c+png_read_header+heap-based+overflow+%28Issue+183+%2F+EUVD-2022-37979%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596963/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35081+%7C+SWFTools+772e55a2+%2Fsrc%2Fpng2swf.c+png_read_header+heap-based+overflow+%28Issue+183+%2F+EUVD-2022-37979%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:14:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35080 | SWFTools 772e55a2 /lib/png.c png_load heap-based overflow (Issue 183 / EUVD-2022-37978)]]></title> 
<description><![CDATA[A vulnerability was found in SWFTools 772e55a2. It has been classified as critical. This issue affects the function png_load in the library /lib/png.c. This manipulation causes heap-based buffer overflow.

This vulnerability is registered as CVE-2022-35080. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596962/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35080+%7C+SWFTools+772e55a2+%2Flib%2Fpng.c+png_load+heap-based+overflow+%28Issue+183+%2F+EUVD-2022-37978%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596962/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35080+%7C+SWFTools+772e55a2+%2Flib%2Fpng.c+png_load+heap-based+overflow+%28Issue+183+%2F+EUVD-2022-37978%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:14:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35135 | Boodskap IoT Platform 4.4.9-02 Request /api/user/upsert/ access control (EUVD-2022-38032)]]></title> 
<description><![CDATA[A vulnerability was found in Boodskap IoT Platform 4.4.9-02. It has been rated as critical. This issue affects some unknown processing of the file /api/user/upsert/ of the component Request Handler. Performing a manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2022-35135. The attack must originate from the local network. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596961/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35135+%7C+Boodskap+IoT+Platform+4.4.9-02+Request+%2Fapi%2Fuser%2Fupsert%2F%26lt%3Buuid%26gt%3B+access+control+%28EUVD-2022-38032%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596961/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35135+%7C+Boodskap+IoT+Platform+4.4.9-02+Request+%2Fapi%2Fuser%2Fupsert%2F%26lt%3Buuid%26gt%3B+access+control+%28EUVD-2022-38032%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:14:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35134 | Boodskap IoT Platform 4.4.9-02 cross site scripting (EUVD-2022-38031)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in Boodskap IoT Platform 4.4.9-02. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as CVE-2022-35134. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596960/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35134+%7C+Boodskap+IoT+Platform+4.4.9-02+cross+site+scripting+%28EUVD-2022-38031%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596960/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35134+%7C+Boodskap+IoT+Platform+4.4.9-02+cross+site+scripting+%28EUVD-2022-38031%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:14:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35132 | Usermin up to 1.850 GPG Module os command injection (EUVD-2022-38029)]]></title> 
<description><![CDATA[A vulnerability was found in Usermin up to 1.850 and classified as critical. This impacts an unknown function of the component GPG Module. Executing a manipulation can lead to os command injection.

This vulnerability appears as CVE-2022-35132. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596959/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35132+%7C+Usermin+up+to+1.850+GPG+Module+os+command+injection+%28EUVD-2022-38029%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596959/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35132+%7C+Usermin+up+to+1.850+GPG+Module+os+command+injection+%28EUVD-2022-38029%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:14:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35120 | IXP EasyInstall 6.6.14725 access control (EUVD-2022-38018)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in IXP EasyInstall 6.6.14725. Affected is an unknown function. Such manipulation leads to improper access controls.

This vulnerability is traded as CVE-2022-35120. Access to the local network is required for this attack to succeed. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596958/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35120+%7C+IXP+EasyInstall+6.6.14725+access+control+%28EUVD-2022-38018%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596958/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35120+%7C+IXP+EasyInstall+6.6.14725+access+control+%28EUVD-2022-38018%29/</guid>
<pubDate>Sun, 14 Jun 2026 13:14:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46306 | Linux Kernel up to 7.0.6 flow_dissector infinite loop]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 6.1.174/6.6.139/6.12.87/6.18.29/7.0.6. This affects an unknown function of the component flow_dissector. The manipulation results in infinite loop.

This vulnerability is cataloged as CVE-2026-46306. The attack must originate from the local network. There is no exploit available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596839/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46306+%7C+Linux+Kernel+up+to+7.0.6+flow_dissector+infinite+loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596839/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46306+%7C+Linux+Kernel+up+to+7.0.6+flow_dissector+infinite+loop/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46299 | Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6 hfsplus hfsplus_fill_super max_unistr_len stack-based overflow]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6. It has been declared as critical. Impacted is the function hfsplus_fill_super of the component hfsplus. Such manipulation of the argument max_unistr_len leads to stack-based buffer overflow.

This vulnerability is uniquely identified as CVE-2026-46299. The attack can only be initiated within the local network. No exploit exists.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596838/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46299+%7C+Linux+Kernel+up+to+6.6.139%2F6.12.87%2F6.18.29%2F7.0.6+hfsplus+hfsplus_fill_super+max_unistr_len+stack-based+overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596838/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46299+%7C+Linux+Kernel+up+to+6.6.139%2F6.12.87%2F6.18.29%2F7.0.6+hfsplus+hfsplus_fill_super+max_unistr_len+stack-based+overflow/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46289 | Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6 lib extract_iter_to_sg memory leak]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 6.6.139/6.12.87/6.18.29/7.0.6. Affected is the function extract_iter_to_sg of the component lib. This manipulation causes memory leak.

This vulnerability is tracked as CVE-2026-46289. The attack is only possible within the local network. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596837/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46289+%7C+Linux+Kernel+up+to+6.6.139%2F6.12.87%2F6.18.29%2F7.0.6+lib+extract_iter_to_sg+memory+leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596837/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46289+%7C+Linux+Kernel+up+to+6.6.139%2F6.12.87%2F6.18.29%2F7.0.6+lib+extract_iter_to_sg+memory+leak/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46304 | Linux Kernel up to 7.1-rc1 nvmet nvmet_tcp_release_queue_work async_event_work deadlock]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Linux Kernel up to 7.1-rc1. Affected by this issue is the function nvmet_tcp_release_queue_work of the component nvmet. Performing a manipulation of the argument async_event_work results in deadlock.

This vulnerability is cataloged as CVE-2026-46304. The attack must originate from the local network. There is no exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596836/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46304+%7C+Linux+Kernel+up+to+7.1-rc1+nvmet+nvmet_tcp_release_queue_work+async_event_work+deadlock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596836/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46304+%7C+Linux+Kernel+up+to+7.1-rc1+nvmet+nvmet_tcp_release_queue_work+async_event_work+deadlock/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46307 | Linux Kernel up to 7.1-rc2 wifi base.c __ubsan_handle_out_of_bounds.cold+0x46/0x4b ts_final_idx out-of-bounds write]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.1-rc2. The affected element is the function __ubsan_handle_out_of_bounds.cold+0x46/0x4b of the file drivers/net/wireless/ath/ath5k/base.c of the component wifi. This manipulation of the argument ts_final_idx causes out-of-bounds write.

This vulnerability is registered as CVE-2026-46307. The attack requires access to the local network. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596835/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46307+%7C+Linux+Kernel+up+to+7.1-rc2+wifi+base.c+__ubsan_handle_out_of_bounds.cold%2B0x46%2F0x4b+ts_final_idx+out-of-bounds+write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596835/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46307+%7C+Linux+Kernel+up+to+7.1-rc2+wifi+base.c+__ubsan_handle_out_of_bounds.cold%2B0x46%2F0x4b+ts_final_idx+out-of-bounds+write/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46277 | Linux Kernel up to 7.0.3 mm folio_free stack-based overflow]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.0.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component mm. This manipulation of the argument folio_free causes stack-based buffer overflow.

This vulnerability is handled as CVE-2026-46277. The attack can only be done within the local network. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596834/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46277+%7C+Linux+Kernel+up+to+7.0.3+mm+folio_free+stack-based+overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596834/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46277+%7C+Linux+Kernel+up+to+7.0.3+mm+folio_free+stack-based+overflow/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46311 | Linux Kernel up to 7.0.8/7.1-rc2 drm privilege escalation]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Linux Kernel up to 7.0.8/7.1-rc2. This affects an unknown function of the component drm. The manipulation leads to privilege escalation.

This vulnerability is referenced as CVE-2026-46311. The attack needs to be initiated within the local network. No exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596833/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46311+%7C+Linux+Kernel+up+to+7.0.8%2F7.1-rc2+drm+privilege+escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596833/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46311+%7C+Linux+Kernel+up+to+7.0.8%2F7.1-rc2+drm+privilege+escalation/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-46303 | Linux Kernel up to 7.1-rc1 isofs rock.c rock_continue cont_extent infinite loop]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.1-rc1. It has been rated as critical. The affected element is the function rock_continue of the file rock.c of the component isofs. Performing a manipulation of the argument cont_extent results in infinite loop.

This vulnerability was named CVE-2026-46303. The attack needs to be approached within the local network. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596832/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46303+%7C+Linux+Kernel+up+to+7.1-rc1+isofs+rock.c+rock_continue+cont_extent+infinite+loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596832/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-46303+%7C+Linux+Kernel+up+to+7.1-rc1+isofs+rock.c+rock_continue+cont_extent+infinite+loop/</guid>
<pubDate>Sun, 14 Jun 2026 11:03:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-1836 | Redmine up to 5.0.13/5.1.9/6.0.6 password recoverable (Nessus ID 320979)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Redmine up to 5.0.13/5.1.9/6.0.6. This impacts an unknown function. The manipulation leads to storing passwords in a recoverable format.

This vulnerability is uniquely identified as CVE-2026-1836. Local access is required to approach this attack. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596831/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-1836+%7C+Redmine+up+to+5.0.13%2F5.1.9%2F6.0.6+password+recoverable+%28Nessus+ID+320979%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596831/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-1836+%7C+Redmine+up+to+5.0.13%2F5.1.9%2F6.0.6+password+recoverable+%28Nessus+ID+320979%29/</guid>
<pubDate>Sun, 14 Jun 2026 11:11:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12143 | form-data up to 2.5.5/3.0.4/4.0.5 crlf injection (GHSA-hmw2-7cc7-3qxx / Nessus ID 320982)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in form-data up to 2.5.5/3.0.4/4.0.5. Affected by this issue is some unknown functionality. Performing a manipulation results in crlf injection.

This vulnerability is identified as CVE-2026-12143. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596830/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12143+%7C+form-data+up+to+2.5.5%2F3.0.4%2F4.0.5+crlf+injection+%28GHSA-hmw2-7cc7-3qxx+%2F+Nessus+ID+320982%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596830/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12143+%7C+form-data+up+to+2.5.5%2F3.0.4%2F4.0.5+crlf+injection+%28GHSA-hmw2-7cc7-3qxx+%2F+Nessus+ID+320982%29/</guid>
<pubDate>Sun, 14 Jun 2026 11:11:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35045 | OTFCC 617837b otfccdump+0x6b0d63 heap-based overflow (EUVD-2022-37943)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in OTFCC 617837b. Affected by this issue is some unknown functionality of the file /release-x64/otfccdump+0x6b0d63. Performing a manipulation results in heap-based buffer overflow.

This vulnerability is cataloged as CVE-2022-35045. The attack must originate from the local network. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596793/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35045+%7C+OTFCC+617837b+otfccdump%2B0x6b0d63+heap-based+overflow+%28EUVD-2022-37943%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596793/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35045+%7C+OTFCC+617837b+otfccdump%2B0x6b0d63+heap-based+overflow+%28EUVD-2022-37943%29/</guid>
<pubDate>Sun, 14 Jun 2026 10:35:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35046 | OTFCC 617837b otfccdump+0x6b0466 heap-based overflow (EUVD-2022-37944)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in OTFCC 617837b. This affects an unknown part of the file /release-x64/otfccdump+0x6b0466. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is registered as CVE-2022-35046. The attack requires access to the local network. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596792/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35046+%7C+OTFCC+617837b+otfccdump%2B0x6b0466+heap-based+overflow+%28EUVD-2022-37944%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596792/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35046+%7C+OTFCC+617837b+otfccdump%2B0x6b0466+heap-based+overflow+%28EUVD-2022-37944%29/</guid>
<pubDate>Sun, 14 Jun 2026 10:35:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35047 | OTFCC 617837b otfccdump+0x6b05aa heap-based overflow (EUVD-2022-37945)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in OTFCC 617837b. This vulnerability affects unknown code of the file /release-x64/otfccdump+0x6b05aa. The manipulation leads to heap-based buffer overflow.

This vulnerability is documented as CVE-2022-35047. The attack requires being on the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596791/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35047+%7C+OTFCC+617837b+otfccdump%2B0x6b05aa+heap-based+overflow+%28EUVD-2022-37945%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596791/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35047+%7C+OTFCC+617837b+otfccdump%2B0x6b05aa+heap-based+overflow+%28EUVD-2022-37945%29/</guid>
<pubDate>Sun, 14 Jun 2026 10:35:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35050 | OTFCC 617837b otfccdump+0x6b04de heap-based overflow (EUVD-2022-37948)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in OTFCC 617837b. The affected element is an unknown function of the file /release-x64/otfccdump+0x6b04de. Such manipulation leads to heap-based buffer overflow.

This vulnerability is traded as CVE-2022-35050. Access to the local network is required for this attack to succeed. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596790/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35050+%7C+OTFCC+617837b+otfccdump%2B0x6b04de+heap-based+overflow+%28EUVD-2022-37948%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596790/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35050+%7C+OTFCC+617837b+otfccdump%2B0x6b04de+heap-based+overflow+%28EUVD-2022-37948%29/</guid>
<pubDate>Sun, 14 Jun 2026 10:35:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35048 | OTFCC 617837b otfccdump+0x6b0b2c heap-based overflow (EUVD-2022-37946)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in OTFCC 617837b. This issue affects some unknown processing of the file /release-x64/otfccdump+0x6b0b2c. The manipulation results in heap-based buffer overflow.

This vulnerability is reported as CVE-2022-35048. The attacker must have access to the local network to execute the attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596789/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35048+%7C+OTFCC+617837b+otfccdump%2B0x6b0b2c+heap-based+overflow+%28EUVD-2022-37946%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596789/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35048+%7C+OTFCC+617837b+otfccdump%2B0x6b0b2c+heap-based+overflow+%28EUVD-2022-37946%29/</guid>
<pubDate>Sun, 14 Jun 2026 10:35:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35051 | OTFCC 617837b otfccdump+0x6b55af heap-based overflow (EUVD-2022-37949)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in OTFCC 617837b. The impacted element is an unknown function of the file /release-x64/otfccdump+0x6b55af. Performing a manipulation results in heap-based buffer overflow.

This vulnerability is known as CVE-2022-35051. Access to the local network is required for this attack. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596788/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35051+%7C+OTFCC+617837b+otfccdump%2B0x6b55af+heap-based+overflow+%28EUVD-2022-37949%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596788/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35051+%7C+OTFCC+617837b+otfccdump%2B0x6b55af+heap-based+overflow+%28EUVD-2022-37949%29/</guid>
<pubDate>Sun, 14 Jun 2026 10:35:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45850 | Linux Kernel up to 6.19.3 ipvs memory corruption (WID-SEC-2026-1700)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.3. This affects an unknown function of the component ipvs. Such manipulation leads to memory corruption.

This vulnerability is referenced as CVE-2026-45850. The attack needs to be initiated within the local network. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596758/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45850+%7C+Linux+Kernel+up+to+6.19.3+ipvs+memory+corruption+%28WID-SEC-2026-1700%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596758/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45850+%7C+Linux+Kernel+up+to+6.19.3+ipvs+memory+corruption+%28WID-SEC-2026-1700%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:48:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45851 | Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3 efi reserve_unaccepted denial of service (WID-SEC-2026-1700)]]></title> 
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3. It has been classified as critical. This issue affects the function reserve_unaccepted of the component efi. The manipulation leads to denial of service.

This vulnerability is documented as CVE-2026-45851. The attack requires being on the local network. There is not any exploit available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596757/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45851+%7C+Linux+Kernel+up+to+6.6.127%2F6.12.74%2F6.18.13%2F6.19.3+efi+reserve_unaccepted+denial+of+service+%28WID-SEC-2026-1700%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596757/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45851+%7C+Linux+Kernel+up+to+6.6.127%2F6.12.74%2F6.18.13%2F6.19.3+efi+reserve_unaccepted+denial+of+service+%28WID-SEC-2026-1700%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:48:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45854 | Linux Kernel up to 6.18.13/6.19.3 crypto privilege escalation (WID-SEC-2026-1700)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 6.18.13/6.19.3. Affected is an unknown function of the component crypto. Executing a manipulation can lead to privilege escalation.

This vulnerability is tracked as CVE-2026-45854. The attack is only possible within the local network. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596756/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45854+%7C+Linux+Kernel+up+to+6.18.13%2F6.19.3+crypto+privilege+escalation+%28WID-SEC-2026-1700%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596756/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45854+%7C+Linux+Kernel+up+to+6.18.13%2F6.19.3+crypto+privilege+escalation+%28WID-SEC-2026-1700%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:48:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45853 | Linux Kernel up to 6.12.74/6.18.13/6.19.3 amdgpu_gmc_get_nps_memranges memory corruption (WID-SEC-2026-1700)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Linux Kernel up to 6.12.74/6.18.13/6.19.3. This affects the function amdgpu_gmc_get_nps_memranges. The manipulation leads to memory corruption.

This vulnerability is documented as CVE-2026-45853. The attack requires being on the local network. There is not any exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596755/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45853+%7C+Linux+Kernel+up+to+6.12.74%2F6.18.13%2F6.19.3+amdgpu_gmc_get_nps_memranges+memory+corruption+%28WID-SEC-2026-1700%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596755/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45853+%7C+Linux+Kernel+up+to+6.12.74%2F6.18.13%2F6.19.3+amdgpu_gmc_get_nps_memranges+memory+corruption+%28WID-SEC-2026-1700%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:48:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45856 | Linux Kernel up to 6.19.3 uverbs ib_uverbs_post_send out-of-bounds (WID-SEC-2026-1700)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Linux Kernel up to 6.19.3. Affected by this vulnerability is the function ib_uverbs_post_send of the component uverbs. The manipulation leads to out-of-bounds read.

