CVE-2026-104123: Schwachstellen-Eintrag (NVD)
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-18 | 2026-10-01 |
|---|---|---|
| ≥90 % | 0 | 377 |
| ≥50 % | 0 | 1137 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 451 |
CVE-2026-91793 | Foxit PDF Editor/Reader Annotation use after free (EUVD-2026-85129)
A vulnerability categorized as critical has been discovered in Foxit PDF Editor and Reader. Impacted is an unknown function of the component Annotation. The manipulation results in use after free. This vulnerability is cataloged as CVE-2026
CVE-2026-47040 | Oracle Database Server up to 19.31/21.22/23.26.2 Net Services missing authentication (Nessus ID 330093)
A vulnerability labeled as critical has been found in Oracle Database Server up to 19.31/21.22/23.26.2. This affects an unknown part of the component Net Services. The manipulation results in missing authentication. This vulnerability is ca
CVE-2026-91790 | Foxit PDF Editor/PDF Reader use after free (EUVD-2026-85132)
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-91790. The attack
CVE-2026-47039 | Oracle Database Server up to 19.31/21.22/23.26.2 Java VM improper authorization
A vulnerability described as problematic has been identified in Oracle Database Server up to 19.31/21.22/23.26.2. This vulnerability affects unknown code of the component Java VM. The manipulation results in improper authorization. This vul
CVE-2026-91792 | Foxit PDF Editor/PDF Reader use after free (EUVD-2026-85130)
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in use after free. This vulnerability is identified as CVE-2026-91792. The
CVE-2026-47045 | Oracle Database Server up to 19.31/21.22/23.26.2 JDBC redirect
A vulnerability described as very critical has been identified in Oracle Database Server up to 19.31/21.22/23.26.2. This issue affects some unknown processing of the component JDBC. Such manipulation leads to open redirect. This vulnerabili
CVE-2026-91817 | Foxit PDF Editor/PDF Reader out-of-bounds
A vulnerability, which was classified as problematic, has been found in Foxit PDF Editor and PDF Reader. This issue affects some unknown processing. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE
CVE-2026-83348 | Oracle Database Server RDBMS privileges management
A vulnerability was found in Oracle Database Server. It has been classified as very critical. Affected by this issue is some unknown functionality of the component RDBMS. This manipulation causes improper privilege management. The identific
CVE-2026-91812 | Foxit PDF Editor/PDF Reader certificate validation
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes improper certificate validation. This vulnerability is tracked as CVE-2026
CVE-2026-83272 | Oracle Database Server Oracle Text privileges management
A vulnerability classified as very critical has been found in Oracle Database Server. The affected element is an unknown function of the component Oracle Text. This manipulation causes improper privilege management. This vulnerability appea
CVE-2026-91802 | Foxit PDF Editor/PDF Reader WebP image decoding heap-based overflow
A vulnerability marked as problematic has been reported in Foxit PDF Editor and PDF Reader. This affects an unknown function of the component WebP image decoding. Performing a manipulation results in heap-based buffer overflow. This vulnera
CVE-2026-91803 | Foxit PDF Editor/PDF Reader Updater privileges management
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been classified as problematic. Impacted is an unknown function of the component Updater. The manipulation leads to improper privilege management. This vulnerability is re
CVE-2026-91813 | Foxit PDF Editor/PDF Reader Update Mechanism race condition
A vulnerability has been found in Foxit PDF Editor and PDF Reader and classified as problematic. The affected element is an unknown function of the component Update Mechanism. The manipulation leads to race condition. This vulnerability is
CVE-2026-86776 | KeePass up to 2.61.1 ReadHeaderField allocation of resources (EUVD-2026-74788)
A vulnerability, which was classified as problematic, has been found in KeePass up to 2.61.1. This issue affects the function ReadHeaderField. This manipulation causes allocation of resources. This vulnerability is tracked as CVE-2026-86776
CVE-2026-91814 | Foxit PDF Editor/PDF Reader Signature Validation data authenticity
