🎯 CVE-2025-8028
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

CVE-2025-8028: Schwachstellen-Eintrag (NVD)

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

Klassifikation & Betroffenheit:
mozilla firefox *mozilla thunderbird *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🇩🇪 BSI-Sicherheitshinweise: BSI · Mozilla Firefox , Firefox ESR und Thunderbird: Mehrere Schwachstellen ↗
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 9.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:22.07.2025
Aktualisiert:30.09.2026 18:10
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🗨 Diskussion zu CVE-2025-8028 0 Beiträge
Antworten, Upvotes & Reaktionen — wie im Community-Feed. Markdown und ```Code``` unterstützt.

Noch keine Analyse zu CVE-2025-8028

Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.

↩️ Antworten auf:

Beitrag zu CVE-2025-8028 verfassen

Neu hier? Als Mitglied sammelst du Karma für Beiträge und Answers.
📧
Code-Formatierung: ```bash ... ``` oder `inline code` 0 / 2000
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 295 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1509 2026-10: 70 9.405 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-192026-10-03
≥90 %538364
≥50 %16031115
≥10 %173
<10 %56400485
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.233 Einträge):
Quelle:
🔍
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59497 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2025-59497 | Microsoft Defender for Endpoint on Linux toctou (EUVD-2025-34266)

A vulnerability classified as critical was found in Microsoft Defender for Endpoint on Linux. Affected by this vulnerability is an unknown functionality. The manipulation results in time-of-check time-of-use. This vulnerability is reported

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-42939 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-42939 | SAP S4HANA 4CORE 104 up to 108 Manage Processing Rules authorization (EUVD-2025-34118 / CNNVD-202510-2076)

A vulnerability marked as critical has been reported in SAP S4HANA 4CORE 104 up to 108. Impacted is an unknown function of the component Manage Processing Rules. The manipulation leads to incorrect authorization. This vulnerability is uniqu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-40755 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-40755 | Siemens SINEC NMS up to 4.0 Endpoint getTotalAndFilterCounts sql injection (ssa-318832)

A vulnerability, which was classified as critical, has been found in Siemens SINEC NMS up to 4.0. The impacted element is the function getTotalAndFilterCounts of the component Endpoint. Performing a manipulation results in sql injection. Th

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-37147 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-37147 | HPE ArubaOS up to 10.7.1.1 Secure Boot authentication spoofing

A vulnerability identified as critical has been detected in HPE ArubaOS up to 8.10.0.18/8.12.0.5/8.13.0.1/10.4.1.8/10.7.1.1. This impacts an unknown function of the component Secure Boot. Performing a manipulation results in authentication

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2025-37138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-37138 | HPE ArubaOS up to 10.7.1.1 Command Line Interface command injection

A vulnerability identified as critical has been detected in HPE ArubaOS up to 8.10.0.18/8.12.0.5/8.13.0.1/10.4.1.8/10.7.1.1. Affected by this issue is some unknown functionality of the component Command Line Interface. The manipulation lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-20717 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-20717 | MediaTek MT7986 WLAN AP Driver stack-based overflow

A vulnerability marked as critical has been reported in MediaTek MT6890, MT7615, MT7622, MT7663, MT7915, MT7916, MT7981 and MT7986. The affected element is an unknown function of the component WLAN AP Driver. This manipulation causes stack-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11720 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-11720 | Mozilla Firefox up to 143 on Android Focus UI ui layer (WID-SEC-2025-2275)

A vulnerability classified as problematic has been found in Mozilla Firefox up to 143 on Android. This vulnerability affects unknown code of the component Focus UI. This manipulation causes improper restriction of rendered ui layers. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-11718 | Mozilla Firefox up to 143 on Android Address Bar clickjacking (WID-SEC-2025-2275)

A vulnerability, which was classified as problematic, was found in Mozilla Firefox up to 143 on Android. The affected element is an unknown function of the component Address Bar. Executing a manipulation can lead to clickjacking. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11717 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2025-11717 | Mozilla Firefox up to 143 on Android denial of service (WID-SEC-2025-2275)