This vulnerability is listed as CVE-2026-45856. The attack must be carried out from within the local network. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596754/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45856+%7C+Linux+Kernel+up+to+6.19.3+uverbs+ib_uverbs_post_send+out-of-bounds+%28WID-SEC-2026-1700%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596754/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45856+%7C+Linux+Kernel+up+to+6.19.3+uverbs+ib_uverbs_post_send+out-of-bounds+%28WID-SEC-2026-1700%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:48:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45855 | Linux Kernel up to 6.12.76/6.18.13/6.19.3 ata_scsi_qc_issue return value (WID-SEC-2026-1700)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.76/6.18.13/6.19.3. This impacts the function ata_scsi_qc_issue. This manipulation causes unchecked return value.

This vulnerability is tracked as CVE-2026-45855. The attack is only possible within the local network. No exploit exists.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596753/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45855+%7C+Linux+Kernel+up+to+6.12.76%2F6.18.13%2F6.19.3+ata_scsi_qc_issue+return+value+%28WID-SEC-2026-1700%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596753/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45855+%7C+Linux+Kernel+up+to+6.12.76%2F6.18.13%2F6.19.3+ata_scsi_qc_issue+return+value+%28WID-SEC-2026-1700%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:48:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53818 | OpenClaw up to 2026.4.23 MCP Loopback Feature authorization (GHSA-rj6p-xmxr-qj4h / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.4.23 and classified as critical. The impacted element is an unknown function of the component MCP Loopback Feature. The manipulation results in missing authorization.

This vulnerability is reported as CVE-2026-53818. The attack requires a local approach. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596717/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53818+%7C+OpenClaw+up+to+2026.4.23+MCP+Loopback+Feature+authorization+%28GHSA-rj6p-xmxr-qj4h+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596717/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53818+%7C+OpenClaw+up+to+2026.4.23+MCP+Loopback+Feature+authorization+%28GHSA-rj6p-xmxr-qj4h+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:23:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12183 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System up to 2.10.2 on Linux System Configuration /php/ajax-login.php improper authentication (EUVD-2026-36653)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Nefteprodukttekhnika BUK TS-G Gas Station Automation System up to 2.10.2 on Linux. The affected element is an unknown function of the file /php/ajax-login.php of the component System Configuration Module. Performing a manipulation results in improper authentication.

This vulnerability is reported as CVE-2026-12183. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596716/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12183+%7C+Nefteprodukttekhnika+BUK+TS-G+Gas+Station+Automation+System+up+to+2.10.2+on+Linux+System+Configuration+%2Fphp%2Fajax-login.php+improper+authentication+%28EUVD-2026-36653%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596716/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12183+%7C+Nefteprodukttekhnika+BUK+TS-G+Gas+Station+Automation+System+up+to+2.10.2+on+Linux+System+Configuration+%2Fphp%2Fajax-login.php+improper+authentication+%28EUVD-2026-36653%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-54421 | OpenStack Ironic up to 35.0.1 improper removal of sensitive information before storage or transfer (EUVD-2026-36658)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in OpenStack Ironic up to 35.0.1. This affects an unknown function. The manipulation leads to improper removal of sensitive information before storage or transfer.

This vulnerability is traded as CVE-2026-54421. It is possible to initiate the attack remotely. There is no exploit available.

Applying a patch is the recommended action to fix this issue. ]]></description>
<link>https://tsecurity.de/de/3596715/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54421+%7C+OpenStack+Ironic+up+to+35.0.1+improper+removal+of+sensitive+information+before+storage+or+transfer+%28EUVD-2026-36658%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596715/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54421+%7C+OpenStack+Ironic+up+to+35.0.1+improper+removal+of+sensitive+information+before+storage+or+transfer+%28EUVD-2026-36658%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-54420 | LiteSpeed cPanel Plugin up to 2.4.7 symlink (EUVD-2026-36657)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in LiteSpeed cPanel Plugin up to 2.4.7. This impacts an unknown function. The manipulation results in symlink following.

This vulnerability is known as CVE-2026-54420. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596714/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54420+%7C+LiteSpeed+cPanel+Plugin+up+to+2.4.7+symlink+%28EUVD-2026-36657%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596714/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54420+%7C+LiteSpeed+cPanel+Plugin+up+to+2.4.7+symlink+%28EUVD-2026-36657%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53787 | Amasty Order Attributes for Magento 2 up to 3.x Upload Endpoint unrestricted upload (EUVD-2026-36430)]]></title> 
<description><![CDATA[A vulnerability was found in Amasty Order Attributes for Magento 2 up to 3.x. It has been classified as critical. The affected element is an unknown function of the component Upload Endpoint. This manipulation causes unrestricted upload.

This vulnerability is registered as CVE-2026-53787. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596713/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53787+%7C+Amasty+Order+Attributes+for+Magento+2+up+to+3.x+Upload+Endpoint+unrestricted+upload+%28EUVD-2026-36430%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596713/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53787+%7C+Amasty+Order+Attributes+for+Magento+2+up+to+3.x+Upload+Endpoint+unrestricted+upload+%28EUVD-2026-36430%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-6428 | Koha up to 26.05.0 Reports reports/catalogue_out.pl strsth2 sql injection (EUVD-2026-36652)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Koha up to 26.05.0. The impacted element is an unknown function of the file reports/catalogue_out.pl of the component Reports Module. Executing a manipulation of the argument strsth2 can lead to sql injection.

This vulnerability appears as CVE-2026-6428. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596712/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-6428+%7C+Koha+up+to+26.05.0+Reports+reports%2Fcatalogue_out.pl+strsth2+sql+injection+%28EUVD-2026-36652%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596712/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-6428+%7C+Koha+up+to+26.05.0+Reports+reports%2Fcatalogue_out.pl+strsth2+sql+injection+%28EUVD-2026-36652%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53721 | Nuxt up to 3.21.6/4.4.6 case sensitivity (EUVD-2026-36427)]]></title> 
<description><![CDATA[A vulnerability was found in Nuxt up to 3.21.6/4.4.6. It has been declared as critical. Affected is an unknown function. Executing a manipulation can lead to improper handling of case sensitivity.

This vulnerability is registered as CVE-2026-53721. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596711/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53721+%7C+Nuxt+up+to+3.21.6%2F4.4.6+case+sensitivity+%28EUVD-2026-36427%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596711/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53721+%7C+Nuxt+up+to+3.21.6%2F4.4.6+case+sensitivity+%28EUVD-2026-36427%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47238 | MacWarrior clipbucket-v5 up to up to 5.5.2 authorization (GHSA-x468-whmw-c863 / EUVD-2026-36369)]]></title> 
<description><![CDATA[A vulnerability was found in MacWarrior clipbucket-v5 up to up to 5.5.2. It has been declared as critical. This vulnerability affects unknown code. Executing a manipulation can lead to authorization bypass.

This vulnerability is handled as CVE-2026-47238. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596710/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47238+%7C+MacWarrior+clipbucket-v5+up+to+up+to+5.5.2+authorization+%28GHSA-x468-whmw-c863+%2F+EUVD-2026-36369%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596710/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47238+%7C+MacWarrior+clipbucket-v5+up+to+up+to+5.5.2+authorization+%28GHSA-x468-whmw-c863+%2F+EUVD-2026-36369%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47197 | duck-organization questbot up to 1.1.5 authorization (EUVD-2026-36414)]]></title> 
<description><![CDATA[A vulnerability was found in duck-organization questbot up to 1.1.5 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to missing authorization.

This vulnerability is registered as CVE-2026-47197. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596709/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47197+%7C+duck-organization+questbot+up+to+1.1.5+authorization+%28EUVD-2026-36414%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596709/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47197+%7C+duck-organization+questbot+up+to+1.1.5+authorization+%28EUVD-2026-36414%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47200 | Nuxt up to 3.21.5/4.4.5 /__nuxt_island/:name access control (EUVD-2026-36422)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Nuxt up to 3.21.5/4.4.5. Affected by this issue is some unknown functionality of the file /__nuxt_island/:name. Such manipulation leads to improper access controls.

This vulnerability is referenced as CVE-2026-47200. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596708/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47200+%7C+Nuxt+up+to+3.21.5%2F4.4.5+%2F__nuxt_island%2F%3Aname+access+control+%28EUVD-2026-36422%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596708/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47200+%7C+Nuxt+up+to+3.21.5%2F4.4.5+%2F__nuxt_island%2F%3Aname+access+control+%28EUVD-2026-36422%29/</guid>
<pubDate>Sun, 14 Jun 2026 09:34:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35018 | Advancecomp 2.3 memory corruption (EUVD-2022-37916 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Advancecomp 2.3. Affected by this issue is some unknown functionality. This manipulation causes memory corruption.

This vulnerability is registered as CVE-2022-35018. The attack requires access to the local network. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596648/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35018+%7C+Advancecomp+2.3+memory+corruption+%28EUVD-2022-37916+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596648/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35018+%7C+Advancecomp+2.3+memory+corruption+%28EUVD-2022-37916+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:24:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35020 | Advancecomp 2.3 sanitizer_common_interceptors.inc __interceptor_memcpy heap-based overflow (EUVD-2022-37918 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Advancecomp 2.3. This vulnerability affects the function __interceptor_memcpy of the file /sanitizer_common/sanitizer_common_interceptors.inc. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is handled as CVE-2022-35020. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596647/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35020+%7C+Advancecomp+2.3+sanitizer_common_interceptors.inc+__interceptor_memcpy+heap-based+overflow+%28EUVD-2022-37918+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596647/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35020+%7C+Advancecomp+2.3+sanitizer_common_interceptors.inc+__interceptor_memcpy+heap-based+overflow+%28EUVD-2022-37918+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:24:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35040 | OTFCC 617837b otfccdump+0x6b5567 heap-based overflow (EUVD-2022-37938)]]></title> 
<description><![CDATA[A vulnerability was found in OTFCC 617837b and classified as critical. The impacted element is an unknown function of the file /release-x64/otfccdump+0x6b5567. Executing a manipulation can lead to heap-based buffer overflow.

The identification of this vulnerability is CVE-2022-35040. The attack needs to be done within the local network. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596646/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35040+%7C+OTFCC+617837b+otfccdump%2B0x6b5567+heap-based+overflow+%28EUVD-2022-37938%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596646/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35040+%7C+OTFCC+617837b+otfccdump%2B0x6b5567+heap-based+overflow+%28EUVD-2022-37938%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:24:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35019 | Advancecomp 2.3 memory corruption (EUVD-2022-37917 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in Advancecomp 2.3. This affects an unknown part. Such manipulation leads to memory corruption.

This vulnerability is documented as CVE-2022-35019. The attack requires being on the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596645/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35019+%7C+Advancecomp+2.3+memory+corruption+%28EUVD-2022-37917+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596645/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35019+%7C+Advancecomp+2.3+memory+corruption+%28EUVD-2022-37917+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:24:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35043 | OTFCC 617837b otfccdump+0x6c08a6 heap-based overflow (EUVD-2022-37941)]]></title> 
<description><![CDATA[A vulnerability was found in OTFCC 617837b. It has been rated as critical. Affected is an unknown function of the file /release-x64/otfccdump+0x6c08a6. This manipulation causes heap-based buffer overflow.

This vulnerability is tracked as CVE-2022-35043. The attack is only possible within the local network. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596644/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35043+%7C+OTFCC+617837b+otfccdump%2B0x6c08a6+heap-based+overflow+%28EUVD-2022-37941%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596644/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35043+%7C+OTFCC+617837b+otfccdump%2B0x6c08a6+heap-based+overflow+%28EUVD-2022-37941%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:24:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34912 | MediaWiki up to 1.37.2/1.38.0 Special:Contributions contributions-title cross site scripting (EUVD-2022-37816)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in MediaWiki up to 1.37.2/1.38.0. This affects an unknown function of the file Special:Contributions. This manipulation of the argument contributions-title causes basic cross site scripting.

This vulnerability is tracked as CVE-2022-34912. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596613/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34912+%7C+MediaWiki+up+to+1.37.2%2F1.38.0+Special%3AContributions+contributions-title+cross+site+scripting+%28EUVD-2022-37816%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596613/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34912+%7C+MediaWiki+up+to+1.37.2%2F1.38.0+Special%3AContributions+contributions-title+cross+site+scripting+%28EUVD-2022-37816%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:05:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35015 | Advancecomp 2.3 /lib/endianrw.h le_uint32_read heap-based overflow (EUVD-2022-37913 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Advancecomp 2.3. This impacts the function le_uint32_read in the library /lib/endianrw.h. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is tracked as CVE-2022-35015. The attack is only possible within the local network. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596612/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35015+%7C+Advancecomp+2.3+%2Flib%2Fendianrw.h+le_uint32_read+heap-based+overflow+%28EUVD-2022-37913+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596612/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35015+%7C+Advancecomp+2.3+%2Flib%2Fendianrw.h+le_uint32_read+heap-based+overflow+%28EUVD-2022-37913+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:05:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35014 | Advancecomp 2.3 memory corruption (EUVD-2022-37912 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Advancecomp 2.3. This affects an unknown function. This manipulation causes memory corruption.

This vulnerability appears as CVE-2022-35014. The attacker needs to be present on the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596611/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35014+%7C+Advancecomp+2.3+memory+corruption+%28EUVD-2022-37912+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596611/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35014+%7C+Advancecomp+2.3+memory+corruption+%28EUVD-2022-37912+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:05:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35016 | Advancecomp 2.3 heap-based overflow (EUVD-2022-37914 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Advancecomp 2.3. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.

This vulnerability is listed as CVE-2022-35016. The attack must be carried out from within the local network. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596610/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35016+%7C+Advancecomp+2.3+heap-based+overflow+%28EUVD-2022-37914+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596610/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35016+%7C+Advancecomp+2.3+heap-based+overflow+%28EUVD-2022-37914+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:05:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34965 | OpenTeknik OSSN Open Source Social Network 6.3 LTS com_installer unrestricted upload (EUVD-2022-37867)]]></title> 
<description><![CDATA[A vulnerability was found in OpenTeknik OSSN Open Source Social Network 6.3 LTS. It has been classified as critical. Impacted is an unknown function of the file /ossn/administrator/com_installer. This manipulation causes unrestricted upload.

The identification of this vulnerability is CVE-2022-34965. It is possible to initiate the attack remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596609/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34965+%7C+OpenTeknik+OSSN+Open+Source+Social+Network+6.3+LTS+com_installer+unrestricted+upload+%28EUVD-2022-37867%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596609/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34965+%7C+OpenTeknik+OSSN+Open+Source+Social+Network+6.3+LTS+com_installer+unrestricted+upload+%28EUVD-2022-37867%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:05:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-35017 | Advancecomp 2.3 heap-based overflow (EUVD-2022-37915 / Nessus ID 211214)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Advancecomp 2.3. Affected by this vulnerability is an unknown functionality. The manipulation results in heap-based buffer overflow.

This vulnerability is cataloged as CVE-2022-35017. The attack must originate from the local network. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596608/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35017+%7C+Advancecomp+2.3+heap-based+overflow+%28EUVD-2022-37915+%2F+Nessus+ID+211214%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596608/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-35017+%7C+Advancecomp+2.3+heap-based+overflow+%28EUVD-2022-37915+%2F+Nessus+ID+211214%29/</guid>
<pubDate>Sun, 14 Jun 2026 08:05:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34833 | Vermeg AgileReporter 21.3 Analysis cross site scripting (EUVD-2022-37739)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in Vermeg AgileReporter 21.3. The impacted element is an unknown function of the component Analysis. Executing a manipulation can lead to cross site scripting.

This vulnerability appears as CVE-2022-34833. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596577/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34833+%7C+Vermeg+AgileReporter+21.3+Analysis+cross+site+scripting+%28EUVD-2022-37739%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596577/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34833+%7C+Vermeg+AgileReporter+21.3+Analysis+cross+site+scripting+%28EUVD-2022-37739%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:23:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34840 | Buffalo WZR-300HP Configuration Setting hard-coded credentials (EUVD-2022-37746)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Buffalo WZR-300HP, WZR-450HP, WZR-600DHP, WZR-900DHP, HW-450HP-ZWE, WZR-450HP-CWT, WZR-450HP-UB, WZR-600DHP2 and WZR-D1100H. The impacted element is an unknown function of the component Configuration Setting Handler. Performing a manipulation results in hard-coded credentials.

This vulnerability is cataloged as CVE-2022-34840. The attack must originate from the local network. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596576/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34840+%7C+Buffalo+WZR-300HP+Configuration+Setting+hard-coded+credentials+%28EUVD-2022-37746%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596576/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34840+%7C+Buffalo+WZR-300HP+Configuration+Setting+hard-coded+credentials+%28EUVD-2022-37746%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:23:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34834 | Vermeg AgileReporter 21.3 Add Comment cross site scripting (EUVD-2022-37740)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in Vermeg AgileReporter 21.3. Affected is an unknown function of the component Add Comment. The manipulation results in cross site scripting.

This vulnerability is reported as CVE-2022-34834. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596575/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34834+%7C+Vermeg+AgileReporter+21.3+Add+Comment+cross+site+scripting+%28EUVD-2022-37740%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596575/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34834+%7C+Vermeg+AgileReporter+21.3+Add+Comment+cross+site+scripting+%28EUVD-2022-37740%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:23:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34908 | Aremis A4N 1.5.0 on Android improper authorization (EUVD-2022-37812)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Aremis A4N 1.5.0 on Android. This affects an unknown part. This manipulation causes improper authorization.

The identification of this vulnerability is CVE-2022-34908. It is possible to initiate the attack remotely. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596574/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34908+%7C+Aremis+A4N+1.5.0+on+Android+improper+authorization+%28EUVD-2022-37812%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596574/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34908+%7C+Aremis+A4N+1.5.0+on+Android+improper+authorization+%28EUVD-2022-37812%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:23:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34911 | MediaWiki up to 1.35.6/1.37.2/1.38.0 Welcome successfulAction Username escape output (EUVD-2022-37815)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in MediaWiki up to 1.35.6/1.37.2/1.38.0. This impacts the function SpecialCreateAccount::successfulAction of the component Welcome Handler. Such manipulation of the argument Username leads to escaping of output.