A vulnerability classified as problematic was found in Foxit PDF Editor and PDF Reader. This vulnerability affects unknown code of the component Signature Validation. Such manipulation leads to insufficient verification of data authenticity
CVE-2026-91796 | Foxit PDF Editor/PDF Reader Secure Reading Mode permission (EUVD-2026-85126)
A vulnerability labeled as problematic has been found in Foxit PDF Editor and PDF Reader. The impacted element is an unknown function of the component Secure Reading Mode. Such manipulation leads to permission issues. This vulnerability is
CVE-2026-91811 | Foxit PDF Editor/PDF Reader PRC Parser out-of-bounds write
A vulnerability described as problematic has been identified in Foxit PDF Editor and PDF Reader. Affected by this issue is some unknown functionality of the component PRC Parser. The manipulation results in out-of-bounds write. This vulnera
CVE-2026-91794 | Foxit PDF Editor/PDF Reader PDF Rendering out-of-bounds write (EUVD-2026-85128)
A vulnerability has been found in Foxit PDF Editor and PDF Reader and classified as critical. Affected by this vulnerability is an unknown functionality of the component PDF Rendering. This manipulation causes out-of-bounds write. The ident
CVE-2026-91805 | Foxit PDF Editor/PDF Reader PDF Page-Tree use after free (EUVD-2026-85123)
A vulnerability, which was classified as problematic, has been found in Foxit PDF Editor and PDF Reader. Affected by this issue is some unknown functionality of the component PDF Page-Tree Handler. This manipulation causes use after free. T
CVE-2026-91810 | Foxit PDF Editor/PDF Reader PDF Image Mask out-of-bounds
A vulnerability marked as problematic has been reported in Foxit PDF Editor and PDF Reader. Affected by this vulnerability is an unknown functionality of the component PDF Image Mask. The manipulation leads to out-of-bounds read. This vulne
CVE-2026-91809 | Foxit PDF Editor/PDF Reader PDF Form Fields use after free
A vulnerability labeled as problematic has been found in Foxit PDF Editor and PDF Reader. Affected is an unknown function of the component PDF Form Fields. Executing a manipulation can lead to use after free. This vulnerability is registere
CVE-2026-91818 | Foxit PDF Editor/PDF Reader JavaScript use after free (EUVD-2026-85156)
A vulnerability, which was classified as problematic, was found in Foxit PDF Editor and PDF Reader. Impacted is an unknown function of the component JavaScript Handler. Executing a manipulation can lead to use after free. This vulnerability
CVE-2026-91788 | Foxit PDF Editor/PDF Reader JavaScript Interface improper authorization (EUVD-2026-85133)
A vulnerability was found in Foxit PDF Editor and PDF Reader and classified as problematic. Affected by this issue is some unknown functionality of the component JavaScript Interface. Such manipulation leads to improper authorization. This
CVE-2026-91799 | Foxit PDF Editor/PDF Reader JavaScript Array use after free (EUVD-2026-85124)
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been declared as critical. This vulnerability affects unknown code of the component JavaScript Array Handler. Executing a manipulation can lead to use after free. This vul
CVE-2026-85016 | Elementor Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress Widget Parameter Processor icon cross site scripting (EUVD-2026-91192)
A vulnerability, which was classified as problematic, has been found in Elementor Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress. Impacted is an unknown function of the component Widget Parameter Processor. This manipulat
CVE-2026-91023 | Motors Plugin up to 1.4.123 on WordPress authorization (EUVD-2026-91194)
A vulnerability has been found in Motors Plugin up to 1.4.123 on WordPress and classified as critical. The impacted element is an unknown function. Performing a manipulation results in missing authorization. This vulnerability is reported a
CVE-2026-91022 | Motors Plugin up to 1.4.123 on WordPress cross site scripting (EUVD-2026-91193)
A vulnerability was found in Motors Plugin up to 1.4.123 on WordPress. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting. This vulnerability is handle
CVE-2026-97317 | RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress Giveaway Settings information disclosure (EUVD-2026-91196)
A vulnerability categorized as problematic has been discovered in RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress. Affected by this issue is some unknown functionality of the component Giveaway Settings.
