CVE-2020-15053: Schwachstellen-Eintrag (NVD)
An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-11 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-55524 | MervinPraison PraisonAI up to 1.6.57 web_crawl server-side request forgery
A vulnerability was found in MervinPraison PraisonAI up to 1.6.57. It has been classified as critical. This affects the function web_crawl. The manipulation leads to server-side request forgery. This vulnerability is referenced as CVE-2026-
CVE-2026-55523 | MervinPraison PraisonAI 1.5.128-1.6.57 Web Crawl Tools web_crawl_tools.py praisonaiagents.tools.web_crawl_tools.web_crawl url server-side request forgery
A vulnerability, which was classified as critical, has been found in MervinPraison PraisonAI 1.5.128-1.6.57. Affected by this issue is the function praisonaiagents.tools.web_crawl_tools.web_crawl of the file praisonaiagents/tools/web_crawl_
CVE-2026-55522 | MervinPraison PraisonAI/praisonaiagents Tool Loader tools.py Workflow._execute_include code injection
A vulnerability marked as critical has been reported in MervinPraison PraisonAI and praisonaiagents. This affects the function Workflow._execute_include of the file tools.py of the component Tool Loader. This manipulation causes code inject
CVE-2026-70612 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 iFrame Sandbox setPermissionRequestHandler sandbox
A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been declared as critical. Affected by this vulnerability is the function setPermissionRequestHandler of the component iFrame Sandbox. The manipulation r
CVE-2026-70611 | Electron up to 39.8.8/40.9.1/41.2.0/42.0.0-beta.2 DevTools showItemInFolder sandbox
A vulnerability was found in Electron up to 39.8.8/40.9.1/41.2.0/42.0.0-beta.2 and classified as critical. The affected element is the function showItemInFolder of the component DevTools. Such manipulation leads to sandbox issue. This vulne
CVE-2026-70610 | Electron up to 39.8.8/40.9.1/41.2.1/42.0.0-beta.3 contextBridge prototype pollution
A vulnerability, which was classified as critical, has been found in Electron up to 39.8.8/40.9.1/41.2.1/42.0.0-beta.3. This vulnerability affects unknown code of the component contextBridge. The manipulation leads to improperly controlled
CVE-2026-38057 | ST Engineering iDirect Evolution iQ-Series terminals up to 4.5.2.1 API endpoint /api/reboot SameSite cross-site request forgery
A vulnerability was found in ST Engineering iDirect Evolution iQ-Series terminals, 3315-Series and 9-Series Terminals up to 4.5.2.1. It has been classified as problematic. This impacts the function reboot of the file /api/reboot of the comp
CVE-2026-38059 | ST Engineering iDirect Evolution iQ-Series terminals up to 4.5.2.1 REST API Endpoint /api/identity information disclosure
A vulnerability, which was classified as problematic, was found in ST Engineering iDirect Evolution iQ-Series terminals, 3315-Series and 9-Series Terminals up to 4.5.2.1. This affects an unknown function of the file /api/identity of the com
CVE-2026-58592 | LadybirdBrowser Ladybird WebAssembly WebAssemblyModule.cpp expired pointer dereference
A vulnerability categorized as problematic has been discovered in LadybirdBrowser Ladybird. Affected by this issue is some unknown functionality of the file WebAssemblyModule.cpp of the component WebAssembly Module. The manipulation results
CVE-2026-48168 | MervinPraison PraisonAI up to 4.6.39 Claude GitHub Actions Workflow command injection
A vulnerability has been found in MervinPraison PraisonAI up to 4.6.39 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Claude GitHub Actions Workflow. The manipulation leads to command
CVE-2026-66738 | SPIP up to 4.4.17 Navigation Menu Endpoint code injection
A vulnerability was found in SPIP up to 4.4.17 and classified as critical. This vulnerability affects unknown code of the component Navigation Menu Endpoint. The manipulation results in code injection. This vulnerability is known as CVE-202
CVE-2025-36572 | Dell PowerStore 4.0.0.0 Image File hard-coded credentials (dsa-2025-223)