This vulnerability is listed as CVE-2022-34911. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596573/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34911+%7C+MediaWiki+up+to+1.35.6%2F1.37.2%2F1.38.0+Welcome+successfulAction+Username+escape+output+%28EUVD-2022-37815%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596573/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34911+%7C+MediaWiki+up+to+1.35.6%2F1.37.2%2F1.38.0+Welcome+successfulAction+Username+escape+output+%28EUVD-2022-37815%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:23:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34909 | Aremis A4N 1.5.0 on Android sql injection (EUVD-2022-37813)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Aremis A4N 1.5.0 on Android. This vulnerability affects unknown code. Such manipulation leads to sql injection.

This vulnerability is referenced as CVE-2022-34909. The attack can only be performed from a local environment. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596572/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34909+%7C+Aremis+A4N+1.5.0+on+Android+sql+injection+%28EUVD-2022-37813%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596572/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34909+%7C+Aremis+A4N+1.5.0+on+Android+sql+injection+%28EUVD-2022-37813%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:23:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-54056 | kovidgoyal kitty up to 0.47.1 kittens/dnd/drop.go utils.CreateAt link following (GHSA-r892-cv7q-fw8x / Nessus ID 320972)]]></title> 
<description><![CDATA[A vulnerability was found in kovidgoyal kitty up to 0.47.1 and classified as critical. Affected by this vulnerability is the function utils.CreateAt of the file kittens/dnd/drop.go. Such manipulation leads to link following.

This vulnerability is documented as CVE-2026-54056. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596559/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54056+%7C+kovidgoyal+kitty+up+to+0.47.1+kittens%2Fdnd%2Fdrop.go+utils.CreateAt+link+following+%28GHSA-r892-cv7q-fw8x+%2F+Nessus+ID+320972%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596559/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54056+%7C+kovidgoyal+kitty+up+to+0.47.1+kittens%2Fdnd%2Fdrop.go+utils.CreateAt+link+following+%28GHSA-r892-cv7q-fw8x+%2F+Nessus+ID+320972%29/</guid>
<pubDate>Sun, 14 Jun 2026 06:54:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-55659 | GPAC 2.4 MP4Box isomedia/box_code_base.c ctts_box_write null pointer dereference (EUVD-2025-210093)]]></title> 
<description><![CDATA[A vulnerability was found in GPAC 2.4. It has been classified as problematic. This issue affects the function ctts_box_write of the file isomedia/box_code_base.c of the component MP4Box. The manipulation leads to null pointer dereference.

This vulnerability is uniquely identified as CVE-2025-55659. The attack can only be initiated within the local network. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596558/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-55659+%7C+GPAC+2.4+MP4Box+isomedia%2Fbox_code_base.c+ctts_box_write+null+pointer+dereference+%28EUVD-2025-210093%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596558/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-55659+%7C+GPAC+2.4+MP4Box+isomedia%2Fbox_code_base.c+ctts_box_write+null+pointer+dereference+%28EUVD-2025-210093%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-52293 | GPAC 2.4 MP4Box media_tools/av_parsers.c gf_hevc_read_sps_bs_internal denial of service (EUVD-2025-210089)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in GPAC 2.4. Affected by this issue is the function gf_hevc_read_sps_bs_internal of the file media_tools/av_parsers.c of the component MP4Box. Such manipulation leads to denial of service.

This vulnerability is traded as CVE-2025-52293. Access to the local network is required for this attack to succeed. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596557/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-52293+%7C+GPAC+2.4+MP4Box+media_tools%2Fav_parsers.c+gf_hevc_read_sps_bs_internal+denial+of+service+%28EUVD-2025-210089%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596557/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-52293+%7C+GPAC+2.4+MP4Box+media_tools%2Fav_parsers.c+gf_hevc_read_sps_bs_internal+denial+of+service+%28EUVD-2025-210089%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-55657 | GPAC 2.4 MP4Box odf/descriptors.c gf_odf_vvc_cfg_write_bs null pointer dereference (EUVD-2025-210091)]]></title> 
<description><![CDATA[A vulnerability was found in GPAC 2.4 and classified as problematic. This vulnerability affects the function gf_odf_vvc_cfg_write_bs of the file odf/descriptors.c of the component MP4Box. Executing a manipulation can lead to null pointer dereference.

This vulnerability is handled as CVE-2025-55657. The attack can only be done within the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596556/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-55657+%7C+GPAC+2.4+MP4Box+odf%2Fdescriptors.c+gf_odf_vvc_cfg_write_bs+null+pointer+dereference+%28EUVD-2025-210091%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596556/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-55657+%7C+GPAC+2.4+MP4Box+odf%2Fdescriptors.c+gf_odf_vvc_cfg_write_bs+null+pointer+dereference+%28EUVD-2025-210091%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-52292 | GPAC 2.4 MP4Box in_file.c filein_process stack-based overflow (EUVD-2025-210088)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in GPAC 2.4. Affected is the function filein_process of the file in_file.c of the component MP4Box. Performing a manipulation results in stack-based buffer overflow.

This vulnerability is identified as CVE-2025-52292. The attack can only be performed from the local network. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596555/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-52292+%7C+GPAC+2.4+MP4Box+in_file.c+filein_process+stack-based+overflow+%28EUVD-2025-210088%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596555/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-52292+%7C+GPAC+2.4+MP4Box+in_file.c+filein_process+stack-based+overflow+%28EUVD-2025-210088%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-44208 | Frappe up to 15.106.x/16.16.x submit_discussion access control (GHSA-xh7m-j2j2-82f2 / EUVD-2026-36485)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Frappe up to 15.106.x/16.16.x. This impacts the function submit_discussion. This manipulation causes improper access controls.

This vulnerability is handled as CVE-2026-44208. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596554/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44208+%7C+Frappe+up+to+15.106.x%2F16.16.x+submit_discussion+access+control+%28GHSA-xh7m-j2j2-82f2+%2F+EUVD-2026-36485%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596554/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44208+%7C+Frappe+up+to+15.106.x%2F16.16.x+submit_discussion+access+control+%28GHSA-xh7m-j2j2-82f2+%2F+EUVD-2026-36485%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47141 | patriksimek vm2 up to 3.11.3 exposure of resource (EUVD-2026-36449)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in patriksimek vm2 up to 3.11.3. This affects an unknown function. This manipulation causes exposure of resource.

The identification of this vulnerability is CVE-2026-47141. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596553/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47141+%7C+patriksimek+vm2+up+to+3.11.3+exposure+of+resource+%28EUVD-2026-36449%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596553/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47141+%7C+patriksimek+vm2+up+to+3.11.3+exposure+of+resource+%28EUVD-2026-36449%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-44494 | Axios up to 1.15.x lib/adapters/http.js setProxy confused deputy (EUVD-2026-36257)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Axios up to 1.15.x. This affects the function setProxy in the library lib/adapters/http.js. Such manipulation leads to unintended intermediary.

This vulnerability is referenced as CVE-2026-44494. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596552/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44494+%7C+Axios+up+to+1.15.x+lib%2Fadapters%2Fhttp.js+setProxy+confused+deputy+%28EUVD-2026-36257%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596552/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-44494+%7C+Axios+up+to+1.15.x+lib%2Fadapters%2Fhttp.js+setProxy+confused+deputy+%28EUVD-2026-36257%29/</guid>
<pubDate>Sun, 14 Jun 2026 07:09:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53806 | OpenClaw up to 2026.5.11 toctou (GHSA-vxx3-6hc9-7cc3 / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.11. It has been rated as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in time-of-check time-of-use.

This vulnerability was named CVE-2026-53806. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596520/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53806+%7C+OpenClaw+up+to+2026.5.11+toctou+%28GHSA-vxx3-6hc9-7cc3+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596520/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53806+%7C+OpenClaw+up+to+2026.5.11+toctou+%28GHSA-vxx3-6hc9-7cc3+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 05:57:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53807 | OpenClaw up to 2026.5.5 authorization (GHSA-w5ww-7chg-mxcq / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.5.5. This vulnerability affects unknown code. The manipulation leads to incorrect authorization.

This vulnerability is referenced as CVE-2026-53807. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596519/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53807+%7C+OpenClaw+up+to+2026.5.5+authorization+%28GHSA-w5ww-7chg-mxcq+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596519/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53807+%7C+OpenClaw+up+to+2026.5.5+authorization+%28GHSA-w5ww-7chg-mxcq+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 05:57:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53808 | OpenClaw up to 2026.5.5 authorization (GHSA-cqwv-9qjx-vxw2 / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in OpenClaw up to 2026.5.5. This issue affects some unknown processing. The manipulation results in incorrect authorization.

This vulnerability is identified as CVE-2026-53808. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596518/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53808+%7C+OpenClaw+up+to+2026.5.5+authorization+%28GHSA-cqwv-9qjx-vxw2+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596518/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53808+%7C+OpenClaw+up+to+2026.5.5+authorization+%28GHSA-cqwv-9qjx-vxw2+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 05:57:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53809 | OpenClaw up to 2026.4.24 authorization (GHSA-p39j-x9h5-q66m / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in OpenClaw up to 2026.4.24. Impacted is an unknown function. This manipulation causes incorrect authorization.

This vulnerability is tracked as CVE-2026-53809. The attack is restricted to local execution. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596517/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53809+%7C+OpenClaw+up+to+2026.4.24+authorization+%28GHSA-p39j-x9h5-q66m+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596517/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53809+%7C+OpenClaw+up+to+2026.4.24+authorization+%28GHSA-p39j-x9h5-q66m+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 05:57:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53812 | OpenClaw up to 2026.5.17 server-side request forgery (GHSA-2hfg-4fh4-qp7f / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in OpenClaw up to 2026.5.17. The impacted element is an unknown function. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as CVE-2026-53812. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596516/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53812+%7C+OpenClaw+up+to+2026.5.17+server-side+request+forgery+%28GHSA-2hfg-4fh4-qp7f+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596516/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53812+%7C+OpenClaw+up+to+2026.5.17+server-side+request+forgery+%28GHSA-2hfg-4fh4-qp7f+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 05:57:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53815 | OpenClaw up to 2026.5.18 Request Message authorization (GHSA-q7q8-3mgw-q67r / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.5.18. Impacted is an unknown function of the component Request Message Handler. Executing a manipulation can lead to missing authorization.

This vulnerability is registered as CVE-2026-53815. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596515/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53815+%7C+OpenClaw+up+to+2026.5.18+Request+Message+authorization+%28GHSA-q7q8-3mgw-q67r+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596515/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53815+%7C+OpenClaw+up+to+2026.5.18+Request+Message+authorization+%28GHSA-q7q8-3mgw-q67r+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 05:57:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12176 | SourceCodester CET Automated Grading System with AI Predictive Analytics /index.php cross site scripting (EUVD-2026-36656)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-12176. The attack is possible to be carried out remotely. Moreover, an exploit is present. ]]></description>
<link>https://tsecurity.de/de/3596452/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12176+%7C+SourceCodester+CET+Automated+Grading+System+with+AI+Predictive+Analytics+%2Findex.php+cross+site+scripting+%28EUVD-2026-36656%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596452/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12176+%7C+SourceCodester+CET+Automated+Grading+System+with+AI+Predictive+Analytics+%2Findex.php+cross+site+scripting+%28EUVD-2026-36656%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12175 | CodeAstro Student Attendance Management System 1.0 createStudents.php admissionNumber sql injection (EUVD-2026-36655)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection.

This vulnerability is known as CVE-2026-12175. Remote exploitation of the attack is possible. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596451/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12175+%7C+CodeAstro+Student+Attendance+Management+System+1.0+createStudents.php+admissionNumber+sql+injection+%28EUVD-2026-36655%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596451/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12175+%7C+CodeAstro+Student+Attendance+Management+System+1.0+createStudents.php+admissionNumber+sql+injection+%28EUVD-2026-36655%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45174 | CyberArk Idira Endpoint Privilege Manager up to 26.4 denial of service (EUVD-2026-36362)]]></title> 
<description><![CDATA[A vulnerability was found in CyberArk Idira Endpoint Privilege Manager up to 26.4. It has been classified as problematic. This affects an unknown function. This manipulation causes denial of service.

This vulnerability appears as CVE-2026-45174. The attack requires local access. There is no available exploit.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596450/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45174+%7C+CyberArk+Idira+Endpoint+Privilege+Manager+up+to+26.4+denial+of+service+%28EUVD-2026-36362%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596450/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45174+%7C+CyberArk+Idira+Endpoint+Privilege+Manager+up+to+26.4+denial+of+service+%28EUVD-2026-36362%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53819 | OpenClaw up to 2026.5.26 untrusted search path (GHSA-8wg3-5mcm-fjq8 / EUVD-2026-36325)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.26. It has been declared as problematic. The affected element is an unknown function. The manipulation results in untrusted search path.

This vulnerability is known as CVE-2026-53819. Attacking locally is a requirement. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596449/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53819+%7C+OpenClaw+up+to+2026.5.26+untrusted+search+path+%28GHSA-8wg3-5mcm-fjq8+%2F+EUVD-2026-36325%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596449/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53819+%7C+OpenClaw+up+to+2026.5.26+untrusted+search+path+%28GHSA-8wg3-5mcm-fjq8+%2F+EUVD-2026-36325%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53816 | OpenClaw up to 2026.5.17 authorization (GHSA-3c6j-hq33-3jv4 / EUVD-2026-36322)]]></title> 
<description><![CDATA[A vulnerability has been found in OpenClaw up to 2026.5.17 and classified as problematic. The affected element is an unknown function. The manipulation leads to missing authorization.

This vulnerability is documented as CVE-2026-53816. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596448/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53816+%7C+OpenClaw+up+to+2026.5.17+authorization+%28GHSA-3c6j-hq33-3jv4+%2F+EUVD-2026-36322%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596448/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53816+%7C+OpenClaw+up+to+2026.5.17+authorization+%28GHSA-3c6j-hq33-3jv4+%2F+EUVD-2026-36322%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53817 | OpenClaw up to 2026.5.21 Device Token authentication spoofing (GHSA-chr9-m4q2-76hw / EUVD-2026-36323)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.5.21. Affected by this issue is some unknown functionality of the component Device Token Handler. The manipulation leads to authentication bypass by spoofing.

This vulnerability is uniquely identified as CVE-2026-53817. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596447/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53817+%7C+OpenClaw+up+to+2026.5.21+Device+Token+authentication+spoofing+%28GHSA-chr9-m4q2-76hw+%2F+EUVD-2026-36323%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596447/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53817+%7C+OpenClaw+up+to+2026.5.21+Device+Token+authentication+spoofing+%28GHSA-chr9-m4q2-76hw+%2F+EUVD-2026-36323%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53811 | OpenClaw up to 2026.5.6 Matrix allowFrom Feature authentication spoofing (GHSA-7hxm-f538-3xp6 / EUVD-2026-36317)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Matrix allowFrom Feature. Such manipulation leads to authentication bypass by spoofing.

This vulnerability is uniquely identified as CVE-2026-53811. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596446/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53811+%7C+OpenClaw+up+to+2026.5.6+Matrix+allowFrom+Feature+authentication+spoofing+%28GHSA-7hxm-f538-3xp6+%2F+EUVD-2026-36317%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596446/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53811+%7C+OpenClaw+up+to+2026.5.6+Matrix+allowFrom+Feature+authentication+spoofing+%28GHSA-7hxm-f538-3xp6+%2F+EUVD-2026-36317%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53814 | OpenClaw up to 2026.5.19 /hooks/agent privileges assignment (GHSA-6fvr-66p3-3qj4 / EUVD-2026-36320)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in OpenClaw up to 2026.5.19. This issue affects some unknown processing of the file /hooks/agent. Performing a manipulation results in incorrect privilege assignment.

This vulnerability is cataloged as CVE-2026-53814. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596445/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53814+%7C+OpenClaw+up+to+2026.5.19+%2Fhooks%2Fagent+privileges+assignment+%28GHSA-6fvr-66p3-3qj4+%2F+EUVD-2026-36320%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596445/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53814+%7C+OpenClaw+up+to+2026.5.19+%2Fhooks%2Fagent+privileges+assignment+%28GHSA-6fvr-66p3-3qj4+%2F+EUVD-2026-36320%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53813 | OpenClaw up to 2026.4.24 uncontrolled search path (GHSA-v8cx-933x-r976 / EUVD-2026-36319)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.4.24. It has been rated as problematic. Affected is an unknown function. Performing a manipulation results in uncontrolled search path.

This vulnerability is known as CVE-2026-53813. Attacking locally is a requirement. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596444/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53813+%7C+OpenClaw+up+to+2026.4.24+uncontrolled+search+path+%28GHSA-v8cx-933x-r976+%2F+EUVD-2026-36319%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596444/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53813+%7C+OpenClaw+up+to+2026.4.24+uncontrolled+search+path+%28GHSA-v8cx-933x-r976+%2F+EUVD-2026-36319%29/</guid>
<pubDate>Sun, 14 Jun 2026 04:38:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34822 | NEC CLUSTERPRO X/EXPRESSCLUSTER X up to 5.0 on Windows path traversal (EUVD-2022-37728)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in NEC CLUSTERPRO X and EXPRESSCLUSTER X up to 5.0 on Windows. This vulnerability affects unknown code. This manipulation causes path traversal.

This vulnerability is registered as CVE-2022-34822. Remote exploitation of the attack is possible. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596407/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34822+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+path+traversal+%28EUVD-2022-37728%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596407/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34822+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+path+traversal+%28EUVD-2022-37728%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34824 | NEC CLUSTERPRO X/EXPRESSCLUSTER X up to 5.0 on Windows permission (EUVD-2022-37730)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in NEC CLUSTERPRO X and EXPRESSCLUSTER X up to 5.0 on Windows. Impacted is an unknown function. Performing a manipulation results in permission issues.