CVE-2026-94298 | BuildKit Plugin up to 1.0.28 on WordPress sql injection (EUVD-2026-91195)
A vulnerability, which was classified as critical, was found in BuildKit Plugin up to 1.0.28 on WordPress. The affected element is an unknown function. Such manipulation leads to sql injection. This vulnerability is documented as CVE-2026-9
CVE-2026-81740 | Paytm Payment Gateway Plugin up to 2.8.8 on WordPress Payment Callback improper authentication (EUVD-2026-91201)
A vulnerability was found in Paytm Payment Gateway Plugin up to 2.8.8 on WordPress and classified as critical. This affects an unknown function of the component Payment Callback Handler. Executing a manipulation can lead to improper authent
CVE-2026-97318 | RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress Parent Page URL Validation redirect (EUVD-2026-91197)
A vulnerability identified as problematic has been detected in RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress. This affects an unknown part of the component Parent Page URL Validation. Performing a manip
USN-8864-1: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking
CVE-2026-93698 | Webpros cPanel/WP Squared adminbin os command injection (WID-SEC-2026-3698)
A vulnerability marked as critical has been reported in Webpros cPanel and WP Squared. This issue affects some unknown processing of the component adminbin. The manipulation leads to os command injection. This vulnerability is referenced as
CVE-2026-93697 | Webpros cPanel/WP Squared Mass Modify Accounts Interface cross site scripting (WID-SEC-2026-3698)
A vulnerability described as problematic has been identified in Webpros cPanel and WP Squared. Impacted is an unknown function of the component Mass Modify Accounts Interface. The manipulation results in cross site scripting. This vulnerabi
CVE-2026-93029 | Webpros cPanel/WP Squared Manage SSL Hosts Interface cross site scripting (WID-SEC-2026-3698)
A vulnerability labeled as problematic has been found in Webpros cPanel and WP Squared. This vulnerability affects unknown code of the component Manage SSL Hosts Interface. Executing a manipulation can lead to cross site scripting. The iden
CVE-2026-102490 | Zammad privileges management (WID-SEC-2026-3694)
A vulnerability was found in Zammad. It has been rated as problematic. This issue affects some unknown processing. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-102490. The
CVE-2026-102489 | Zammad up to 6.5.4/7.1.3 session fixiation (WID-SEC-2026-3694)
A vulnerability, which was classified as critical, has been found in Zammad up to 6.5.4/7.1.3. This impacts an unknown function. Performing a manipulation results in session fixiation. This vulnerability is known as CVE-2026-102489. Remote
Angriffe auf FortiMail-Zero-Day-Lücke beobachtet
Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz. Weiterlesen
FortiMail: Angriffe auf Zero-Day-Lücke laufen, Workaround verfügbar
Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz. Weiterlesen
CVE-2026-92820 | SaturdayDrive Ninja Forms Plugin up to 3.3.34 on WordPress External File Upload file_path path traversal (EUVD-2026-91175)
A vulnerability categorized as critical has been discovered in SaturdayDrive Ninja Forms Plugin up to 3.3.34 on WordPress. This impacts an unknown function of the component External File Upload. The manipulation of the argument file_path re
CVE-2026-15897 | WebRehab Super Forms Plugin up to 6.3.316 on WordPress Register/Login Add-on before_email_success_msg user_id privileges management (EUVD-2026-91176)
A vulnerability marked as critical has been reported in WebRehab Super Forms Plugin up to 6.3.316 on WordPress. Affected by this issue is the function before_email_success_msg of the component Register/Login Add-on. Performing a manipulatio
CVE-2026-92174 | SiteOrigin Widgets Bundle Plugin up to 1.73.2 on WordPress REST Endpoint previews update_fields theme unrestricted upload (EUVD-2026-91178)
A vulnerability was found in SiteOrigin Widgets Bundle Plugin up to 1.73.2 on WordPress. It has been declared as critical. The impacted element is the function update_fields of the file /wp-json/sowb/v1/widgets/previews of the component RES
CVE-2026-90438 | Ninja Forms Plugin up to 3.15.4 on WordPress cross site scripting (EUVD-2026-91177)