A vulnerability was found in Dell PowerStore 4.0.0.0. It has been rated as critical. This issue affects some unknown processing of the component Image File Handler. The manipulation leads to hard-coded credentials. This vulnerability is uni
CVE-2026-28265 | Dell PowerStore path traversal (dsa-2026-157)
A vulnerability was found in Dell PowerStore, PowerStore 500T, PowerStore 1000T, PowerStore 1200T, PowerStore 3000T, PowerStore 3200Q, PowerStore 3200T, PowerStore 5000T, PowerStore 5200Q, PowerStore 5200T, PowerStore 7000T, PowerStore 9000
CVE-2026-48158 | dai-shi use-context-selector src/install.js permission
A vulnerability classified as critical was found in dai-shi use-context-selector. This affects an unknown function of the file src/install.js. Such manipulation leads to permission issues. This vulnerability is listed as CVE-2026-48158. The
CVE-2026-63105 | Razinsoft Ready eCommerce up to 4.5.1 Messaging System Messages.vue cross site scripting
A vulnerability marked as problematic has been reported in Razinsoft Ready eCommerce up to 4.5.1. This affects an unknown part of the file Messages.vue of the component Messaging System. The manipulation leads to cross site scripting. This
CVE-2026-63106 | Razinsoft Ready eCommerce up to 4.5.1 Product Listing API ProductController.php rating sql injection
A vulnerability, which was classified as critical, was found in Razinsoft Ready eCommerce up to 4.5.1. This issue affects some unknown processing of the file ProductController.php of the component Product Listing API. Such manipulation of t
CVE-2026-52880 | klever-io klever-go up to 1.7.17 REST API Gin Engine.Run denial of service (EUVD-2026-54722)
A vulnerability was found in klever-io klever-go up to 1.7.17. It has been declared as problematic. Affected by this vulnerability is the function Gin Engine.Run of the component REST API. Such manipulation leads to denial of service. This
CVE-2026-52878 | Klever-IO Klever-Go up to 1.7.17 Pubsub Topic-Validator Callback txVersionChecker.CheckTxVersion null pointer dereference
A vulnerability has been found in Klever-IO Klever-Go up to 1.7.17 and classified as problematic. This affects the function txVersionChecker.CheckTxVersion of the component Pubsub Topic-Validator Callback. The manipulation leads to null poi
CVE-2026-52879 | klever-io klever-go up to 1.7.17 Direct-Message Ingress allocation of resources
A vulnerability, which was classified as problematic, has been found in klever-io klever-go up to 1.7.17. The affected element is an unknown function of the component Direct-Message Ingress Handler. Performing a manipulation results in allo
CVE-2022-43640 | Foxit PDF Reader PDF File Parser out-of-bounds (ZDI-22-1660 / EUVD-2022-46636)
A vulnerability, which was classified as problematic, has been found in Foxit PDF Reader. Affected by this vulnerability is an unknown functionality of the component PDF File Parser. The manipulation leads to out-of-bounds read. This vulner
CVE-2022-43639 | Foxit PDF Reader U3D File Parser use after free (ZDI-22-1659 / EUVD-2022-46635)
A vulnerability labeled as critical has been found in Foxit PDF Reader. The affected element is an unknown function of the component U3D File Parser. The manipulation results in use after free. This vulnerability was named CVE-2022-43639. T
CVE-2022-43638 | Foxit PDF Reader U3D File Parser use after free (ZDI-22-1658 / EUVD-2022-46634)
A vulnerability marked as critical has been reported in Foxit PDF Reader. The impacted element is an unknown function of the component U3D File Parser. This manipulation causes use after free. The identification of this vulnerability is CVE
CVE-2026-47249 | klever-io klever-go up to 1.7.17 Resolver Batch.Decompress allocation of resources
A vulnerability labeled as problematic has been found in klever-io klever-go up to 1.7.17. Affected by this issue is the function Batch.Decompress of the component Resolver. Executing a manipulation can lead to allocation of resources. The
CVE-2026-42016 | JFrog Artifactory up to 7.133.10 privileges management
A vulnerability identified as critical has been detected in JFrog Artifactory up to 7.133.10. Impacted is an unknown function. Performing a manipulation results in improper privilege management. This vulnerability was named CVE-2026-42016.