A vulnerability, which was classified as problematic, has been found in Mozilla Firefox up to 143 on Android. Impacted is an unknown function. Performing a manipulation results in denial of service. This vulnerability is known as CVE-2025-1

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 20.4%
CVE-2025-10242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10242 | Ivanti Endpoint Manager Mobile prior 12.4.0.4/12.5.0.4/12.6.0.2 os command injection (EUVD-2025-34213 / Nessus ID 270691)

A vulnerability categorized as critical has been discovered in Ivanti Endpoint Manager Mobile. This issue affects some unknown processing. The manipulation results in os command injection. This vulnerability is identified as CVE-2025-10242.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 15.3%
CVE-2025-9713 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-9713 | Ivanti Endpoint Manager path traversal (EUVD-2025-34088 / Nessus ID 275450)

A vulnerability, which was classified as critical, was found in Ivanti Endpoint Manager. Affected is an unknown function. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CVE-2025-9713. The attack can be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-9626 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9626 | Page Blocks Plugin up to 1.1.0 on WordPress admin_process_widget_page_change cross-site request forgery (EUVD-2025-33848)

A vulnerability classified as problematic was found in Page Blocks Plugin up to 1.1.0 on WordPress. Affected by this vulnerability is the function admin_process_widget_page_change. The manipulation results in cross-site request forgery. Thi

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-8593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-8593 | GSheetConnector for Gravity Forms Plugin up to 1.3.27 on WordPress Plugin Installation install_plugin authorization (EUVD-2025-33844)

A vulnerability classified as critical has been found in GSheetConnector for Gravity Forms Plugin up to 1.3.27 on WordPress. The impacted element is the function install_plugin of the component Plugin Installation Handler. Performing a mani

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2025-37729 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-37729 | Elastic Cloud Enterprise up to 3.8.1/4.0.1 Template Engine special elements in template engine (EUVD-2025-34069)

A vulnerability has been found in Elastic Cloud Enterprise up to 3.8.1/4.0.1 and classified as problematic. This affects an unknown part of the component Template Engine. The manipulation leads to improper neutralization of special elements

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-31995 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31995 | HCL MaxAI Workbench input validation (KB0124425)

A vulnerability was found in HCL MaxAI Workbench and classified as critical. This affects an unknown function. Such manipulation leads to improper input validation. This vulnerability is traded as CVE-2025-31995. The attack may be launched

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11629 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11629 | RainyGao DocSys up to 2.02.36 /Manage/getUserList.do getUserList sql injection (EUVD-2025-33886)

A vulnerability was found in RainyGao DocSys up to 2.02.36. It has been declared as critical. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. This vulnerability is referenc

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11611 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11611 | SourceCodester Simple Inventory System 1.0 /user.php uemail sql injection (EUVD-2025-33873)

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection. This vuln

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11597 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11597 | code-projects E-Commerce Website 1.0 product_add_qty.php prod_id sql injection (EUVD-2025-33860)

A vulnerability identified as critical has been detected in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument prod_id leads to sql inje

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-10375 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-10375 | accessiBe Plugin up to 2.10 on WordPress Setting cross-site request forgery (EUVD-2025-33840)

A vulnerability, which was classified as problematic, has been found in accessiBe Plugin up to 2.10 on WordPress. This impacts the function accessibe_signup/accessibe_login/accessibe_license_trial/accessibe_modify_config/accessibe_add_verif

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105080 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105080 | C4illin ConvertX up to 0.18.x privileges management (EUVD-2026-91868)

A vulnerability has been found in C4illin ConvertX up to 0.18.x and classified as critical. The impacted element is an unknown function. The manipulation leads to improper privilege management. This vulnerability is referenced as CVE-2026-1

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-79113 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79113 | aswf OpenAPV prior 1.1.1.0 privilege escalation (EUVD-2026-91869)

A vulnerability was found in aswf OpenAPV and classified as critical. This affects an unknown function. The manipulation results in privilege escalation. This vulnerability is identified as CVE-2026-79113. The attack can be executed remotel

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-105083 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105083 | ImageMagick up to 6.9.13-56/7.1.2-31 Policy Cache policy.xml LoadPolicyCache access control (EUVD-2026-91870)

