Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | CVEs | Anteil |
|---|---|---|
| ≥90 % | 720 | 0,2 % |
| ≥50 % | 3.223 | 0,9 % |
| ≥10 % | 22.115 | 6,0 % |
| <10 % | 342.373 | 92,9 % |
Telegram Desktop 7.2.9 corrige CVE-2026-107181 de robo de cuenta
Un clic en un link dentro de un chat de grupo bastaba para que un atacante leyera cualquier archivo del equipo de la víctima y, con él, robara la sesión activa de su cuenta. El hallazgo, publicado por el investigador detrás del blog beaksec
CVE-2026-98382 | Linux Kernel up to 7.3-rc4 BPF drivers/net/veth.c __bpf_offload_dev_match null pointer dereference (EUVD-2026-95537 / WID-SEC-2026-3822)
A vulnerability was found in Linux Kernel up to 6.6.157/6.12.111/6.18.54/7.2.8/7.3-rc4. It has been classified as very critical. This issue affects the function __bpf_offload_dev_match of the file drivers/net/veth.c of the component BPF. Pe
CVE-2026-98381 | Linux Kernel up to 7.3-rc4 veth drivers/net/veth.c veth_set_channels xdp_prog memory corruption (EUVD-2026-95536 / WID-SEC-2026-3822)
A vulnerability was found in Linux Kernel up to 7.3-rc4 and classified as very critical. This vulnerability affects the function veth_set_channels of the file drivers/net/veth.c of the component veth. Such manipulation of the argument xdp_p
CVE-2026-98379 | Linux Kernel up to 7.3-rc4 ip6t_rpfilter ip6t_rpfilter.c rpfilter_mt null pointer dereference (EUVD-2026-95534 / WID-SEC-2026-3822)
A vulnerability identified as critical has been detected in Linux Kernel up to 7.3-rc4. This affects the function rpfilter_mt of the file net/ipv6/netfilter/ip6t_rpfilter.c of the component ip6t_rpfilter. This manipulation causes null point
CVE-2026-98378 | Linux Kernel up to 7.3-rc4 Link Iterator kernel/bpf/syscall.c bpf_link_put use after free (EUVD-2026-95533 / WID-SEC-2026-3822)
A vulnerability was found in Linux Kernel up to 7.3-rc4. It has been declared as very critical. Impacted is the function bpf_link_put of the file kernel/bpf/syscall.c of the component Link Iterator. Executing a manipulation can lead to use
CVE-2026-98377 | Linux Kernel up to 6.12.111/6.18.54/7.2.8/7.3-rc4 vlan __vlan_insert_inner_tag information disclosure (EUVD-2026-95532 / WID-SEC-2026-3822)
A vulnerability has been found in Linux Kernel up to 6.12.111/6.18.54/7.2.8/7.3-rc4 and classified as problematic. This affects the function __vlan_insert_inner_tag of the component vlan. This manipulation causes information disclosure. Thi
CVE-2026-106155 | Progress Telerik Report Server up to 10.3.24.1112 Shared Reporting Engine cross site scripting (WID-SEC-2026-3823)
A vulnerability described as problematic has been identified in Progress Telerik Report Server up to 10.3.24.1112. This affects an unknown function of the component Shared Reporting Engine. Such manipulation leads to cross site scripting. T
CVE-2026-97791 | Apache CXF up to 3.6.12/4.1.8/4.2.3 STSTokenValidator information disclosure (WID-SEC-2026-3824)
A vulnerability, which was classified as problematic, was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. This affects the function STSTokenValidator. The manipulation results in information disclosure. This vulnerability is known as CVE-2026
CVE-2026-106145 | Progress Telerik Report Server up to 10.3.24.1112 Service Agent SignalR Hub privileges management (WID-SEC-2026-3823)
A vulnerability labeled as critical has been found in Progress Telerik Report Server up to 10.3.24.1112. The affected element is an unknown function of the component Service Agent SignalR Hub. The manipulation results in improper privilege
CVE-2026-97468 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Security Token Service Cache STSTokenValidator.hashCode improper authentication (WID-SEC-2026-3824)
A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been rated as critical. This affects the function STSTokenValidator.hashCode of the component Security Token Service Cache. The manipulation leads to improper authenti
CVE-2026-86463 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Query Parser resource consumption (WID-SEC-2026-3824)
A vulnerability classified as problematic has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3. Impacted is an unknown function of the component Query Parser. Performing a manipulation results in resource consumption. This vulnerability is
CVE-2026-79650 | Apache CXF up to 3.6.12/4.1.8/4.2.3 OIDC relying-party component state redirect (WID-SEC-2026-3824)
A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component OIDC relying-party component. Performing a manipulation of
CVE-2026-78384 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Compression Utils CompressionUtils.inflate resource consumption (WID-SEC-2026-3824)
A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. It has been declared as problematic. Affected by this issue is the function CompressionUtils.inflate of the component Compression Utils. Executing a manipulation can lead to