CVE-2026-59717 | Home Assistant up to 2026.6.0 Onboarding Flow /auth/authorize redirect
A vulnerability was found in Home Assistant up to 2026.6.0. It has been classified as problematic. This issue affects some unknown processing of the file /auth/authorize of the component Onboarding Flow. Performing a manipulation results in
CVE-2026-48026 | Treeverse lakeFS/lakeFS-Enterprise up to 1.81.0/1.83.0 Web UI README.md cross site scripting (EUVD-2026-54717)
A vulnerability classified as problematic was found in Treeverse lakeFS and lakeFS-Enterprise up to 1.81.0/1.83.0. Impacted is an unknown function of the file README.md of the component Web UI. Such manipulation leads to cross site scriptin
CVE-2026-47243 | Kata Containers kata-containers up to 3.30.x virtiofsd symlink
A vulnerability classified as critical has been found in Kata Containers kata-containers up to 3.30.x. This affects an unknown part of the component virtiofsd. The manipulation leads to symlink following. This vulnerability is uniquely iden
CVE-2026-58262 | klever-io klever-go up to 1.7.19 signature verification (EUVD-2026-54712)
A vulnerability identified as problematic has been detected in klever-io klever-go up to 1.7.19. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper verification of cryptographic signatu
CVE-2026-66061 | home-assistant Home Assistant 1.10.0 improper authorization
A vulnerability, which was classified as problematic, has been found in home-assistant Home Assistant 1.10.0. This vulnerability affects unknown code. This manipulation causes improper authorization. This vulnerability is registered as CVE-
CVE-2026-54338 | JupyterHub up to 5.4.x Form-based Login Authenticator resource consumption (Nessus ID 333522)
A vulnerability classified as problematic has been found in JupyterHub up to 5.4.x. Affected by this issue is some unknown functionality of the component Form-based Login Authenticator. The manipulation leads to resource consumption. This v
CVE-2026-69207 | honojs Hono up to 4.12.33 CORS Middleware cors redos
A vulnerability classified as problematic was found in honojs Hono up to 4.12.33. This affects the function cors of the component CORS Middleware. The manipulation results in inefficient regular expression complexity. This vulnerability is
CVE-2026-73515 | PostGIS 2.3.3 FlatGeobuf property metadata decoder out-of-bounds (WID-SEC-2026-3306)
A vulnerability was found in PostGIS 2.3.3 and classified as critical. Affected is an unknown function of the component FlatGeobuf property metadata decoder. The manipulation results in out-of-bounds read. This vulnerability is reported as
CVE-2022-43637 | Foxit PDF Reader U3D File Parser use after free (ZDI-22-1657 / EUVD-2022-46633)
A vulnerability described as critical has been identified in Foxit PDF Reader. This affects an unknown function of the component U3D File Parser. Such manipulation leads to use after free. This vulnerability is referenced as CVE-2022-43637.