A vulnerability was found in ImageMagick up to 6.9.13-56/7.1.2-31. It has been classified as problematic. This impacts the function LoadPolicyCache of the file policy.xml of the component Policy Cache. This manipulation causes improper acce

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-95865 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-95865 | Beaver Builder Page Builder Plugin up to 2.11.0.5 on WordPress AJAX Endpoint fields[][value] sql injection (EUVD-2026-91875)

A vulnerability was found in Beaver Builder Page Builder Plugin up to 2.11.0.5 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component AJAX Endpoint. Performing a manipulation

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-105090 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-105090 | Formbricks up to 5.4.3/6.0.0 Survey-level Custom Head Scripts feature cross site scripting (EUVD-2026-91874)

A vulnerability was found in Formbricks up to 5.4.3/6.0.0. It has been declared as problematic. Affected is an unknown function of the component Survey-level Custom Head Scripts feature. Such manipulation leads to cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-96270 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
WordPress

CVE-2026-96270 | Ultimate Member Plugin up to 2.13.1 on WordPress Admin UI jQuery.html form_id cross site scripting (EUVD-2026-91876)

A vulnerability marked as problematic has been reported in Ultimate Member Plugin up to 2.13.1 on WordPress. This issue affects the function jQuery.html of the component Admin UI. This manipulation of the argument form_id causes cross site

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-94378 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-94378 | psmplugins SupportCandy Plugin up to 3.5.3 on WordPress name cross site scripting (EUVD-2026-91878)

A vulnerability classified as problematic has been found in psmplugins SupportCandy Plugin up to 3.5.3 on WordPress. The affected element is an unknown function. Performing a manipulation of the argument Name results in cross site scripting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-100180 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-100180 | jegtheme Jeg Kit for Elementor Plugin up to 3.2.19 on WordPress cross site scripting (EUVD-2026-91877)

A vulnerability identified as problematic has been detected in jegtheme Jeg Kit for Elementor Plugin up to 3.2.19 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is documented a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-94539 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-94539 | psmplugins SupportCandy Plugin up to 3.5.3 on WordPress sort_by sql injection (EUVD-2026-91879)

A vulnerability categorized as critical has been discovered in psmplugins SupportCandy Plugin up to 3.5.3 on WordPress. Affected by this issue is some unknown functionality. Executing a manipulation of the argument sort_by can lead to sql i

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-92243 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92243 | vinod-dalvi Ivory Search Plugin up to 5.5.18 on WordPress cross site scripting (EUVD-2026-91880)

A vulnerability described as problematic has been identified in vinod-dalvi Ivory Search Plugin up to 5.5.18 on WordPress. Impacted is an unknown function. Such manipulation of the argument s leads to cross site scripting. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-93428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-93428 | Ultimate Member Plugin up to 2.13.1 on WordPress authorization (EUVD-2026-91881)

A vulnerability labeled as problematic has been found in Ultimate Member Plugin up to 2.13.1 on WordPress. This vulnerability affects unknown code. The manipulation results in authorization bypass. This vulnerability is reported as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Citrix NetScaler Keeps Rebooting Following the 0-Day Patch

Citrix NetScaler customers are reporting repeated appliance reboots after installing build 14.1-73.37, the emergency update released for two zero-day flaws under active attack. The failures appear linked to crafted SAML authentication traff

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-39919 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-39919 | Artifex Ghostscript up to 10.7.x JPEG 2000 Output Adapter base/sjpx_openjpeg.c buffer overflow (Nessus ID 350696 / WID-SEC-2026-3408)

A vulnerability was found in Artifex Ghostscript up to 10.7.x. It has been classified as critical. This affects an unknown part of the file base/sjpx_openjpeg.c of the component JPEG 2000 Output Adapter. Performing a manipulation results in

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-15806 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15806 | PSF Python up to 3.15.x urllib.request HTTPPasswordMgr missing encryption (EUVD-2026-61013 / WID-SEC-2026-2924)