This vulnerability is reported as CVE-2022-34824. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3596406/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34824+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+permission+%28EUVD-2022-37730%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596406/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34824+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+permission+%28EUVD-2022-37730%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34823 | NEC CLUSTERPRO X/EXPRESSCLUSTER X up to 5.0 on Windows buffer overflow (EUVD-2022-37729)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in NEC CLUSTERPRO X and EXPRESSCLUSTER X up to 5.0 on Windows. This issue affects some unknown processing. Such manipulation leads to buffer overflow.

This vulnerability is documented as CVE-2022-34823. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596405/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34823+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+buffer+overflow+%28EUVD-2022-37729%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596405/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34823+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+buffer+overflow+%28EUVD-2022-37729%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34825 | NEC CLUSTERPRO X/EXPRESSCLUSTER X up to 5.0 on Windows uncontrolled search path (EUVD-2022-37731)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in NEC CLUSTERPRO X and EXPRESSCLUSTER X up to 5.0 on Windows. The affected element is an unknown function. Executing a manipulation can lead to uncontrolled search path.

This vulnerability appears as CVE-2022-34825. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596404/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34825+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+uncontrolled+search+path+%28EUVD-2022-37731%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596404/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34825+%7C+NEC+CLUSTERPRO+X%2FEXPRESSCLUSTER+X+up+to+5.0+on+Windows+uncontrolled+search+path+%28EUVD-2022-37731%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34827 | Carel Boss Mini 1.5.0 access control (EUVD-2022-37733)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Carel Boss Mini 1.5.0. Affected is an unknown function. Such manipulation leads to improper access controls.

This vulnerability is traded as CVE-2022-34827. Access to the local network is required for this attack to succeed. There is no exploit available. ]]></description>
<link>https://tsecurity.de/de/3596403/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34827+%7C+Carel+Boss+Mini+1.5.0+access+control+%28EUVD-2022-37733%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596403/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34827+%7C+Carel+Boss+Mini+1.5.0+access+control+%28EUVD-2022-37733%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34830 | ARM Mali GPU Driver up to 2022-06-29 race condition (EUVD-2022-37736)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in ARM Mali GPU Driver up to 2022-06-29. This vulnerability affects unknown code. Such manipulation leads to race condition.

This vulnerability is referenced as CVE-2022-34830. It is possible to launch the attack remotely. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596402/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34830+%7C+ARM+Mali+GPU+Driver+up+to+2022-06-29+race+condition+%28EUVD-2022-37736%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596402/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34830+%7C+ARM+Mali+GPU+Driver+up+to+2022-06-29+race+condition+%28EUVD-2022-37736%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34832 | Vermeg AgileReporter 21.3 Analysis xml external entity reference (EUVD-2022-37738)]]></title> 
<description><![CDATA[A vulnerability was found in Vermeg AgileReporter 21.3. It has been rated as problematic. This issue affects some unknown processing of the component Analysis. This manipulation causes xml external entity reference.

This vulnerability is registered as CVE-2022-34832. The attack requires access to the local network. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3596401/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34832+%7C+Vermeg+AgileReporter+21.3+Analysis+xml+external+entity+reference+%28EUVD-2022-37738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596401/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34832+%7C+Vermeg+AgileReporter+21.3+Analysis+xml+external+entity+reference+%28EUVD-2022-37738%29/</guid>
<pubDate>Sun, 14 Jun 2026 03:17:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-52858 | vim up to 9.2.0560 Working Directory code injection (GHSA-52mc-rq6p-rc7c / WID-SEC-2026-1759)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in vim up to 9.2.0560. This affects an unknown function of the component Working Directory Handler. Performing a manipulation results in code injection.

This vulnerability is known as CVE-2026-52858. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596372/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-52858+%7C+vim+up+to+9.2.0560+Working+Directory+code+injection+%28GHSA-52mc-rq6p-rc7c+%2F+WID-SEC-2026-1759%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596372/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-52858+%7C+vim+up+to+9.2.0560+Working+Directory+code+injection+%28GHSA-52mc-rq6p-rc7c+%2F+WID-SEC-2026-1759%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:38:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49261 | MariaDB Server up to 12.3.1 os command injection (GHSA-3p3m-4x7c-p4pw / WID-SEC-2026-1744)]]></title> 
<description><![CDATA[A vulnerability was found in MariaDB Server up to 10.6.26/10.11.17/11.4.11/11.8.7/12.3.1. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes os command injection.

This vulnerability is tracked as CVE-2026-49261. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596371/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49261+%7C+MariaDB+Server+up+to+12.3.1+os+command+injection+%28GHSA-3p3m-4x7c-p4pw+%2F+WID-SEC-2026-1744%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596371/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49261+%7C+MariaDB+Server+up+to+12.3.1+os+command+injection+%28GHSA-3p3m-4x7c-p4pw+%2F+WID-SEC-2026-1744%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:38:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-48163 | MariaDB Server up to 12.3.1 joiner os command injection (GHSA-rpgv-q6gv-684r / WID-SEC-2026-1744)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in MariaDB Server up to 10.6.26/10.11.17/11.4.11/11.8.7/12.3.1. This vulnerability affects unknown code of the component joiner Handler. The manipulation leads to os command injection.

This vulnerability is listed as CVE-2026-48163. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596370/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48163+%7C+MariaDB+Server+up+to+12.3.1+joiner+os+command+injection+%28GHSA-rpgv-q6gv-684r+%2F+WID-SEC-2026-1744%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596370/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48163+%7C+MariaDB+Server+up+to+12.3.1+joiner+os+command+injection+%28GHSA-rpgv-q6gv-684r+%2F+WID-SEC-2026-1744%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:38:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-34507 | OpenClaw up to 2026.4.28 QQBot Admin Command authorization (GHSA-w4v6-g3wm-w36c / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in OpenClaw up to 2026.4.28. The impacted element is an unknown function of the component QQBot Admin Command Handler. Performing a manipulation results in incorrect authorization.

This vulnerability is known as CVE-2026-34507. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596369/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-34507+%7C+OpenClaw+up+to+2026.4.28+QQBot+Admin+Command+authorization+%28GHSA-w4v6-g3wm-w36c+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596369/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-34507+%7C+OpenClaw+up+to+2026.4.28+QQBot+Admin+Command+authorization+%28GHSA-w4v6-g3wm-w36c+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:38:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-35630 | OpenClaw up to 2026.5.17 authorization (GHSA-mgq6-vr84-7m2j / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability has been found in OpenClaw up to 2026.5.17 and classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes missing authorization.

The identification of this vulnerability is CVE-2026-35630. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596368/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35630+%7C+OpenClaw+up+to+2026.5.17+authorization+%28GHSA-mgq6-vr84-7m2j+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596368/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35630+%7C+OpenClaw+up+to+2026.5.17+authorization+%28GHSA-mgq6-vr84-7m2j+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:38:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-32906 | OpenClaw up to 2026.5.11 Slack Plugin authorization (GHSA-wv26-j37q-2g7p / WID-SEC-2026-1738)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.11 and classified as problematic. Affected by this issue is some unknown functionality of the component Slack Plugin. Such manipulation leads to incorrect authorization.

This vulnerability is referenced as CVE-2026-32906. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596367/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-32906+%7C+OpenClaw+up+to+2026.5.11+Slack+Plugin+authorization+%28GHSA-wv26-j37q-2g7p+%2F+WID-SEC-2026-1738%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596367/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-32906+%7C+OpenClaw+up+to+2026.5.11+Slack+Plugin+authorization+%28GHSA-wv26-j37q-2g7p+%2F+WID-SEC-2026-1738%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:38:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.12.6]]></title> 
<description><![CDATA[chore: bump version to 15.12.6 ]]></description>
<link>https://tsecurity.de/de/3596361/IT+Reverse+Engineering/Tools/v15.12.6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596361/IT+Reverse+Engineering/Tools/v15.12.6/</guid>
<pubDate>Sun, 14 Jun 2026 02:35:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12174 | D-Link DCS-935L 1.10.01 HTTP /web/cgi-bin/greece/rhea snprintf data format string (EUVD-2026-36654)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string.

This vulnerability is traded as CVE-2026-12174. The attack may be launched remotely. Furthermore, there is an exploit available. ]]></description>
<link>https://tsecurity.de/de/3596351/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12174+%7C+D-Link+DCS-935L+1.10.01+HTTP+%2Fweb%2Fcgi-bin%2Fgreece%2Frhea+snprintf+data+format+string+%28EUVD-2026-36654%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596351/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12174+%7C+D-Link+DCS-935L+1.10.01+HTTP+%2Fweb%2Fcgi-bin%2Fgreece%2Frhea+snprintf+data+format+string+%28EUVD-2026-36654%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-45172 | CyberArk Software PAM Self-Hosted/Privilege Cloud up to 14.0.5/14.2.4/14.6.2/15.0.1 os command injection (EUVD-2026-36364)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in CyberArk Software PAM Self-Hosted and Privilege Cloud up to 14.0.5/14.2.4/14.6.2/15.0.1. The affected element is an unknown function. This manipulation causes os command injection.

The identification of this vulnerability is CVE-2026-45172. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596350/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45172+%7C+CyberArk+Software+PAM+Self-Hosted%2FPrivilege+Cloud+up+to+14.0.5%2F14.2.4%2F14.6.2%2F15.0.1+os+command+injection+%28EUVD-2026-36364%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596350/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-45172+%7C+CyberArk+Software+PAM+Self-Hosted%2FPrivilege+Cloud+up+to+14.0.5%2F14.2.4%2F14.6.2%2F15.0.1+os+command+injection+%28EUVD-2026-36364%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47208 | patriksimek vm2 up to 3.11.3 dynamically-managed code resources (EUVD-2026-36447)]]></title> 
<description><![CDATA[A vulnerability was found in patriksimek vm2 up to 3.11.3 and classified as critical. This affects an unknown function. Such manipulation leads to dynamically-managed code resources.

This vulnerability is listed as CVE-2026-47208. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596349/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47208+%7C+patriksimek+vm2+up+to+3.11.3+dynamically-managed+code+resources+%28EUVD-2026-36447%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596349/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47208+%7C+patriksimek+vm2+up+to+3.11.3+dynamically-managed+code+resources+%28EUVD-2026-36447%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47210 | patriksimek vm2 up to 3.11.3 Promise.prototype.finally dynamically-managed code resources (EUVD-2026-36448)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in patriksimek vm2 up to 3.11.3. This affects the function Promise.prototype.finally. Such manipulation leads to dynamically-managed code resources.

This vulnerability is uniquely identified as CVE-2026-47210. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596348/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47210+%7C+patriksimek+vm2+up+to+3.11.3+Promise.prototype.finally+dynamically-managed+code+resources+%28EUVD-2026-36448%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596348/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47210+%7C+patriksimek+vm2+up+to+3.11.3+Promise.prototype.finally+dynamically-managed+code+resources+%28EUVD-2026-36448%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47140 | patriksimek vm2 up to 3.11.3 protection mechanism (EUVD-2026-36446)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in patriksimek vm2 up to 3.11.3. Affected by this issue is some unknown functionality. This manipulation causes protection mechanism failure.

This vulnerability is handled as CVE-2026-47140. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596347/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47140+%7C+patriksimek+vm2+up+to+3.11.3+protection+mechanism+%28EUVD-2026-36446%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596347/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47140+%7C+patriksimek+vm2+up+to+3.11.3+protection+mechanism+%28EUVD-2026-36446%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47137 | patriksimek vm2 up to 3.11.3 Configuration dynamically-managed code resources (EUVD-2026-36443)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in patriksimek vm2 up to 3.11.3. Affected is an unknown function of the component Configuration Handler. The manipulation leads to dynamically-managed code resources.

This vulnerability is traded as CVE-2026-47137. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596346/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47137+%7C+patriksimek+vm2+up+to+3.11.3+Configuration+dynamically-managed+code+resources+%28EUVD-2026-36443%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596346/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47137+%7C+patriksimek+vm2+up+to+3.11.3+Configuration+dynamically-managed+code+resources+%28EUVD-2026-36443%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47131 | patriksimek vm2 up to 3.11.3 dynamically-managed code resources (EUVD-2026-36441)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in patriksimek vm2 up to 3.11.3. The affected element is an unknown function. The manipulation results in dynamically-managed code resources.

This vulnerability is identified as CVE-2026-47131. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596345/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47131+%7C+patriksimek+vm2+up+to+3.11.3+dynamically-managed+code+resources+%28EUVD-2026-36441%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596345/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47131+%7C+patriksimek+vm2+up+to+3.11.3+dynamically-managed+code+resources+%28EUVD-2026-36441%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-40677 | AMD Management Console/Ryzen Master/µProf up to 13.x cleartext transmission (EUVD-2026-36488)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in AMD Management Console, Ryzen Master and &micro;Prof up to 13.x. This affects an unknown function. Such manipulation leads to cleartext transmission of sensitive information.

This vulnerability is traded as CVE-2026-40677. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596344/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-40677+%7C+AMD+Management+Console%2FRyzen+Master%2F%C2%B5Prof+up+to+13.x+cleartext+transmission+%28EUVD-2026-36488%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596344/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-40677+%7C+AMD+Management+Console%2FRyzen+Master%2F%C2%B5Prof+up+to+13.x+cleartext+transmission+%28EUVD-2026-36488%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47135 | patriksimek vm2 up to 3.11.3 protection mechanism (EUVD-2026-36442)]]></title> 
<description><![CDATA[A vulnerability has been found in patriksimek vm2 up to 3.11.3 and classified as problematic. The impacted element is an unknown function. This manipulation causes protection mechanism failure.

This vulnerability is tracked as CVE-2026-47135. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596343/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47135+%7C+patriksimek+vm2+up+to+3.11.3+protection+mechanism+%28EUVD-2026-36442%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596343/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47135+%7C+patriksimek+vm2+up+to+3.11.3+protection+mechanism+%28EUVD-2026-36442%29/</guid>
<pubDate>Sun, 14 Jun 2026 02:02:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11670 | Google Chrome up to 149.0.7827.53 PDF use after free (ID 515469 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Google Chrome. Affected by this issue is some unknown functionality of the component PDF. The manipulation results in use after free.

This vulnerability was named CVE-2026-11670. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596311/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11670+%7C+Google+Chrome+up+to+149.0.7827.53+PDF+use+after+free+%28ID+515469+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596311/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11670+%7C+Google+Chrome+up+to+149.0.7827.53+PDF+use+after+free+%28ID+515469+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:46:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11671 | Google Chrome up to 149.0.7827.53 Navigation use after free (ID 516608 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability was found in Google Chrome and classified as critical. Impacted is an unknown function of the component Navigation. Executing a manipulation can lead to use after free.

This vulnerability is tracked as CVE-2026-11671. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596310/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11671+%7C+Google+Chrome+up+to+149.0.7827.53+Navigation+use+after+free+%28ID+516608+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596310/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11671+%7C+Google+Chrome+up+to+149.0.7827.53+Navigation+use+after+free+%28ID+516608+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:46:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11673 | Google Chrome up to 149.0.7827.53 InterestGroups use after free (ID 516902 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Google Chrome. This vulnerability affects unknown code of the component InterestGroups. Such manipulation leads to use after free.

This vulnerability is referenced as CVE-2026-11673. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596309/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11673+%7C+Google+Chrome+up+to+149.0.7827.53+InterestGroups+use+after+free+%28ID+516902+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596309/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11673+%7C+Google+Chrome+up+to+149.0.7827.53+InterestGroups+use+after+free+%28ID+516902+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:46:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11674 | Google Chrome up to 149.0.7827.53 Guest View use after free (ID 516910 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability has been found in Google Chrome and classified as critical. This issue affects some unknown processing of the component Guest View. Performing a manipulation results in use after free.

This vulnerability is identified as CVE-2026-11674. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596308/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11674+%7C+Google+Chrome+up+to+149.0.7827.53+Guest+View+use+after+free+%28ID+516910+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596308/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11674+%7C+Google+Chrome+up+to+149.0.7827.53+Guest+View+use+after+free+%28ID+516910+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:46:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11675 | Google Chrome up to 149.0.7827.53 Skia cross-domain policy (ID 516915 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Skia. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.

This vulnerability appears as CVE-2026-11675. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596307/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11675+%7C+Google+Chrome+up+to+149.0.7827.53+Skia+cross-domain+policy+%28ID+516915+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596307/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11675+%7C+Google+Chrome+up+to+149.0.7827.53+Skia+cross-domain+policy+%28ID+516915+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:46:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53826 | OpenClaw up to 2026.4.25 exposure of resource (GHSA-6c4r-g249-wv3c / EUVD-2026-36614)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.25. This affects an unknown part. The manipulation leads to exposure of resource.

This vulnerability is uniquely identified as CVE-2026-53826. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596286/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53826+%7C+OpenClaw+up+to+2026.4.25+exposure+of+resource+%28GHSA-6c4r-g249-wv3c+%2F+EUVD-2026-36614%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596286/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53826+%7C+OpenClaw+up+to+2026.4.25+exposure+of+resource+%28GHSA-6c4r-g249-wv3c+%2F+EUVD-2026-36614%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53825 | OpenClaw up to 2026.4.6 memory-wiki Ingest Feature path traversal (GHSA-p2fh-f5fc-44hr / EUVD-2026-36613)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in OpenClaw up to 2026.4.6. Affected is an unknown function of the component memory-wiki Ingest Feature. The manipulation leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-53825. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596285/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53825+%7C+OpenClaw+up+to+2026.4.6+memory-wiki+Ingest+Feature+path+traversal+%28GHSA-p2fh-f5fc-44hr+%2F+EUVD-2026-36613%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596285/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53825+%7C+OpenClaw+up+to+2026.4.6+memory-wiki+Ingest+Feature+path+traversal+%28GHSA-p2fh-f5fc-44hr+%2F+EUVD-2026-36613%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53827 | OpenClaw up to 2026.5.1 server-side request forgery (GHSA-grc3-2j34-p6gm / EUVD-2026-36615)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.1. It has been declared as critical. The impacted element is an unknown function. The manipulation results in server-side request forgery.