CVE-2022-43636 | TP-Link TL-WR940N httpd random values (ZDI-22-1614 / EUVD-2022-46632)
A vulnerability classified as problematic has been found in TP-Link TL-WR940N. Affected by this vulnerability is an unknown functionality of the component httpd. The manipulation leads to insufficiently random values. This vulnerability is
CVE-2022-43634 | Netatalk dsi_writeinit heap-based overflow (EUVD-2022-46630)
A vulnerability categorized as critical has been discovered in Netatalk. Affected is the function dsi_writeinit. Such manipulation leads to heap-based buffer overflow. This vulnerability is referenced as CVE-2022-43634. It is possible to la
CVE-2022-43635 | TP-Link TL-WR940N httpd information disclosure (ZDI-22-1615 / EUVD-2022-46631)
A vulnerability categorized as problematic has been discovered in TP-Link TL-WR940N. The affected element is an unknown function of the component httpd. The manipulation results in information disclosure. This vulnerability is known as CVE-
CVE-2022-43633 | D-Link DIR-1935 SetSysLogSettings command injection (ZDI-22-1505 / EUVD-2022-46629)
A vulnerability has been found in D-Link DIR-1935 and classified as critical. Affected by this vulnerability is the function SetSysLogSettings. This manipulation causes command injection. This vulnerability is handled as CVE-2022-43633. The
CVE-2022-43631 | D-Link DIR-1935 SetVirtualServerSettings VirtualServerInfo command injection (ZDI-22-1502 / EUVD-2022-46627)
A vulnerability was found in D-Link DIR-1935. It has been classified as critical. This affects the function SetVirtualServerSettings. Performing a manipulation of the argument VirtualServerInfo results in command injection. This vulnerabili
CVE-2022-43632 | D-Link DIR-1935 SetQoSSettings QoSInfo command injection (ZDI-22-1504 / EUVD-2022-46628)
A vulnerability was found in D-Link DIR-1935 and classified as critical. Affected by this issue is the function SetQoSSettings. Such manipulation of the argument QoSInfo leads to command injection. This vulnerability is uniquely identified
CVE-2022-43629 | D-Link DIR-1935 SetSysEmailSettings command injection (ZDI-22-1500 / EUVD-2022-46625)
A vulnerability was found in D-Link DIR-1935. It has been rated as critical. This issue affects the function SetSysEmailSettings. The manipulation leads to command injection. This vulnerability is referenced as CVE-2022-43629. The attack ne
CVE-2022-43630 | D-Link DIR-1935 SOAPAction stack-based overflow (ZDI-22-1501 / EUVD-2022-46626)
A vulnerability was found in D-Link DIR-1935. It has been declared as critical. This vulnerability affects the function SOAPAction. Executing a manipulation can lead to stack-based buffer overflow. The identification of this vulnerability i
CVE-2022-43628 | D-Link DIR-1935 SetIPv6FirewallSettings IPv6FirewallRule command injection (ZDI-22-1499 / EUVD-2022-46624)
A vulnerability labeled as critical has been found in D-Link DIR-1935. The impacted element is the function SetIPv6FirewallSettings. Such manipulation of the argument IPv6FirewallRule leads to command injection. This vulnerability is listed
CVE-2026-70429 | Jenkins Project up to 2.567.x privileges management
A vulnerability labeled as critical has been found in Jenkins Project Jenkins up to 2.567.x. The affected element is an unknown function. Executing a manipulation can lead to improper privilege management. This vulnerability is handled as C
CVE-2026-70609 | Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 DevTools webContents.openDevTools mode sandbox
A vulnerability has been found in Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 and classified as critical. Impacted is the function webContents.openDevTools of the component DevTools. This manipulation of the argument mode causes sandb
CVE-2026-70608 | Electron up to 39.8.9/41.10.2/42.0.0 iFrame Sandbox sandbox
A vulnerability, which was classified as critical, was found in Electron up to 39.8.9/41.10.2/42.0.0. This issue affects some unknown processing of the component iFrame Sandbox. The manipulation results in sandbox issue. This vulnerability
CVE-2024-7049 | open-webui up to 0.3.8 wrong session
This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all. Weiterlesen
CVE-2026-70607 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 BrowserWindow window.open input validation
A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been declared as critical. This affects the function window.open of the component BrowserWindow. The manipulation results in improper input validation. T