A vulnerability described as problematic has been identified in Ninja Forms Plugin up to 3.15.4 on WordPress. This affects an unknown part. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2026
CVE-2026-78471 | optimizingmatters Autoptimize Plugin up to 3.1.15.1 on WordPress w3-total-cache.php Comment Author Name cross site scripting (EUVD-2026-91179)
A vulnerability was found in optimizingmatters Autoptimize Plugin up to 3.1.15.1 on WordPress. It has been rated as problematic. This affects an unknown function of the file w3-total-cache/w3-total-cache.php. The manipulation of the argumen
CVE-2026-15896 | WebRehab Super Forms Plugin up to 6.3.316 on WordPress parse_request path traversal (EUVD-2026-91180)
A vulnerability identified as problematic has been detected in WebRehab Super Forms Plugin up to 6.3.316 on WordPress. Affected is the function parse_request. This manipulation causes path traversal. The identification of this vulnerability
CVE-2022-45498 | Tenda W6-S 1.0.0.4 /goform/SysToolReboot tpi_systool_handle denial of service (EUVD-2022-48364)
A vulnerability described as problematic has been identified in Tenda W6-S 1.0.0.4. The impacted element is the function tpi_systool_handle of the file /goform/SysToolReboot. The manipulation results in denial of service. This vulnerability
CVE-2022-45497 | Tenda W6-S 1.0.0.4 /goform/exeCommand tpi_get_ping_output command injection (EUVD-2022-48363)
A vulnerability was found in Tenda W6-S 1.0.0.4. It has been rated as critical. The impacted element is the function tpi_get_ping_output of the file /goform/exeCommand. Performing a manipulation results in command injection. This vulnerabil
CVE-2022-45496 | json.h json_parse_string buffer overflow (ID 92 / 0825301a07cbf51653882bf2b153cc81fdadf41)
A vulnerability, which was classified as critical, has been found in json.h. This vulnerability affects the function json_parse_string. Performing a manipulation results in buffer overflow. This vulnerability is cataloged as CVE-2022-45496.
USN-8851-2: Linux kernel (Raspberry Pi) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking
CVE-2022-45494 | sheredom json.h json_parse_object heap-based overflow (ID 93 / EUVD-2022-48360)
A vulnerability classified as critical has been found in sheredom json.h. Affected by this issue is the function json_parse_object. The manipulation leads to heap-based buffer overflow. This vulnerability is traded as CVE-2022-45494. Access
CVE-2022-45493 | json.h json_parse_key buffer overflow (GHSA-r2mm-2f4c-6243 / 0825301a07cbf51653882bf2b153cc81fdadf41)
A vulnerability classified as critical was found in json.h. This affects the function json_parse_key. Such manipulation leads to buffer overflow. This vulnerability is listed as CVE-2022-45493. The attack must be carried out from within the
CVE-2022-45492 | json.h json_parse_number buffer overflow (ID 95 / 0825301a07cbf51653882bf2b153cc81fdadf41)
A vulnerability classified as critical has been found in json.h. Affected by this issue is the function json_parse_number. This manipulation causes buffer overflow. This vulnerability is tracked as CVE-2022-45492. The attack is only possibl
CVE-2022-45491 | json.h json_parse_value buffer overflow (ID 94 / 0825301a07cbf51653882bf2b153cc81fdadf41)
A vulnerability described as critical has been identified in json.h. Affected by this vulnerability is the function json_parse_value. The manipulation results in buffer overflow. This vulnerability is identified as CVE-2022-45491. The attac
CVE-2026-104054 | A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in mis
CVE-2026-104053 | A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible
CVE-2026-21140 | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
CVE-2026-104052 | A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to
CVE-2026-104480 | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio a
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able t
CVE-2026-103098 | Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor networ
CVE-2026-103097 | An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and m
Noch keine Analyse zu CVE-2026-104123
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.