This vulnerability is known as CVE-2026-53827. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596284/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53827+%7C+OpenClaw+up+to+2026.5.1+server-side+request+forgery+%28GHSA-grc3-2j34-p6gm+%2F+EUVD-2026-36615%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596284/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53827+%7C+OpenClaw+up+to+2026.5.1+server-side+request+forgery+%28GHSA-grc3-2j34-p6gm+%2F+EUVD-2026-36615%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53821 | OpenClaw up to 2026.5.17 Websocket Connection authorization (GHSA-qjpc-qf9m-xwmr / EUVD-2026-36609)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in OpenClaw up to 2026.5.17. The impacted element is an unknown function of the component Websocket Connection Handler. This manipulation causes missing authorization.

The identification of this vulnerability is CVE-2026-53821. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596283/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53821+%7C+OpenClaw+up+to+2026.5.17+Websocket+Connection+authorization+%28GHSA-qjpc-qf9m-xwmr+%2F+EUVD-2026-36609%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596283/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53821+%7C+OpenClaw+up+to+2026.5.17+Websocket+Connection+authorization+%28GHSA-qjpc-qf9m-xwmr+%2F+EUVD-2026-36609%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53822 | OpenClaw up to 2026.5.17 Command Argument toctou (GHSA-2j8v-hwgc-x698 / EUVD-2026-36610)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.17. It has been rated as critical. This vulnerability affects unknown code of the component Command Argument Handler. The manipulation leads to time-of-check time-of-use.

This vulnerability is traded as CVE-2026-53822. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596282/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53822+%7C+OpenClaw+up+to+2026.5.17+Command+Argument+toctou+%28GHSA-2j8v-hwgc-x698+%2F+EUVD-2026-36610%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596282/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53822+%7C+OpenClaw+up+to+2026.5.17+Command+Argument+toctou+%28GHSA-2j8v-hwgc-x698+%2F+EUVD-2026-36610%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53823 | OpenClaw up to 2026.5.2 allowFrom Feature authentication spoofing (GHSA-c29c-2q9c-pc86 / EUVD-2026-36611)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.5.2. This issue affects some unknown processing of the component allowFrom Feature. The manipulation results in authentication bypass by spoofing.

This vulnerability is known as CVE-2026-53823. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596281/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53823+%7C+OpenClaw+up+to+2026.5.2+allowFrom+Feature+authentication+spoofing+%28GHSA-c29c-2q9c-pc86+%2F+EUVD-2026-36611%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596281/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53823+%7C+OpenClaw+up+to+2026.5.2+allowFrom+Feature+authentication+spoofing+%28GHSA-c29c-2q9c-pc86+%2F+EUVD-2026-36611%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-41157 | Imagination Graphics DDK up to 26.1 RTM GPU user-space Driver out-of-bounds write (EUVD-2026-36607)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Imagination Graphics DDK up to 1.18 RTM/23.2 RTM/24.2 RTM/25.3 RTM/26.1 RTM. The affected element is an unknown function of the component GPU user-space Driver. The manipulation results in out-of-bounds write.

This vulnerability was named CVE-2026-41157. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596280/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-41157+%7C+Imagination+Graphics+DDK+up+to+26.1+RTM+GPU+user-space+Driver+out-of-bounds+write+%28EUVD-2026-36607%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596280/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-41157+%7C+Imagination+Graphics+DDK+up+to+26.1+RTM+GPU+user-space+Driver+out-of-bounds+write+%28EUVD-2026-36607%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-41155 | Imagination Graphics DDK up to 26.1 RTM Kernel improper isolation or compartmentalization (EUVD-2026-36606)]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in Imagination Graphics DDK up to 1.18 RTM/23.2 RTM/24.2 RTM/25.3 RTM/26.1 RTM. Affected is an unknown function of the component Kernel Module. Executing a manipulation can lead to improper isolation or compartmentalization.

This vulnerability is tracked as CVE-2026-41155. The attack is only possible within the local network. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596279/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-41155+%7C+Imagination+Graphics+DDK+up+to+26.1+RTM+Kernel+improper+isolation+or+compartmentalization+%28EUVD-2026-36606%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596279/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-41155+%7C+Imagination+Graphics+DDK+up+to+26.1+RTM+Kernel+improper+isolation+or+compartmentalization+%28EUVD-2026-36606%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-34195 | Imagination Graphics DDK up to 24.2 RTM/25.3 RTM out-of-bounds write (EUVD-2026-36605)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Imagination Graphics DDK up to 24.2 RTM/25.3 RTM. Affected by this issue is some unknown functionality. Executing a manipulation can lead to out-of-bounds write.

This vulnerability is handled as CVE-2026-34195. The attack can only be done within the local network. There is not any exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596278/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-34195+%7C+Imagination+Graphics+DDK+up+to+24.2+RTM%2F25.3+RTM+out-of-bounds+write+%28EUVD-2026-36605%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596278/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-34195+%7C+Imagination+Graphics+DDK+up+to+24.2+RTM%2F25.3+RTM+out-of-bounds+write+%28EUVD-2026-36605%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53820 | OpenClaw up to 2026.5.11 authorization (GHSA-qh2f-99mv-mrcf / EUVD-2026-36608)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.11. It has been declared as problematic. This affects an unknown part. Executing a manipulation can lead to missing authorization.

This vulnerability appears as CVE-2026-53820. The attack requires local access. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596277/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53820+%7C+OpenClaw+up+to+2026.5.11+authorization+%28GHSA-qh2f-99mv-mrcf+%2F+EUVD-2026-36608%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596277/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53820+%7C+OpenClaw+up+to+2026.5.11+authorization+%28GHSA-qh2f-99mv-mrcf+%2F+EUVD-2026-36608%29/</guid>
<pubDate>Sun, 14 Jun 2026 00:20:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12027 | Google Chrome up to 149.0.7827.103 Headless sandbox (ID 517517 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Google Chrome. Impacted is an unknown function of the component Headless. Such manipulation leads to sandbox issue.

This vulnerability is documented as CVE-2026-12027. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596225/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12027+%7C+Google+Chrome+up+to+149.0.7827.103+Headless+sandbox+%28ID+517517+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596225/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12027+%7C+Google+Chrome+up+to+149.0.7827.103+Headless+sandbox+%28ID+517517+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12028 | Google Chrome up to 149.0.7827.103 on Android GPU use after free (ID 517555 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability has been found in Google Chrome on Android and classified as critical. Impacted is an unknown function of the component GPU. Performing a manipulation results in use after free.

This vulnerability is known as CVE-2026-12028. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596224/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12028+%7C+Google+Chrome+up+to+149.0.7827.103+on+Android+GPU+use+after+free+%28ID+517555+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596224/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12028+%7C+Google+Chrome+up+to+149.0.7827.103+on+Android+GPU+use+after+free+%28ID+517555+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12029 | Google Chrome up to 149.0.7827.103 on Windows Video use after free (ID 518002 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Google Chrome on Windows. The affected element is an unknown function of the component Video. Performing a manipulation results in use after free.

This vulnerability is reported as CVE-2026-12029. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596223/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12029+%7C+Google+Chrome+up+to+149.0.7827.103+on+Windows+Video+use+after+free+%28ID+518002+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596223/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12029+%7C+Google+Chrome+up+to+149.0.7827.103+on+Windows+Video+use+after+free+%28ID+518002+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12031 | Google Chrome up to 149.0.7827.103 on Windows Views sandbox (ID 518045 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, was found in Google Chrome on Windows. The impacted element is an unknown function of the component Views. Executing a manipulation can lead to sandbox issue.

This vulnerability appears as CVE-2026-12031. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596222/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12031+%7C+Google+Chrome+up+to+149.0.7827.103+on+Windows+Views+sandbox+%28ID+518045+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596222/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12031+%7C+Google+Chrome+up+to+149.0.7827.103+on+Windows+Views+sandbox+%28ID+518045+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12032 | Google Chrome up to 149.0.7827.103 on Android Passwords improper isolation or compartmentalization (ID 518128 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability was found in Google Chrome on Android. It has been classified as problematic. The impacted element is an unknown function of the component Passwords. The manipulation leads to improper isolation or compartmentalization.

This vulnerability is uniquely identified as CVE-2026-12032. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596221/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12032+%7C+Google+Chrome+up+to+149.0.7827.103+on+Android+Passwords+improper+isolation+or+compartmentalization+%28ID+518128+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596221/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12032+%7C+Google+Chrome+up+to+149.0.7827.103+on+Android+Passwords+improper+isolation+or+compartmentalization+%28ID+518128+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12034 | Google Chrome up to 149.0.7827.103 on Linux File sandbox (ID 519258 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Google Chrome on Linux. Affected is an unknown function of the component File Handler. Such manipulation leads to sandbox issue.

This vulnerability is referenced as CVE-2026-12034. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596220/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12034+%7C+Google+Chrome+up+to+149.0.7827.103+on+Linux+File+sandbox+%28ID+519258+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596220/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12034+%7C+Google+Chrome+up+to+149.0.7827.103+on+Linux+File+sandbox+%28ID+519258+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12033 | Google Chrome up to 149.0.7827.103 VideoCapture out-of-bounds (ID 519248 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability has been found in Google Chrome and classified as problematic. This affects an unknown function of the component VideoCapture. The manipulation leads to out-of-bounds read.

This vulnerability is traded as CVE-2026-12033. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596219/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12033+%7C+Google+Chrome+up+to+149.0.7827.103+VideoCapture+out-of-bounds+%28ID+519248+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596219/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12033+%7C+Google+Chrome+up+to+149.0.7827.103+VideoCapture+out-of-bounds+%28ID+519248+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-12035 | Google Chrome up to 149.0.7827.103 on Windows Views use after free (ID 520210 / WID-SEC-2026-1893)]]></title> 
<description><![CDATA[A vulnerability was found in Google Chrome on Windows and classified as critical. This impacts an unknown function of the component Views. The manipulation results in use after free.

This vulnerability is known as CVE-2026-12035. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596218/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12035+%7C+Google+Chrome+up+to+149.0.7827.103+on+Windows+Views+use+after+free+%28ID+520210+%2F+WID-SEC-2026-1893%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596218/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-12035+%7C+Google+Chrome+up+to+149.0.7827.103+on+Windows+Views+use+after+free+%28ID+520210+%2F+WID-SEC-2026-1893%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:19 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-47367 | Ubiquiti UID Enterprise Agent up to 1.61.3 input validation (WID-SEC-2026-1872)]]></title> 
<description><![CDATA[A vulnerability described as very critical has been identified in Ubiquiti UID Enterprise Agent up to 1.61.3. This impacts an unknown function. Executing a manipulation can lead to improper input validation.

This vulnerability is tracked as CVE-2026-47367. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596217/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47367+%7C+Ubiquiti+UID+Enterprise+Agent+up+to+1.61.3+input+validation+%28WID-SEC-2026-1872%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596217/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-47367+%7C+Ubiquiti+UID+Enterprise+Agent+up+to+1.61.3+input+validation+%28WID-SEC-2026-1872%29/</guid>
<pubDate>Sat, 13 Jun 2026 23:38:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-42573 | sveltejs svelte up to 5.55.6 cross site scripting (GHSA-rcqx-6q8c-2c42)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in sveltejs svelte up to 5.55.6. Affected by this issue is some unknown functionality. This manipulation causes cross site scripting.

This vulnerability is registered as CVE-2026-42573. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596205/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42573+%7C+sveltejs+svelte+up+to+5.55.6+cross+site+scripting+%28GHSA-rcqx-6q8c-2c42%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596205/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42573+%7C+sveltejs+svelte+up+to+5.55.6+cross+site+scripting+%28GHSA-rcqx-6q8c-2c42%29/</guid>
<pubDate>Sat, 13 Jun 2026 22:50:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-42599 | sveltejs svelte up to 5.55.6 cross site scripting (GHSA-pr6f-5x2q-rwfp)]]></title> 
<description><![CDATA[A vulnerability has been found in sveltejs svelte up to 5.55.6 and classified as problematic. This impacts an unknown function. The manipulation leads to cross site scripting.

This vulnerability is referenced as CVE-2026-42599. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596204/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42599+%7C+sveltejs+svelte+up+to+5.55.6+cross+site+scripting+%28GHSA-pr6f-5x2q-rwfp%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596204/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42599+%7C+sveltejs+svelte+up+to+5.55.6+cross+site+scripting+%28GHSA-pr6f-5x2q-rwfp%29/</guid>
<pubDate>Sat, 13 Jun 2026 22:50:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-42567 | sveltejs svelte up to 5.55.6 redos (GHSA-9rmh-mm8f-r9h6)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in sveltejs svelte up to 5.55.6. This affects an unknown function. Executing a manipulation can lead to inefficient regular expression complexity.

The identification of this vulnerability is CVE-2026-42567. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596175/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42567+%7C+sveltejs+svelte+up+to+5.55.6+redos+%28GHSA-9rmh-mm8f-r9h6%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596175/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-42567+%7C+sveltejs+svelte+up+to+5.55.6+redos+%28GHSA-9rmh-mm8f-r9h6%29/</guid>
<pubDate>Sat, 13 Jun 2026 22:13:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-38615 | DedeCMS 5.7.118 file_manage_control.php os command injection]]></title> 
<description><![CDATA[A vulnerability was found in DedeCMS 5.7.118 and classified as critical. Affected is an unknown function of the file file_manage_control.php. The manipulation results in os command injection.

This vulnerability is identified as CVE-2026-38615. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596174/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-38615+%7C+DedeCMS+5.7.118+file_manage_control.php+os+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596174/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-38615+%7C+DedeCMS+5.7.118+file_manage_control.php+os+command+injection/</guid>
<pubDate>Sat, 13 Jun 2026 22:13:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3088 | Netgear RBSE960 prior 7.2.7.15 out-of-bounds write]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Netgear RBR860, RBRE950, RBRE960, RBRE970, RBRE971, RBS860, RBSE950 and RBSE960. Affected by this issue is some unknown functionality. Executing a manipulation can lead to out-of-bounds write.

The identification of this vulnerability is CVE-2026-3088. The attack needs to be done within the local network. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596173/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3088+%7C+Netgear+RBSE960+prior+7.2.7.15+out-of-bounds+write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596173/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3088+%7C+Netgear+RBSE960+prior+7.2.7.15+out-of-bounds+write/</guid>
<pubDate>Sat, 13 Jun 2026 22:13:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53837 | OpenClaw up to 2026.5.5 Mattermost failing open (GHSA-gp79-m99v-gjmh / EUVD-2026-36625)]]></title> 
<description><![CDATA[A vulnerability identified as problematic has been detected in OpenClaw up to 2026.5.5. Impacted is an unknown function of the component Mattermost Handler. This manipulation causes not failing securely.

This vulnerability is handled as CVE-2026-53837. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596161/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53837+%7C+OpenClaw+up+to+2026.5.5+Mattermost+failing+open+%28GHSA-gp79-m99v-gjmh+%2F+EUVD-2026-36625%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596161/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53837+%7C+OpenClaw+up+to+2026.5.5+Mattermost+failing+open+%28GHSA-gp79-m99v-gjmh+%2F+EUVD-2026-36625%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53838 | OpenClaw up to 2026.5.26 toctou (GHSA-83w9-h5wv-j9xm / EUVD-2026-36626)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in OpenClaw up to 2026.5.26. The affected element is an unknown function. Such manipulation leads to time-of-check time-of-use.

This vulnerability is uniquely identified as CVE-2026-53838. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596160/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53838+%7C+OpenClaw+up+to+2026.5.26+toctou+%28GHSA-83w9-h5wv-j9xm+%2F+EUVD-2026-36626%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596160/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53838+%7C+OpenClaw+up+to+2026.5.26+toctou+%28GHSA-83w9-h5wv-j9xm+%2F+EUVD-2026-36626%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53836 | OpenClaw up to 2026.5.11 Allowlist Parser incomplete blacklist (GHSA-j472-gf56-x589 / EUVD-2026-36624)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.5.11. This impacts an unknown function of the component Allowlist Parser. Such manipulation leads to incomplete blacklist.

This vulnerability is uniquely identified as CVE-2026-53836. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596159/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53836+%7C+OpenClaw+up+to+2026.5.11+Allowlist+Parser+incomplete+blacklist+%28GHSA-j472-gf56-x589+%2F+EUVD-2026-36624%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596159/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53836+%7C+OpenClaw+up+to+2026.5.11+Allowlist+Parser+incomplete+blacklist+%28GHSA-j472-gf56-x589+%2F+EUVD-2026-36624%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53834 | OpenClaw up to 2026.4.26 Configuration authorization (GHSA-77pv-3w4q-vrj5 / EUVD-2026-36622)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in OpenClaw up to 2026.4.26. This issue affects some unknown processing of the component Configuration Handler. This manipulation causes incorrect authorization.

The identification of this vulnerability is CVE-2026-53834. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596158/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53834+%7C+OpenClaw+up+to+2026.4.26+Configuration+authorization+%28GHSA-77pv-3w4q-vrj5+%2F+EUVD-2026-36622%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596158/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53834+%7C+OpenClaw+up+to+2026.4.26+Configuration+authorization+%28GHSA-77pv-3w4q-vrj5+%2F+EUVD-2026-36622%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53835 | OpenClaw up to 2026.5.5 Dynamic-Agent Binding Feature authorization (GHSA-3wqp-prf6-2m72 / EUVD-2026-36623)]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in OpenClaw up to 2026.5.5. The affected element is an unknown function of the component Dynamic-Agent Binding Feature. Performing a manipulation results in incorrect authorization.