A vulnerability classified as problematic was found in PSF Python up to 3.15.x. The affected element is the function HTTPPasswordMgr of the component urllib.request. Executing a manipulation can lead to missing encryption of sensitive data.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-63578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63578 | Legion of the Bouncy Castle bc-csharp up to 2.6.x Password-Based Decryption PbeUtilities.GenerateCipherParameters allocation of resources (WID-SEC-2026-3713)

A vulnerability classified as problematic has been found in Legion of the Bouncy Castle bc-csharp up to 2.6.x. The impacted element is the function PbeUtilities.GenerateCipherParameters of the component Password-Based Decryption. Performing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-63577 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63577 | Legion of the Bouncy Castle bc-csharp up to 2.6.x DirectoryName Name-Constraint Check PkixNameConstraintValidator.WithinDNSubtree certificate validation (WID-SEC-2026-3713)

A vulnerability categorized as problematic has been discovered in Legion of the Bouncy Castle bc-csharp up to 2.6.x. This affects the function PkixNameConstraintValidator.WithinDNSubtree of the component DirectoryName Name-Constraint Check.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-63576 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63576 | Legion of the Bouncy Castle bc-csharp up to 2.6.x PkixNameConstraintValidator PkixNameConstraintValidator.ExtractHostFromURL certificate validation (WID-SEC-2026-3713)

A vulnerability, which was classified as problematic, has been found in Legion of the Bouncy Castle bc-csharp up to 2.6.x. The affected element is the function PkixNameConstraintValidator.ExtractHostFromURL of the component PkixNameConstrai

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-63575 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63575 | Legion of the Bouncy Castle bc-csharp up to 2.6.x PKCS#12 Key Derivation Pkcs12Store.Load infinite loop (WID-SEC-2026-3713)

A vulnerability described as problematic has been identified in Legion of the Bouncy Castle bc-csharp up to 2.6.x. The affected element is the function Pkcs12Store.Load of the component PKCS#12 Key Derivation. Such manipulation leads to inf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-63574 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63574 | Legion of the Bouncy Castle bc-csharp up to 2.6.x OpenPGP Subpacket Parsers memory allocation (WID-SEC-2026-3713)

A vulnerability was found in Legion of the Bouncy Castle bc-csharp up to 2.6.x. It has been declared as problematic. Affected by this vulnerability is the function SignatureSubpacketsParser.ReadPacket/UserAttributeSubpacketsParser.ReadPacke

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-63573 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63573 | Legion of the Bouncy Castle bc-csharp up to 2.6.x KeyTransRecipientInformation.UnwrapKey random values (WID-SEC-2026-3713)

A vulnerability was found in Legion of the Bouncy Castle bc-csharp up to 2.6.x. It has been rated as problematic. Affected by this issue is the function KeyTransRecipientInformation.UnwrapKey. Performing a manipulation results in insufficie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1%
CVE-2025-60006 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-60006 | Juniper Junos OS Evolved prior 24.2R1/24.2R2-S2-EVO/24.4R2-EVO CLI os command injection (JSA103163 / EUVD-2025-33362)

A vulnerability classified as critical has been found in Juniper Junos OS Evolved. Affected by this vulnerability is an unknown functionality of the component CLI. The manipulation leads to os command injection. This vulnerability is unique

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-21065 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-21065 | Samsung Retail Mode up to 5.59.10 input validation

A vulnerability was found in Samsung Retail Mode up to 5.59.10. It has been declared as critical. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper input validation. The identification

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-21060 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-21060 | Samsung Smart Switch 3.7.64.10 cleartext storage

A vulnerability classified as problematic was found in Samsung Smart Switch 3.7.64.10. Impacted is an unknown function. Executing a manipulation can lead to cleartext storage of sensitive information. This vulnerability appears as CVE-2025-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11583 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11583 | code-projects Online Job Search Engine 1.0 /postjob.php txtjobID sql injection (EUVD-2025-33774)

A vulnerability labeled as critical has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing a manipulation of the argument txtjobID can lead to sql injection. The ide

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11554 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11554 | Portabilis i-Educar up to 2.9.10 User Type AccessLevelController.php insecure inherited permissions (EUVD-2025-33561)

A vulnerability, which was classified as critical, has been found in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Typ