CVE-2026-70602 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Extension Tab/Scripting APIs information disclosure
A vulnerability labeled as problematic has been found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. This affects an unknown function of the component Extension Tab/Scripting APIs. Executing a manipulation can lead to information dis
CVE-2026-70605 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Redirect net.fetch/net.request redirect
A vulnerability identified as problematic has been detected in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. The impacted element is the function net.fetch/net.request of the component Redirect Handler. Performing a manipulation result
CVE-2026-70603 | Electron up to 39.8.5/40.8.x/41.1.0/42.0.0-beta.0 Shell shell.openPath input validation
A vulnerability was found in Electron up to 39.8.5/40.8.x/41.1.0/42.0.0-beta.0. It has been rated as critical. Impacted is the function shell.openPath of the component Shell. This manipulation causes improper input validation. This vulnerab
CVE-2026-70606 | Electron up to 40.10.5/41.9.0/42.5.0 Custom Protocol information disclosure
A vulnerability classified as problematic was found in Electron up to 40.10.5/41.9.0/42.5.0. This impacts an unknown function of the component Custom Protocol Handler. The manipulation results in information disclosure. This vulnerability i
CVE-2026-70604 | Electron up to 39.8.9/40.9.2/41.3.9 Custom Scheme cross-domain policy
A vulnerability described as problematic has been identified in Electron up to 39.8.9/40.9.2/41.3.9. The impacted element is an unknown function of the component Custom Scheme. Executing a manipulation can lead to permissive cross-domain po
CVE-2026-78575 | IBM Langflow OSS up to 1.11.5 MCP stdio server command injection (WID-SEC-2026-3239)
A vulnerability has been found in IBM Langflow OSS up to 1.11.5 and classified as critical. The affected element is an unknown function of the component MCP stdio server. This manipulation causes command injection. This vulnerability is reg
CVE-2026-78569 | IBM Langflow OSS up to 1.11.5 Security Scanner access control (WID-SEC-2026-3239)
A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.11.5. The impacted element is an unknown function of the component Security Scanner. This manipulation causes improper access controls. This vulne
CVE-2026-78571 | IBM Langflow up to 1.11.5 eval code injection (WID-SEC-2026-3239)
A vulnerability was found in IBM Langflow up to 1.11.5. It has been declared as critical. This impacts the function eval. Executing a manipulation can lead to code injection. This vulnerability appears as CVE-2026-78571. The attack may be p
CVE-2026-76059 | IBM Langflow OSS up to 1.11.5 access control (WID-SEC-2026-3239)
A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.11.5. This issue affects some unknown processing. The manipulation leads to improper access controls. This vulnerability is listed as CVE-2026-760
CVE-2026-9667 | IBM WebSphere Application Server 8.5/9.0 server-side request forgery (WID-SEC-2026-3255)
A vulnerability categorized as problematic has been discovered in IBM WebSphere Application Server 8.5/9.0. This affects an unknown part. The manipulation results in server-side request forgery. This vulnerability was named CVE-2026-9667. T
CVE-2026-9336 | IBM WebSphere Application Server 8.5/9.0 Administrative Endpoint denial of service (WID-SEC-2026-3255)
A vulnerability has been found in IBM WebSphere Application Server 8.5/9.0 and classified as problematic. This affects an unknown part of the component Administrative Endpoint. Performing a manipulation results in denial of service. This vu
CVE-2026-9338 | IBM WebSphere Application Server 8.5/9.0 resource consumption (WID-SEC-2026-3255)
A vulnerability, which was classified as problematic, was found in IBM WebSphere Application Server 8.5/9.0. Affected by this issue is some unknown functionality. Such manipulation leads to resource consumption. This vulnerability is traded
CVE-2026-86812 | WPCafe Plugin up to 3.0.17 on WordPress REST endpoint access control (EUVD-2026-75972)
A vulnerability identified as critical has been detected in WPCafe Plugin up to 3.0.17 on WordPress. This affects an unknown function of the component REST endpoint. This manipulation causes improper access controls. This vulnerability is r