This vulnerability is identified as CVE-2026-53835. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596157/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53835+%7C+OpenClaw+up+to+2026.5.5+Dynamic-Agent+Binding+Feature+authorization+%28GHSA-3wqp-prf6-2m72+%2F+EUVD-2026-36623%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596157/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53835+%7C+OpenClaw+up+to+2026.5.5+Dynamic-Agent+Binding+Feature+authorization+%28GHSA-3wqp-prf6-2m72+%2F+EUVD-2026-36623%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53832 | OpenClaw up to 2026.5.17 authentication spoofing (GHSA-rggc-m335-3wvj / EUVD-2026-36620)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in OpenClaw up to 2026.5.17. This vulnerability affects unknown code. Such manipulation leads to authentication bypass by spoofing.

This vulnerability is uniquely identified as CVE-2026-53832. Local access is required to approach this attack. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596156/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53832+%7C+OpenClaw+up+to+2026.5.17+authentication+spoofing+%28GHSA-rggc-m335-3wvj+%2F+EUVD-2026-36620%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596156/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53832+%7C+OpenClaw+up+to+2026.5.17+authentication+spoofing+%28GHSA-rggc-m335-3wvj+%2F+EUVD-2026-36620%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53830 | OpenClaw up to 2026.4.21 session expiration (GHSA-275c-xpvc-jgfw / EUVD-2026-36618)]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in OpenClaw up to 2026.4.21. This affects an unknown function. Such manipulation leads to session expiration.

This vulnerability is referenced as CVE-2026-53830. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596155/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53830+%7C+OpenClaw+up+to+2026.4.21+session+expiration+%28GHSA-275c-xpvc-jgfw+%2F+EUVD-2026-36618%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596155/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53830+%7C+OpenClaw+up+to+2026.4.21+session+expiration+%28GHSA-275c-xpvc-jgfw+%2F+EUVD-2026-36618%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53828 | OpenClaw up to 2026.5.5 Policy Enforcement authorization (GHSA-p73f-w79w-jqr5 / EUVD-2026-36616)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in OpenClaw up to 2026.5.5. Impacted is an unknown function of the component Policy Enforcement Handler. Such manipulation leads to incorrect authorization.

This vulnerability is referenced as CVE-2026-53828. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596154/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53828+%7C+OpenClaw+up+to+2026.5.5+Policy+Enforcement+authorization+%28GHSA-p73f-w79w-jqr5+%2F+EUVD-2026-36616%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596154/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53828+%7C+OpenClaw+up+to+2026.5.5+Policy+Enforcement+authorization+%28GHSA-p73f-w79w-jqr5+%2F+EUVD-2026-36616%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53829 | OpenClaw up to 2026.5.17 clickjacking (GHSA-xww8-gqvh-92x9 / EUVD-2026-36617)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.5.17. It has been rated as problematic. This affects an unknown function. This manipulation causes clickjacking.

This vulnerability is handled as CVE-2026-53829. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596153/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53829+%7C+OpenClaw+up+to+2026.5.17+clickjacking+%28GHSA-xww8-gqvh-92x9+%2F+EUVD-2026-36617%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596153/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53829+%7C+OpenClaw+up+to+2026.5.17+clickjacking+%28GHSA-xww8-gqvh-92x9+%2F+EUVD-2026-36617%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53831 | OpenClaw up to 2026.5.17 on POSIX Configuration Data toctou (GHSA-mhq8-78pj-5j79 / EUVD-2026-36619)]]></title> 
<description><![CDATA[A vulnerability described as critical has been identified in OpenClaw up to 2026.5.17 on POSIX. Affected by this vulnerability is an unknown functionality of the component Configuration Data Handler. The manipulation results in time-of-check time-of-use.

This vulnerability was named CVE-2026-53831. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3596152/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53831+%7C+OpenClaw+up+to+2026.5.17+on+POSIX+Configuration+Data+toctou+%28GHSA-mhq8-78pj-5j79+%2F+EUVD-2026-36619%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596152/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53831+%7C+OpenClaw+up+to+2026.5.17+on+POSIX+Configuration+Data+toctou+%28GHSA-mhq8-78pj-5j79+%2F+EUVD-2026-36619%29/</guid>
<pubDate>Sat, 13 Jun 2026 21:44:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.12.5]]></title> 
<description><![CDATA[chore: bump version to 15.12.5 ]]></description>
<link>https://tsecurity.de/de/3596121/IT+Reverse+Engineering/Tools/v15.12.5/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596121/IT+Reverse+Engineering/Tools/v15.12.5/</guid>
<pubDate>Sat, 13 Jun 2026 21:51:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11662 | Google Chrome up to 149.0.7827.53 Bindings type confusion (ID 513773 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Google Chrome. This affects an unknown function of the component Bindings. Such manipulation leads to type confusion.

This vulnerability is traded as CVE-2026-11662. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596107/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11662+%7C+Google+Chrome+up+to+149.0.7827.53+Bindings+type+confusion+%28ID+513773+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596107/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11662+%7C+Google+Chrome+up+to+149.0.7827.53+Bindings+type+confusion+%28ID+513773+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:43:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11663 | Google Chrome up to 149.0.7827.53 Skia use after free (ID 513820 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in Google Chrome. This impacts an unknown function of the component Skia. Performing a manipulation results in use after free.

This vulnerability is known as CVE-2026-11663. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596106/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11663+%7C+Google+Chrome+up+to+149.0.7827.53+Skia+use+after+free+%28ID+513820+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596106/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11663+%7C+Google+Chrome+up+to+149.0.7827.53+Skia+use+after+free+%28ID+513820+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:43:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11665 | Google Chrome up to 149.0.7827.53 on Windows Dawn out-of-bounds (ID 513948 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability was found in Google Chrome on Windows. It has been declared as problematic. The impacted element is an unknown function of the component Dawn. The manipulation results in out-of-bounds read.

This vulnerability is cataloged as CVE-2026-11665. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596105/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11665+%7C+Google+Chrome+up+to+149.0.7827.53+on+Windows+Dawn+out-of-bounds+%28ID+513948+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596105/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11665+%7C+Google+Chrome+up+to+149.0.7827.53+on+Windows+Dawn+out-of-bounds+%28ID+513948+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:43:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11668 | Google Chrome up to 149.0.7827.53 on Linux Codecs uninitialized variable (ID 515419 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in Google Chrome on Linux. This vulnerability affects unknown code of the component Codecs. The manipulation results in use of uninitialized variable.

This vulnerability is identified as CVE-2026-11668. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596104/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11668+%7C+Google+Chrome+up+to+149.0.7827.53+on+Linux+Codecs+uninitialized+variable+%28ID+515419+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596104/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11668+%7C+Google+Chrome+up+to+149.0.7827.53+on+Linux+Codecs+uninitialized+variable+%28ID+515419+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:43:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11669 | Google Chrome up to 149.0.7827.53 on ChromeOS Media external control of assumed-immutable web parameter (ID 515429 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Google Chrome on ChromeOS. This affects an unknown part of the component Media. This manipulation causes external control of assumed-immutable web parameter.

The identification of this vulnerability is CVE-2026-11669. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596103/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11669+%7C+Google+Chrome+up+to+149.0.7827.53+on+ChromeOS+Media+external+control+of+assumed-immutable+web+parameter+%28ID+515429+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596103/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11669+%7C+Google+Chrome+up+to+149.0.7827.53+on+ChromeOS+Media+external+control+of+assumed-immutable+web+parameter+%28ID+515429+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:43:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53833 | OpenClaw up to 2026.4.28 QQBot authentication spoofing (GHSA-jvm4-4j77-39p6 / EUVD-2026-36621)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in OpenClaw up to 2026.4.28. This vulnerability affects unknown code of the component QQBot Handler. The manipulation results in authentication bypass by spoofing.

This vulnerability was named CVE-2026-53833. The attack needs to be approached locally. There is no available exploit.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596102/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53833+%7C+OpenClaw+up+to+2026.4.28+QQBot+authentication+spoofing+%28GHSA-jvm4-4j77-39p6+%2F+EUVD-2026-36621%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596102/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53833+%7C+OpenClaw+up+to+2026.4.28+QQBot+authentication+spoofing+%28GHSA-jvm4-4j77-39p6+%2F+EUVD-2026-36621%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-53824 | OpenClaw up to 2026.4.23 session expiration (GHSA-4m3v-q747-pc6h / EUVD-2026-36612)]]></title> 
<description><![CDATA[A vulnerability was found in OpenClaw up to 2026.4.23. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in session expiration.

This vulnerability is known as CVE-2026-53824. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596101/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53824+%7C+OpenClaw+up+to+2026.4.23+session+expiration+%28GHSA-4m3v-q747-pc6h+%2F+EUVD-2026-36612%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596101/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-53824+%7C+OpenClaw+up+to+2026.4.23+session+expiration+%28GHSA-4m3v-q747-pc6h+%2F+EUVD-2026-36612%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11624 | Google MCP Toolbox for Databases up to 0.24.x origin validation (Issue 3113 / EUVD-2026-36650)]]></title> 
<description><![CDATA[A vulnerability was found in Google MCP Toolbox for Databases up to 0.24.x and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to origin validation error.

This vulnerability is tracked as CVE-2026-11624. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596100/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11624+%7C+Google+MCP+Toolbox+for+Databases+up+to+0.24.x+origin+validation+%28Issue+3113+%2F+EUVD-2026-36650%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596100/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11624+%7C+Google+MCP+Toolbox+for+Databases+up+to+0.24.x+origin+validation+%28Issue+3113+%2F+EUVD-2026-36650%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-5513 | ladela Online Scheduling and Appointment Booking System Plugin setting cross site scripting (EUVD-2026-36651)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in ladela Online Scheduling and Appointment Booking System Plugin up to 27.2 on WordPress. Impacted is an unknown function of the component setting Handler. Such manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2026-5513. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3596099/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-5513+%7C+ladela+Online+Scheduling+and+Appointment+Booking+System+Plugin+setting+cross+site+scripting+%28EUVD-2026-36651%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596099/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-5513+%7C+ladela+Online+Scheduling+and+Appointment+Booking+System+Plugin+setting+cross+site+scripting+%28EUVD-2026-36651%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-1291 | tigroumeow Meow Gallery Plugin up to 5.4.4 on WordPress REST API Endpoint authorization (EUVD-2026-36649)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in tigroumeow Meow Gallery Plugin up to 5.4.4 on WordPress. This impacts an unknown function of the component REST API Endpoint. This manipulation causes authorization bypass.

The identification of this vulnerability is CVE-2026-1291. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596098/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-1291+%7C+tigroumeow+Meow+Gallery+Plugin+up+to+5.4.4+on+WordPress+REST+API+Endpoint+authorization+%28EUVD-2026-36649%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596098/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-1291+%7C+tigroumeow+Meow+Gallery+Plugin+up+to+5.4.4+on+WordPress+REST+API+Endpoint+authorization+%28EUVD-2026-36649%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9629 | codesupplyco Canvas Plugin up to 2.5.2 on WordPress day cross site scripting (EUVD-2026-36648)]]></title> 
<description><![CDATA[A vulnerability was found in codesupplyco Canvas Plugin up to 2.5.2 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument day results in cross site scripting.

This vulnerability is cataloged as CVE-2026-9629. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596097/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9629+%7C+codesupplyco+Canvas+Plugin+up+to+2.5.2+on+WordPress+day+cross+site+scripting+%28EUVD-2026-36648%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596097/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9629+%7C+codesupplyco+Canvas+Plugin+up+to+2.5.2+on+WordPress+day+cross+site+scripting+%28EUVD-2026-36648%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9062 | Store Locator WordPress Plugin up to 1.6.8 on WordPress information disclosure (EUVD-2026-36644)]]></title> 
<description><![CDATA[A vulnerability classified as problematic was found in Store Locator WordPress Plugin up to 1.6.8 on WordPress. This affects an unknown function. The manipulation results in information disclosure.

This vulnerability was named CVE-2026-9062. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596096/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9062+%7C+Store+Locator+WordPress+Plugin+up+to+1.6.8+on+WordPress+information+disclosure+%28EUVD-2026-36644%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596096/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9062+%7C+Store+Locator+WordPress+Plugin+up+to+1.6.8+on+WordPress+information+disclosure+%28EUVD-2026-36644%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9134 | fooplugins Photo Gallery by FooGallery Plugin up to 3.1.31 on WordPress Shortcode foogallery_sanitize_javascript cross site scripting (EUVD-2026-36645)]]></title> 
<description><![CDATA[A vulnerability has been found in fooplugins Photo Gallery by FooGallery Plugin up to 3.1.31 on WordPress and classified as problematic. Affected by this vulnerability is the function foogallery_sanitize_javascript of the component Shortcode Handler. Performing a manipulation results in cross site scripting.

This vulnerability is identified as CVE-2026-9134. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3596095/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9134+%7C+fooplugins+Photo+Gallery+by+FooGallery+Plugin+up+to+3.1.31+on+WordPress+Shortcode+foogallery_sanitize_javascript+cross+site+scripting+%28EUVD-2026-36645%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596095/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9134+%7C+fooplugins+Photo+Gallery+by+FooGallery+Plugin+up+to+3.1.31+on+WordPress+Shortcode+foogallery_sanitize_javascript+cross+site+scripting+%28EUVD-2026-36645%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-3297 | Softaculous Page Builder Plugin up to 2.0.9 on WordPress cross site scripting (EUVD-2026-36646)]]></title> 
<description><![CDATA[A vulnerability was found in Softaculous Page Builder Plugin up to 2.0.9 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2026-3297. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3596094/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3297+%7C+Softaculous+Page+Builder+Plugin+up+to+2.0.9+on+WordPress+cross+site+scripting+%28EUVD-2026-36646%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596094/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-3297+%7C+Softaculous+Page+Builder+Plugin+up+to+2.0.9+on+WordPress+cross+site+scripting+%28EUVD-2026-36646%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9109 | john-dagelmore GPTranslate Plugin up to 2.31 on WordPress Deterministically Derived API Key request gptApiKey cross site scripting (EUVD-2026-36642)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in john-dagelmore GPTranslate Plugin up to 2.31 on WordPress. Affected is an unknown function of the file /wp-json/gptranslate/v1/request of the component Deterministically Derived API Key Handler. Such manipulation of the argument gptApiKey leads to cross site scripting.

This vulnerability is referenced as CVE-2026-9109. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596093/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9109+%7C+john-dagelmore+GPTranslate+Plugin+up+to+2.31+on+WordPress+Deterministically+Derived+API+Key+request+gptApiKey+cross+site+scripting+%28EUVD-2026-36642%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596093/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9109+%7C+john-dagelmore+GPTranslate+Plugin+up+to+2.31+on+WordPress+Deterministically+Derived+API+Key+request+gptApiKey+cross+site+scripting+%28EUVD-2026-36642%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9061 | Store Locator Plugin up to 1.6.8 on WordPress cross site scripting (EUVD-2026-36643)]]></title> 
<description><![CDATA[A vulnerability was found in Store Locator Plugin up to 1.6.8 on WordPress. It has been rated as problematic. This issue affects some unknown processing. This manipulation causes cross site scripting.

This vulnerability is registered as CVE-2026-9061. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596092/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9061+%7C+Store+Locator+Plugin+up+to+1.6.8+on+WordPress+cross+site+scripting+%28EUVD-2026-36643%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596092/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9061+%7C+Store+Locator+Plugin+up+to+1.6.8+on+WordPress+cross+site+scripting+%28EUVD-2026-36643%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:54:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[I'm putting together a full guide on typical DRM tricks and how they get cracked.(denuvo : 2026 Re9)]]></title> 
<description><![CDATA[  submitted by    /u/SnooFloofs280   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3596069/IT+Reverse+Engineering/I%27m+putting+together+a+full+guide+on+typical+DRM+tricks+and+how+they+get+cracked.%28denuvo+%3A+2026+Re9%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596069/IT+Reverse+Engineering/I%27m+putting+together+a+full+guide+on+typical+DRM+tricks+and+how+they+get+cracked.%28denuvo+%3A+2026+Re9%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:25:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-54057 | kovidgoyal kitty up to 0.47.2 code injection (GHSA-5gmr-9gwg-hhq6 / Nessus ID 320963)]]></title> 
<description><![CDATA[A vulnerability was found in kovidgoyal kitty up to 0.47.2 and classified as critical. This vulnerability affects unknown code. Executing a manipulation can lead to code injection.

This vulnerability is registered as CVE-2026-54057. The attack needs to be launched locally. No exploit is available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596051/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54057+%7C+kovidgoyal+kitty+up+to+0.47.2+code+injection+%28GHSA-5gmr-9gwg-hhq6+%2F+Nessus+ID+320963%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596051/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-54057+%7C+kovidgoyal+kitty+up+to+0.47.2+code+injection+%28GHSA-5gmr-9gwg-hhq6+%2F+Nessus+ID+320963%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:33:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11657 | Google Chrome up to 149.0.7827.53 on macOS Payments use after free (ID 513465 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Google Chrome on macOS. Affected is an unknown function of the component Payments. The manipulation leads to use after free.

This vulnerability is referenced as CVE-2026-11657. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3596050/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11657+%7C+Google+Chrome+up+to+149.0.7827.53+on+macOS+Payments+use+after+free+%28ID+513465+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596050/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11657+%7C+Google+Chrome+up+to+149.0.7827.53+on+macOS+Payments+use+after+free+%28ID+513465+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:33:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11656 | Google Chrome up to 149.0.7827.53 ServiceWorker use after free (ID 513424 / Nessus ID 320958)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in Google Chrome. The impacted element is an unknown function of the component ServiceWorker. Executing a manipulation can lead to use after free.

This vulnerability is handled as CVE-2026-11656. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3596049/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11656+%7C+Google+Chrome+up+to+149.0.7827.53+ServiceWorker+use+after+free+%28ID+513424+%2F+Nessus+ID+320958%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596049/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11656+%7C+Google+Chrome+up+to+149.0.7827.53+ServiceWorker+use+after+free+%28ID+513424+%2F+Nessus+ID+320958%29/</guid>
<pubDate>Sat, 13 Jun 2026 20:33:22 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0420 | Netgear RAX120v1/RAX120v2/RAX35/RAX38/RAX40 prior 1.2.9.52 TLS Certificate Validation missing cryptographic step]]></title> 
<description><![CDATA[A vulnerability was found in Netgear RAX120v1, RAX120v2, RAX35, RAX38 and RAX40. It has been declared as problematic. Affected by this issue is some unknown functionality of the component TLS Certificate Validation Handler. Such manipulation leads to missing cryptographic step.