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 13%
CVE-2025-61913 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-61913 | FlowiseAI Flowise up to 3.0.7 WriteFileTool/ReadFileTool path traversal (GHSA-j44m-5v8f-gc9c / EUVD-2025-33322)

A vulnerability was found in FlowiseAI Flowise up to 3.0.7 and classified as critical. The affected element is an unknown function of the component WriteFileTool/ReadFileTool. Such manipulation leads to path traversal. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59990 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)

A vulnerability labeled as problematic has been found in Juniper Junos Space up to 24.1R3. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting. This vulnerability appears as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59988 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59988 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)

A vulnerability categorized as problematic has been discovered in Juniper Junos Space up to 24.1R3. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability appears as CVE-2025-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59984 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59984 | Juniper Junos Space up to 24.1R3 cross site scripting (JSA103140)

A vulnerability was found in Juniper Junos Space up to 24.1R3. It has been declared as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability is documented as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-36636 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-36636 | Tenable Security Center up to 6.6.x access control (Nessus ID 269967)

A vulnerability was found in Tenable Security Center up to 6.6.x. It has been rated as critical. This vulnerability affects unknown code. This manipulation causes improper access controls. The identification of this vulnerability is CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11495 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11495 | GNU Binutils 2.45 Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow (Bug 33502 / Nessus ID 270764)

A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11494 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11494 | GNU Binutils 2.45 Linker bfd/elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds (Bug 33499 / Nessus ID 270764)

A vulnerability was found in GNU Binutils 2.45 and classified as problematic. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-59452 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59452 | YoSmart YoLink API up to 2025-10-02 generation of predictable numbers or identifiers

A vulnerability classified as problematic has been found in YoSmart YoLink API up to 2025-10-02. This vulnerability affects unknown code. This manipulation causes generation of predictable numbers or identifiers. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11402 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11402 | SourceCodester Hotel and Lodge Management System 1.0 /del_curr.php id sql injection

A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /del_curr.php. Such manipulation of the argument ID leads t

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11396 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11396 | code-projects Simple Food Ordering System 1.0 /product.php category sql injection

A vulnerability described as critical has been identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql injection. This vu

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-11321 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11321 | zhuimengshaonian wisdom-education up to 1.0.4 WrongBookController.java subjectId authorization (EUVD-2025-32489)

A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4. It has been rated as problematic. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2025-11300 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11300 | Belkin F9K1015 1.00.10 /goform/formWlanMP ateFunc buffer overflow (EUVD-2025-32466)

A vulnerability classified as critical was found in Belkin F9K1015 1.00.10. The impacted element is an unknown function of the file /goform/formWlanMP. The manipulation of the argument ateFunc results in buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 1.1%
CVE-2025-11297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11297 | Belkin F9K1015 1.00.10 /goform/formSetLanguage webpage buffer overflow (EUVD-2025-32462)

A vulnerability marked as critical has been reported in Belkin F9K1015 1.00.10. This issue affects some unknown processing of the file /goform/formSetLanguage. Performing a manipulation of the argument webpage results in buffer overflow. Th

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-9897 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9897 | AP Background Plugin up to 3.8.2 on WordPress advParallaxBackAdminSaveSlider cross-site request forgery

A vulnerability was found in AP Background Plugin up to 3.8.2 on WordPress and classified as problematic. Impacted is the function advParallaxBackAdminSaveSlider. Executing a manipulation can lead to cross-site request forgery. This vulnera

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-9892 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9892 | Restrict User Registration Plugin up to 1.0.1 on WordPress Setting update cross-site request forgery

A vulnerability has been found in Restrict User Registration Plugin up to 1.0.1 on WordPress and classified as problematic. Affected is the function update of the component Setting Handler. This manipulation causes cross-site request forger

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-9286 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9286 | Appy Pie Connect for WooCommerce Plugin up to 1.1.2 on WordPress REST reset_user_password authorization

A vulnerability has been found in Appy Pie Connect for WooCommerce Plugin up to 1.1.2 on WordPress and classified as critical. Affected by this issue is the function reset_user_password of the component REST Handler. This manipulation cause

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.