This vulnerability is listed as CVE-2026-0420. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595967/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0420+%7C+Netgear+RAX120v1%2FRAX120v2%2FRAX35%2FRAX38%2FRAX40+prior+1.2.9.52+TLS+Certificate+Validation+missing+cryptographic+step/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595967/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0420+%7C+Netgear+RAX120v1%2FRAX120v2%2FRAX35%2FRAX38%2FRAX40+prior+1.2.9.52+TLS+Certificate+Validation+missing+cryptographic+step/</guid>
<pubDate>Sat, 13 Jun 2026 19:03:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0419 | Netgear JR6150 up to 1.0.1.26 input validation]]></title> 
<description><![CDATA[A vulnerability was found in Netgear JR6150 up to 1.0.1.26. It has been classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes improper input validation.

This vulnerability is tracked as CVE-2026-0419. The attack is restricted to local execution. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3595966/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0419+%7C+Netgear+JR6150+up+to+1.0.1.26+input+validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595966/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0419+%7C+Netgear+JR6150+up+to+1.0.1.26+input+validation/</guid>
<pubDate>Sat, 13 Jun 2026 19:03:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0417 | Netgear XR1000 1.0.0.100 input validation]]></title> 
<description><![CDATA[A vulnerability described as problematic has been identified in Netgear MR60, MR70, MR80, MS60, MS70, MS80, R6400v2, R6700v3, R6900P, R7000, R7000P, R7960P, R8000P, R8500, RAX20, RAX35v2, RAX40v2, RAX41, RAX42, RAX43, RAX45, RAX48, RAX50, RAX50S, RAXE450, RAXE500 and XR1000 1.0.0.100. Affected is an unknown function. Such manipulation leads to improper input validation.

This vulnerability is uniquely identified as CVE-2026-0417. The attack can only be initiated within the local network. No exploit exists.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3595965/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0417+%7C+Netgear+XR1000+1.0.0.100+input+validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595965/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0417+%7C+Netgear+XR1000+1.0.0.100+input+validation/</guid>
<pubDate>Sat, 13 Jun 2026 19:03:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0416 | Netgear RAXE450/RAXE500 1.0.11.216 Standard Management Interface input validation]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Netgear RAXE450 and RAXE500 1.0.11.216. This impacts an unknown function of the component Standard Management Interface. This manipulation causes improper input validation.

This vulnerability is handled as CVE-2026-0416. The attack can only be done within the local network. There is not any exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595964/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0416+%7C+Netgear+RAXE450%2FRAXE500+1.0.11.216+Standard+Management+Interface+input+validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595964/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0416+%7C+Netgear+RAXE450%2FRAXE500+1.0.11.216+Standard+Management+Interface+input+validation/</guid>
<pubDate>Sat, 13 Jun 2026 19:03:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0418 | Netgear XR1000 prior 4.6.14.4 Configuration external control of setting]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in Netgear CBR750, EX6120, EX6130, MR60, MR70, MR80, MS60, MS70, MS80, RAX15, RAX20, RAX200, RAX35v2, RAX38v2, RAX40v2, RAX42, RAX43, RAX45, RAX48, RAX50, RAX50S, RAX75, RAX80, RAXE450, RAXE500, RBR750, RBR840, RBR850, RBRE960, RBS750, RBS840, RBS850, RBSE960, RS700 and XR1000. Affected by this vulnerability is an unknown functionality of the component Configuration Handler. Performing a manipulation results in external control of system or configuration setting.

This vulnerability was named CVE-2026-0418. The attack needs to be approached within the local network. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595963/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0418+%7C+Netgear+XR1000+prior+4.6.14.4+Configuration+external+control+of+setting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595963/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0418+%7C+Netgear+XR1000+prior+4.6.14.4+Configuration+external+control+of+setting/</guid>
<pubDate>Sat, 13 Jun 2026 19:03:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0412 | Netgear JR6150 up to 1.0.1.26 improper authorization]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Netgear JR6150 up to 1.0.1.26. Impacted is an unknown function. The manipulation results in improper authorization.

This vulnerability is reported as CVE-2026-0412. The attacker must have access to the local network to execute the attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3595922/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0412+%7C+Netgear+JR6150+up+to+1.0.1.26+improper+authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595922/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0412+%7C+Netgear+JR6150+up+to+1.0.1.26+improper+authorization/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0410 | Netgear XR1000v2 prior 1.0.11.216 improper authorization]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Netgear R7000, RAX20, RAX35v2, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX45, RAX49S, RAX50, RAX50S, RAX50v2, RAX54Sv2, RAX54v2, RAXE450, RAXE500, XR1000 and XR1000v2. This affects an unknown function. The manipulation results in improper authorization.

This vulnerability is known as CVE-2026-0410. Access to the local network is required for this attack. No exploit is available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3595921/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0410+%7C+Netgear+XR1000v2+prior+1.0.11.216+improper+authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595921/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0410+%7C+Netgear+XR1000v2+prior+1.0.11.216+improper+authorization/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11787 | Red Hat Directory Server/Enterprise Linux 389 Directory Server ldap_utf8prev buffer over-read]]></title> 
<description><![CDATA[A vulnerability was found in Red Hat Directory Server and Enterprise Linux. It has been declared as problematic. This affects the function ldap_utf8prev of the component 389 Directory Server. Such manipulation leads to buffer over-read.

This vulnerability is documented as CVE-2026-11787. The attack can be executed remotely. There is not any exploit available. ]]></description>
<link>https://tsecurity.de/de/3595920/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11787+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+ldap_utf8prev+buffer+over-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595920/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11787+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+ldap_utf8prev+buffer+over-read/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11788 | Red Hat Directory Server/Enterprise Linux 389 Directory Server null pointer dereference]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Red Hat Directory Server and Enterprise Linux. This issue affects some unknown processing of the component 389 Directory Server. Executing a manipulation can lead to null pointer dereference.

This vulnerability appears as CVE-2026-11788. The attack may be performed from remote. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3595919/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11788+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+null+pointer+dereference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595919/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11788+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+null+pointer+dereference/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11786 | Red Hat Directory Server/Enterprise Linux 389 Directory Server out-of-bounds]]></title> 
<description><![CDATA[A vulnerability was found in Red Hat Directory Server and Enterprise Linux. It has been classified as problematic. Affected by this issue is some unknown functionality of the component 389 Directory Server. This manipulation causes out-of-bounds read.

This vulnerability is registered as CVE-2026-11786. The attack needs to be launched locally. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3595918/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11786+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595918/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11786+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+out-of-bounds/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0415 | Netgear RBSE960 prior 9.12.4.9 improper authorization]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in Netgear RBE97x, RBR750, RBR840, RBR850, RBR860, RBRE950, RBRE960, RBS750, RBS840, RBS850, RBS860, RBSE950 and RBSE960. This issue affects some unknown processing. The manipulation leads to improper authorization.

This vulnerability is documented as CVE-2026-0415. The attack requires being on the local network. There is not any exploit available.

You should upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595917/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0415+%7C+Netgear+RBSE960+prior+9.12.4.9+improper+authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595917/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0415+%7C+Netgear+RBSE960+prior+9.12.4.9+improper+authorization/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-24064 | Waves Audio Waves Central up to 16.5.5 Trusted XPC Client untrusted search path]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Waves Audio Waves Central up to 16.5.5. This vulnerability affects unknown code of the component Trusted XPC Client. This manipulation causes untrusted search path.

The identification of this vulnerability is CVE-2026-24064. The attack can only be executed locally. There is no exploit available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595916/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-24064+%7C+Waves+Audio+Waves+Central+up+to+16.5.5+Trusted+XPC+Client+untrusted+search+path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595916/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-24064+%7C+Waves+Audio+Waves+Central+up+to+16.5.5+Trusted+XPC+Client+untrusted+search+path/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11789 | Red Hat Directory Server/Enterprise Linux 389 Directory Server integer underflow]]></title> 
<description><![CDATA[A vulnerability labeled as problematic has been found in Red Hat Directory Server and Enterprise Linux. The affected element is an unknown function of the component 389 Directory Server. The manipulation results in integer underflow.

This vulnerability is known as CVE-2026-11789. It is possible to launch the attack remotely. No exploit is available. ]]></description>
<link>https://tsecurity.de/de/3595915/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11789+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+integer+underflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595915/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11789+%7C+Red+Hat+Directory+Server%2FEnterprise+Linux+389+Directory+Server+integer+underflow/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-24065 | Waves Audio Waves Central up to 16.5.5 Helper Service toctou]]></title> 
<description><![CDATA[A vulnerability was found in Waves Audio Waves Central up to 16.5.5. It has been classified as critical. The impacted element is an unknown function of the component Helper Service. The manipulation leads to time-of-check time-of-use.

This vulnerability is listed as CVE-2026-24065. The attack must be carried out locally. There is no available exploit.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3595914/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-24065+%7C+Waves+Audio+Waves+Central+up+to+16.5.5+Helper+Service+toctou/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595914/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-24065+%7C+Waves+Audio+Waves+Central+up+to+16.5.5+Helper+Service+toctou/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0411 | Netgear RBE97x/RBR350/RBR760/RBS350/RBS760 prior 6.3.8.11 information disclosure]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Netgear RBE97x, RBR350, RBR760, RBS350 and RBS760. Impacted is an unknown function. This manipulation causes information disclosure.

This vulnerability appears as CVE-2026-0411. The attacker needs to be present on the local network. There is no available exploit.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595913/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0411+%7C+Netgear+RBE97x%2FRBR350%2FRBR760%2FRBS350%2FRBS760+prior+6.3.8.11+information+disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595913/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0411+%7C+Netgear+RBE97x%2FRBR350%2FRBR760%2FRBS350%2FRBS760+prior+6.3.8.11+information+disclosure/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49938 | Fortinet FortiPortal up to 7.0.14/7.2.8/7.4.7 access control (FG-IR-26-140)]]></title> 
<description><![CDATA[A vulnerability was found in Fortinet FortiPortal up to 7.0.14/7.2.8/7.4.7 and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to improper access controls.

This vulnerability is tracked as CVE-2026-49938. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3595912/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49938+%7C+Fortinet+FortiPortal+up+to+7.0.14%2F7.2.8%2F7.4.7+access+control+%28FG-IR-26-140%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595912/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49938+%7C+Fortinet+FortiPortal+up+to+7.0.14%2F7.2.8%2F7.4.7+access+control+%28FG-IR-26-140%29/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0414 | Netgear RBE97x 6.3.8.11 code injection]]></title> 
<description><![CDATA[A vulnerability was found in Netgear RBE97x 6.3.8.11. It has been rated as critical. This affects an unknown part. Performing a manipulation results in code injection.

This vulnerability is cataloged as CVE-2026-0414. The attack must originate from the local network. There is no exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3595911/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0414+%7C+Netgear+RBE97x+6.3.8.11+code+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595911/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0414+%7C+Netgear+RBE97x+6.3.8.11+code+injection/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0409 | Netgear Orbi 370 prior 12.1.2.7 memory corruption]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in Netgear Orbi 370. This issue affects some unknown processing. The manipulation results in memory corruption.

This vulnerability is reported as CVE-2026-0409. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3595910/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0409+%7C+Netgear+Orbi+370+prior+12.1.2.7+memory+corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595910/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0409+%7C+Netgear+Orbi+370+prior+12.1.2.7+memory+corruption/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0413 | Netgear RBSE960 prior 12.1.2.1 stack-based overflow]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Netgear RBE37X, RBE77X, RBR750, RBR840, RBR850, RBR860, RBRE950, RBRE960, RBS750, RBS840, RBS850, RBS860, RBSE950 and RBSE960. This vulnerability affects unknown code. Executing a manipulation can lead to stack-based buffer overflow.

This vulnerability is registered as CVE-2026-0413. The attack requires access to the local network. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595909/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0413+%7C+Netgear+RBSE960+prior+12.1.2.1+stack-based+overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595909/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-0413+%7C+Netgear+RBSE960+prior+12.1.2.1+stack-based+overflow/</guid>
<pubDate>Sat, 13 Jun 2026 18:22:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[v15.12.4]]></title> 
<description><![CDATA[@oh-my-pi/pi-agent-core
Fixed

Fixed remote compaction input trimming to use unlimited context when model.contextWindow is unset

@oh-my-pi/pi-ai
Added

Added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAuth application can replace the bundled credentials when GitLab rejects the bundled client_id&#039;s redirect URI. Setting GITLAB_REDIRECT_URI also disables the random-port fallback (strict OAuth providers reject mismatched URIs anyway). (#2424)
Added AuthStorage.listStoredCredentials() and AuthStorage.removeCredential() for per-account credential management.

Changed

Replaced the OpenAI SDK client usage in openai-completions, openai-responses, azure-openai-responses, and openai-codex-responses with the new internal postOpenAIStream OpenAI-wire JSON/SSE transport

Fixed

Fixed streaming providers to cancel upstream model requests when the client closes the response body, so interrupted SSE sessions stop instead of continuing in the background
Fixed: provider request builders treat unknown model.maxTokens (null) as &quot;no model cap&quot; instead of coercing to 0 via Math.min; Anthropic falls back to the 64k Claude-Code cap for its required max_tokens.
Fixed transient stream failures on OpenAI-compatible providers by retrying HTTP 408/429/5xx responses and transient network errors with Retry-After/quota-hint aware backoff
Fixed SSE stream handling for OpenAI-compatible responses by parsing wire-level JSON frames directly and honoring [DONE] termination
Fixed stream error handling for OpenAI-compatible providers by preserving structured HTTP status/headers and response body details from failed requests for retry and strict-tool fallback logic
Fixed OpenAI-compat streams ending with a bare finish_reason: &quot;error&quot; (gateways like OpenRouter reporting upstream failures, e.g. Gemini MALFORMED_FUNCTION_CALL) surfacing as a non-retryable Provider finish_reason: error. The reason is now mapped to Provider returned error finish_reason, which the session retry classifier recognizes as transient, so the turn auto-retries instead of stopping with a pinned error banner.
Fixed SqliteAuthCredentialStore.open() crashing with SQLITE_BUSY_RECOVERY (errno 261) when several omp --session panes restore concurrently after an unclean shutdown: PRAGMA busy_timeout = 5000 now runs as a standalone statement BEFORE PRAGMA journal_mode=WAL (the first lock-taking statement during WAL recovery), and open() retries the BUSY family &mdash; SQLITE_BUSY, SQLITE_BUSY_RECOVERY, SQLITE_BUSY_SNAPSHOT, SQLITE_BUSY_TIMEOUT &mdash; with bounded exponential backoff. The exhausted-retry error message includes the DB path. Exported isSqliteBusyError(err) for callers that need the same classifier (#2421).
Fixed MiniMax-M3 OpenAI-compatible streams rendering reasoning twice when the same chunk carried both &hellip; content and structured reasoning_content; structured reasoning now wins and cumulative MiniMax reasoning snapshots are collapsed to deltas. (#2433)
Fixed Gemini turns silently halting the agent when the model returned finishReason: STOP with only an empty (or whitespace-only) text part and no tool call &mdash; the well-known &quot;empty response&quot; failure. All Google surfaces (public Generative Language streamGoogle, Vertex streamGoogleVertex, and Cloud Code Assist google-gemini-cli/google-antigravity) now classify such a turn as empty via the shared hasMeaningfulGoogleContent check and retry it up to MAX_EMPTY_STREAM_RETRIES times before surfacing an error. The Cloud Code Assist path previously had an empty-stream retry that never fired for this case (its hasContent flag counted an empty-string text part as content), and the public/Vertex path had no retry at all; the retry now emits a single start event so no duplicate partial message leaks downstream.

@oh-my-pi/pi-catalog
Added

Added bundled Fireworks models deepseek-v4-flash, kimi-k2.7-code, minimax-m2.5, minimax-m3, nemotron-3-ultra-nvfp4, qwen3.6-plus, and qwen3.7-plus
Changed

Changed

Model contextWindow/maxTokens are now number | null; discovery emits null when a provider reports no limit, replacing the 222222/8888 (UNK_CONTEXT_WINDOW/UNK_MAX_TOKENS) sentinels (now removed). Bundled models.json unknown limits are null.
Changed the github-copilot model context window to 524288 tokens
Changed Fireworks model discovery to source the control-plane List Models API (GET /v1/accounts/fireworks/models?filter=supports_serverless=true) instead of the OpenAI-compatible /v1/models inference listing. The inference endpoint returns a sparse, account-specific subset that omits on-demand serverless models (e.g. kimi-k2.7-code), so newly published serverless models stayed invisible in the picker until hand-added to the bundled catalog. The control-plane catalog enumerates every serverless model with capability metadata (supportsServerless/supportsTools/supportsImageInput/contextLength/displayName), paginated and filtered to tool-capable READY entries, then merged with bundled/models.dev references &mdash; the Kimi K2 max-output clamp and DeepSeek V4 thinking-toggle strip are preserved, and unbundled models default to reasoning so buildModel derives the Fireworks effort map. New serverless releases now surface automatically with no catalog edits.

Fixed

Filled missing contextWindow and maxTokens in generated models.json for proxy/reseller variants by inheriting limits from canonical-family and segment-reference models
Ignored zero-cost x-ai subscription entries as reference sources when backfilling limits so inflated values are not propagated
Fixed the model cache opening with PRAGMA journal_mode=WAL before PRAGMA busy_timeout, so concurrent omp startups could crash inside getDb() on SQLITE_BUSY during WAL recovery instead of waiting through the transient lock. The busy handler is now installed before the first lock-taking statement (#2421).

@oh-my-pi/pi-coding-agent
Breaking Changes

Removed the top-level --list-models flag path and migrated model listing to the new omp models command

Added

Added omp models command to list and manage models with ls, find, canonical, and refresh actions
Added --json output plus -e/--extension, --no-extensions, and --config controls to omp models listings
Added skills.enableAgentsUser and skills.enableAgentsProject settings (default on) so the canonical OMP-native ~/.agent[s]/skills and project-walkup .agent[s]/skills are configurable independently from the third-party Claude/Codex/Pi toggles.

Changed

Model registry merge and omp models / model picker handle unknown context/output limits (null) &mdash; unknown limits render as - instead of a fake 222K/8.9K.
Changed omp models to use cached provider data by default and require omp models refresh for a forced online re-fetch
Updated model-resolution errors to point to omp models when a provider or model is not found
Upgraded workspace catalog packages to their latest versions as of 3 days ago, and refactored the ACP agent implementation to be compatible with @agentclientprotocol/sdk version 0.25.0.
Made the zod version requirement in the workspace catalog more tolerant (^4.0.0 instead of 4.4.3), and aligned type definitions in coding-agent extensibility modules.
Changed /logout to pick a stored account after the provider, so multi-account OAuth providers can remove one credential without logging out every account.
Changed the status-line context% to report the provider&#039;s real prompt-token count &mdash; anchored on the last assistant response, matching the /context panel and the collab host broadcast &mdash; instead of an independent cl100k estimate of the whole conversation. The estimate could read several points high and climb past 100% on subscription/Codex models (whose advertised window, e.g. 272K, is already the input budget after reserving max output) while the request was still well within the real limit. Right after compaction the segment now shows ? until the next response re-establishes the true count, and the redundant per-message estimate cache was dropped in favor of memoizing getContextUsage().

Fixed

Fixed ACP thinking-delta mapping to tolerate live chunks that only carry delta text.
Fixed image input to Ollama (local ollama, ollama-cloud, and any ollama-chat model) failing with an opaque HTTP 400 when an attached image was encoded as WebP. Ollama decodes images through llama.cpp / stb_image, which is built without WebP support, so the resize pipeline now auto-excludes WebP for those models &mdash; the automatic equivalent of OMP_NO_WEBP=1, applied across every image path (@file mentions and prompt/paste/CLI attachments, the read/inspect_image tools, eval display images, fetched images, and browser screenshots). Other providers are unaffected and still honor OMP_NO_WEBP.
Fixed queued steering/follow-up display to derive from the agent-core queue, so queued chips clear when the core dequeues them and no longer strand after empty-Enter aborts.
Fixed model auth gateway probing to avoid skipping candidates with unknown maxTokens limits (null)
Fixed model listings so providers registered via extensions are now included from -e and configured extensions sources
Fixed /mcp reauth, /mcp test, and /mcp unauth to find and operate on MCP servers reported by /mcp list even when they are only runtime-discovered and not stored in writable config, including namespaced plugin servers like cloudflare:cloudflare-api
Fixed MCP server name validation so colon-namespaced server IDs are accepted when persisting reauth overrides so namespaced OAuth MCP servers can be stored in user config as server:subserver entries
Retried assistant turns that stop with reasoning/thinking only and no final text or tool call, so Gemini/Antigravity thought-only STOP responses continue instead of silently ending the session.
Fixed ~/.agent[s]/skills not appearing as /skill: commands when every named source toggle (skills.enableCodexUser, skills.enableClaudeUser, skills.enableClaudeProject, skills.enablePiUser, skills.enablePiProject) was off: loadSkills gated the agents provider on anyBuiltInSkillSourceEnabled, so a user who turned off the Claude/Codex/Pi sources to clean noise also lost their own canonical OMP-native skills. The agents provider now reads the dedicated enableAgentsUser/enableAgentsProject toggles, decoupled from the third-party fall-through (#2401).
Fixed Windows PowerShell image paste so Ctrl+V can fall back to the PowerShell clipboard bridge when the native clipboard reader reports no image (#2429).
Fixed misaligned box borders in Mermaid ASCII rendering for CJK (Korean/Japanese/Chinese) and emoji labels &mdash; affects both fenced mermaid code blocks in assistant messages and the render_mermaid tool. beautiful-mermaid@1.1.3 measures label width in UTF-16 code units while terminals render East Asian characters 2 columns wide; a patchedDependencies entry rebuilds its ASCII renderer to measure terminal display columns (grapheme-cluster aware, wcwidth-style policy). The patch mirrors the upstream PR (lukilabs/beautiful-mermaid#128) and should be dropped once it ships in a release.
Fixed interrupt loader state getting stuck after queued-message aborts by removing the session-layer flush/latch path; empty Enter now aborts the active turn and lets the existing post-unwind queue drain resume normally.
Fixed /goal  and /goal set  during streaming so goal context is steered immediately but objective submission waits for the active turn to finish instead of spamming AgentBusyError (#2454).
Fixed concurrent omp --session startups (e.g. cmux pane restore after an unclean shutdown) crashing with SQLITE_BUSY_RECOVERY while the agent SQLite databases were still under WAL recovery. The auth credential store and AgentStorage.open() retry the SQLITE_BUSY family with bounded backoff, and every shared SQLite open path (AgentStorage, history, autoresearch, memories, github cache, auto-QA grievances, catalog model cache, stats) now installs the busy handler before the first lock-taking statement so transient WAL recovery contention waits instead of crashing (#2421).
Mnemopi per-project / per-project-tagged bank derivation is now stable for one cwd, ignoring the surrounding git layout. Previously the bank id was hashed from git.repo.resolveSync(cwd)?.repoRoot ?? path.resolve(cwd), so adding or removing a .git anywhere above the working directory silently repointed the same conversation to a new bank and stranded its memories (e.g. /home/x/projects/repo flipping between projects-&hellip; and repo-&hellip;). The derivation in packages/coding-agent/src/mnemopi/config.ts now hashes path.resolve(cwd) directly, and session startup widens the recall set with any sibling bank under /banks/ whose working_memory rows already carry the active cwd in metadata_json.$.cwd, so memories stranded by the old, less-stable derivation become visible again on the next session without manual migration (#2412).
Fixed model switching (Ctrl+P role cycling and the alt+p / /switch / /models selector) intermittently freezing the UI for several seconds. AgentSession.setModel/setModelTemporary ran an eager await modelRegistry.getApiKey(model) purely as an existence pre-flight and discarded the value &mdash; but getApiKey does real work: it synchronously executes command-backed key programs (apiKey: &quot;!cmd&quot;, execSync with a 10s timeout, blocking the event loop) and refreshes OAuth tokens over the network when one crosses the expiry window (the &quot;fine for a few switches, then a multi-second stall&quot; symptom). Switching now uses the synchronous, side-effect-free ModelRegistry.hasConfiguredAuth check; the concrete key (command execution + OAuth refresh) is still resolved lazily per request via the existing resolver, so an unconfigured provider still fails fast with No API key while a healthy switch never touches the network or spawns a subprocess. hasConfiguredAuth no longer runs the command program or refreshes tokens either, matching its documented &quot;probe without resolving an API key&quot; contract.
Fixed session resume (pi -c / --continue / --session) hanging for ~10s at startup &mdash; surfaced by the watchdog as Still starting &hellip; phase: createAgentSession &gt; restoreSessionModel &mdash; when an OAuth token needed refreshing or the auth broker (OMP_AUTH_BROKER_URL) was unreachable. Picking which saved model to restore is a pure selection that only needs to know whether auth is configured, but restoreSessionModel probed each candidate with the async getApiKey, which refreshes OAuth tokens over the network, executes command-backed key programs, and issues auth-broker requests &mdash; so a slow or unreachable endpoint stalled resume for the full refresh timeout per candidate. Startup model selection now uses the synchronous, side-effect-free ModelRegistry.hasConfiguredAuth probe (the same fix already applied to interactive model switching); the concrete key is still resolved lazily on the first request via the resolver.

@oh-my-pi/collab-web
Fixed

Fixed context usage percentage calculations to return null when context window is missing or non-positive, preventing invalid or Infinity/NaN usage display

@oh-my-pi/pi-mnemopi
Fixed

Fixed consolidateToEpisodic (the function backing sleep / sleepAllSessions) never populating the episodic graph: the gists and graph_edges tables stayed at 0 rows across every bank even after multiple consolidation cycles, so Polyphonic Recall&#039;s graph voice (BFS over findGistsByParticipant / findRelatedMemories) always returned nothing. Consolidation now best-effort ingests the new episodic memory into EpisodicGraph so the gist row, gist&rarr;memory ctx edge, fact edges, and cross-memory similarity/entity/temporal edges land alongside the episodic row. Independent of the existing MNEMOPI_PROACTIVE_LINKING flag, which still gates the same enrichment on the remember() write path. (#2435)

@oh-my-pi/pi-natives
Fixed

Fixed native shell execution rejecting quoted heredocs whose closing delimiter is the final line without a trailing newline, matching bash paste-run snippets.

@oh-my-pi/omp-stats
Fixed

Fixed the stats dashboard&#039;s SQLite init never setting PRAGMA busy_timeout, so a concurrent omp startup hitting WAL recovery could crash initDb() with SQLITE_BUSY instead of waiting through it. The busy handler is now installed before PRAGMA journal_mode=WAL (#2421).

@oh-my-pi/pi-tui
Added

PI_FORCE_HYPERLINKS=1 / PI_NO_HYPERLINKS=1 env overrides for the OSC 8 hyperlink capability, mirroring the PI_FORCE_SYNC_OUTPUT/PI_NO_SYNC_OUTPUT shape (opt-out beats force-on).

Changed

Auto-enable OSC 8 hyperlinks inside tmux when tmux self-reports &gt;= 3.4 via TERM_PROGRAM_VERSION; tmux 3.4 stores OSC 8 as a cell attribute and forwards it to outer terminals whose terminal-features include hyperlinks. Older tmux, GNU screen, and tmux without a reported version still default off. Resolution is factored into hyperlinksUserOverride() and shouldEnableHyperlinksByDefault() mirroring the sync-output helpers (#2403).

@oh-my-pi/pi-utils
Fixed

Fixed abortable stream wrappers to cancel the source stream on abort, so timeout watchdogs release upstream HTTP bodies instead of only stopping the local reader.

@oh-my-pi/pi-wire
Changed

Changed WireModel.contextWindow and ContextUsage.contextWindow to number | null to allow representing unavailable context-window values

What&#039;s Changed

fix(tui): respect OSC 8 hyperlinks under tmux &gt;= 3.4 by @roboomp in #2404
fix(skills): load ~/.agents/skills even when third-party source toggles are off by @roboomp in #2405
fix(coding-agent): stabilize mnemopi per-project bank derivation (#2412) by @roboomp in #2414
fix(auth): retried SQLITE_BUSY family and hoisted busy_timeout by @roboomp in #2423
fix(ai): added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI overrides for gitlab-duo OAuth by @roboomp in #2425
fix(coding-agent): restore Windows image paste fallback by @roboomp in #2430
fix(ai): deduplicate MiniMax reasoning stream by @roboomp in #2434
fix(mnemopi): populated gists and graph_edges during consolidation by @roboomp in #2439
fix: align Mermaid ASCII box borders for CJK/emoji labels by @chan1103 in #2442
docs: document project settings and disabledProviders by @roboomp in #2448
fix(cli): defer goal objectives while streaming by @roboomp in #2455

Full Changelog: v15.12.3...v15.12.4 ]]></description>
<link>https://tsecurity.de/de/3595882/IT+Reverse+Engineering/Tools/v15.12.4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595882/IT+Reverse+Engineering/Tools/v15.12.4/</guid>
<pubDate>Sat, 13 Jun 2026 18:19:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8365 | creativethemeshq Blocksy Plugin up to 2.1.41 on WordPress blocksy_sanitize_post_meta_options deserialization]]></title> 
<description><![CDATA[A vulnerability marked as critical has been reported in creativethemeshq Blocksy Plugin up to 2.1.41 on WordPress. This vulnerability affects the function blocksy_sanitize_post_meta_options. Performing a manipulation results in deserialization.

This vulnerability is identified as CVE-2026-8365. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595714/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8365+%7C+creativethemeshq+Blocksy+Plugin+up+to+2.1.41+on+WordPress+blocksy_sanitize_post_meta_options+deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595714/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8365+%7C+creativethemeshq+Blocksy+Plugin+up+to+2.1.41+on+WordPress+blocksy_sanitize_post_meta_options+deserialization/</guid>
<pubDate>Sat, 13 Jun 2026 15:22:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-49818 | Apache Airflow Samba Provider up to 4.12.5 Destination path traversal]]></title> 
<description><![CDATA[A vulnerability classified as critical has been found in Apache Airflow Samba Provider up to 4.12.5. Impacted is an unknown function of the component Destination Handler. The manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-49818. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595713/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49818+%7C+Apache+Airflow+Samba+Provider+up+to+4.12.5+Destination+path+traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595713/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-49818+%7C+Apache+Airflow+Samba+Provider+up+to+4.12.5+Destination+path+traversal/</guid>
<pubDate>Sat, 13 Jun 2026 15:22:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-8977 | techjewel WP GDPR Cookie Consent Plugin up to 1.0.0 on WordPress Configuration handleAjaxCalls gdprConfig cross site scripting]]></title> 
<description><![CDATA[A vulnerability was found in techjewel WP GDPR Cookie Consent Plugin up to 1.0.0 on WordPress. It has been classified as problematic. This affects the function handleAjaxCalls of the component Configuration Handler. The manipulation of the argument gdprConfig leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-8977. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3595662/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8977+%7C+techjewel+WP+GDPR+Cookie+Consent+Plugin+up+to+1.0.0+on+WordPress+Configuration+handleAjaxCalls+gdprConfig+cross+site+scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595662/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-8977+%7C+techjewel+WP+GDPR+Cookie+Consent+Plugin+up+to+1.0.0+on+WordPress+Configuration+handleAjaxCalls+gdprConfig+cross+site+scripting/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-25688 | Apache Answer up to 2.0.0 AI Answer Rendering cross site scripting]]></title> 
<description><![CDATA[A vulnerability classified as problematic has been found in Apache Answer up to 2.0.0. Affected is an unknown function of the component AI Answer Rendering. This manipulation causes cross site scripting.

This vulnerability is registered as CVE-2026-25688. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595661/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25688+%7C+Apache+Answer+up+to+2.0.0+AI+Answer+Rendering+cross+site+scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595661/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-25688+%7C+Apache+Answer+up+to+2.0.0+AI+Answer+Rendering+cross+site+scripting/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2009-10007 | ETHER Catalyst::Plugin::Authentication up to 0.10_026 on Perl Session ID Cookie session fixiation]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in ETHER Catalyst::Plugin::Authentication up to 0.10_026 on Perl. This vulnerability affects unknown code of the component Session ID Cookie Handler. Such manipulation leads to session fixiation.

This vulnerability is uniquely identified as CVE-2009-10007. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595660/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2009-10007+%7C+ETHER+Catalyst%3A%3APlugin%3A%3AAuthentication+up+to+0.10_026+on+Perl+Session+ID+Cookie+session+fixiation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595660/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2009-10007+%7C+ETHER+Catalyst%3A%3APlugin%3A%3AAuthentication+up+to+0.10_026+on+Perl+Session+ID+Cookie+session+fixiation/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-41979 | Huawei HarmonyOS 6.0.0/6.1.0 Print]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Huawei HarmonyOS 6.0.0/6.1.0. This affects an unknown function of the component Print Module. The manipulation leads to an unknown weakness.

This vulnerability is listed as CVE-2026-41979. The attack must be carried out locally. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3595659/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-41979+%7C+Huawei+HarmonyOS+6.0.0%2F6.1.0+Print/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595659/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-41979+%7C+Huawei+HarmonyOS+6.0.0%2F6.1.0+Print/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-4986 | WPForms Plugin 1.9.1.6/1.9.2.3/1.10.0.1 on WordPress Transaction authorization]]></title> 
<description><![CDATA[A vulnerability was found in WPForms Plugin 1.9.1.6/1.9.2.3/1.10.0.1 on WordPress. It has been classified as critical. Impacted is an unknown function of the component Transaction Handler. This manipulation causes missing authorization.

This vulnerability is handled as CVE-2026-4986. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended. ]]></description>
<link>https://tsecurity.de/de/3595658/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4986+%7C+WPForms+Plugin+1.9.1.6%2F1.9.2.3%2F1.10.0.1+on+WordPress+Transaction+authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595658/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-4986+%7C+WPForms+Plugin+1.9.1.6%2F1.9.2.3%2F1.10.0.1+on+WordPress+Transaction+authorization/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11572 | degit up to 2.8.5/3.3.0 exec os command injection (SNYK-JS-DEGIT-17116207)]]></title> 
<description><![CDATA[A vulnerability was found in degit up to 2.8.5/3.3.0. It has been rated as critical. The impacted element is the function exec. Performing a manipulation results in os command injection.

This vulnerability was named CVE-2026-11572. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3595657/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11572+%7C+degit+up+to+2.8.5%2F3.3.0+exec+os+command+injection+%28SNYK-JS-DEGIT-17116207%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595657/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11572+%7C+degit+up+to+2.8.5%2F3.3.0+exec+os+command+injection+%28SNYK-JS-DEGIT-17116207%29/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2025-62858 | QNAP QTS/QuTS hero stack-based overflow (qsa-26-10)]]></title> 
<description><![CDATA[A vulnerability labeled as critical has been found in QNAP QTS and QuTS hero. Affected is an unknown function. The manipulation results in stack-based buffer overflow.

This vulnerability is identified as CVE-2025-62858. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded. ]]></description>
<link>https://tsecurity.de/de/3595656/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-62858+%7C+QNAP+QTS%2FQuTS+hero+stack-based+overflow+%28qsa-26-10%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595656/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-62858+%7C+QNAP+QTS%2FQuTS+hero+stack-based+overflow+%28qsa-26-10%29/</guid>
<pubDate>Sat, 13 Jun 2026 14:37:20 +0200</pubDate>
</item>
</channel> 
</rss>
<!-- Generated in 0,24ms -->