CVE-2026-73179 | Apache CXF up to 3.6.12/4.1.8/4.2.3 JPA OAuth2 Authorization Code Grant Provider race condition (WID-SEC-2026-3824)
A vulnerability classified as problematic was found in Apache CXF up to 3.6.12/4.1.8/4.2.3. The affected element is an unknown function of the component JPA OAuth2 Authorization Code Grant Provider. Executing a manipulation can lead to race
CVE-2026-108039 | Apache CXF up to 3.6.12/4.1.8/4.2.3 StaxUtils denial of service (WID-SEC-2026-3824)
A vulnerability has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3 and classified as problematic. This impacts an unknown function of the component StaxUtils. This manipulation causes denial of service. This vulnerability is handled as C
CVE-2026-107938 | Apache CXF up to 3.6.12/4.1.8/4.2.3 cxf-rt-transports-http-netty-client certificate validation (WID-SEC-2026-3824)
A vulnerability described as problematic has been identified in Apache CXF up to 3.6.12/4.1.8/4.2.3. This issue affects some unknown processing of the component cxf-rt-transports-http-netty-client. Such manipulation leads to improper certif
CVE-2026-107937 | Apache CXF up to 3.6.12/4.1.8/4.2.3 Parser denial of service (WID-SEC-2026-3824)
A vulnerability was found in Apache CXF up to 3.6.12/4.1.8/4.2.3 and classified as problematic. Affected is an unknown function of the component Parser. Such manipulation leads to denial of service. This vulnerability is uniquely identified
CVE-2026-100227 | Apache CXF up to 3.6.12/4.1.8/4.2.3 JAX-RS XML Signature Interceptors data authenticity (WID-SEC-2026-3824)
A vulnerability, which was classified as critical, has been found in Apache CXF up to 3.6.12/4.1.8/4.2.3. The impacted element is the function XmlSigInHandler/XmlSigInInterceptor/XmlSecInInterceptor of the component JAX-RS XML Signature Int
CVE-2026-98375 | Linux Kernel up to 7.3-rc6 netfront handle_incoming_queue information disclosure (EUVD-2026-95525 / WID-SEC-2026-3826)
A vulnerability was found in Linux Kernel up to 7.3-rc6. It has been rated as problematic. This vulnerability affects the function handle_incoming_queue of the component netfront. Performing a manipulation results in information disclosure.
CVE-2026-106438 | MongoDB up to 1.30.12/2.5.5 C Driver calculation (WID-SEC-2026-3830)
A vulnerability has been found in MongoDB up to 1.30.12/2.5.5 and classified as problematic. Affected by this issue is some unknown functionality of the component C Driver. This manipulation causes incorrect calculation. This vulnerability
CVE-2026-106437 | MongoDB C Driver up to 1.30.12/2.5.5 BSON buffer-reservation API bson_reserve_buffer integer underflow (WID-SEC-2026-3830)
A vulnerability marked as critical has been reported in MongoDB C Driver up to 1.30.12/2.5.5. The affected element is the function bson_reserve_buffer of the component BSON buffer-reservation API. This manipulation causes integer underflow.
CVE-2026-106435 | MongoDB Python Driver up to 4.18.2 Binary Accelerator decode buffer overflow (WID-SEC-2026-3830)
A vulnerability labeled as critical has been found in MongoDB Python Driver up to 4.18.2. The affected element is the function decode of the component Binary Accelerator. Such manipulation leads to buffer overflow. This vulnerability is doc
CVE-2026-106432 | MongoDB PHP Driver up to 1.21.10/2.1.10/2.5.3 BSON encoder heap-based overflow (WID-SEC-2026-3830)
A vulnerability identified as very critical has been detected in MongoDB PHP Driver up to 1.21.10/2.1.10/2.5.3. Affected is an unknown function of the component BSON encoder. Performing a manipulation results in heap-based buffer overflow.
CVE-2019-8906 | libmagic 5.35 readelf.c do_core_note out-of-bounds (ID 277708 / BID-107137)
A vulnerability was found in libmagic 5.35. It has been declared as critical. This affects the function do_core_note of the file readelf.c. Executing a manipulation can lead to out-of-bounds read. This vulnerability is registered as CVE-201
CVE-2019-12086 | Oracle JD Edwards EnterpriseOne Tools 9.2 Monitoring/Diagnostics SEC information disclosure (Nessus ID 236644 / ID 176941)
A vulnerability labeled as critical has been found in Oracle JD Edwards EnterpriseOne Tools 9.2. This issue affects some unknown processing of the component Monitoring/Diagnostics SEC. Executing a manipulation can lead to information disclo
CVE-2018-14719 | FasterXML jackson-databind up to 2.9.6 Deserialization blaze-ds-opt/blaze-ds-core deserialization (RHSA-2019:0782 / Nessus ID 121251)
A vulnerability labeled as critical has been found in FasterXML jackson-databind up to 2.9.6. This affects the function blaze-ds-opt/blaze-ds-core of the component Deserialization. Executing a manipulation can lead to deserialization. The i
CVE-2018-12022 | Oracle Clusterware 12.1.0.2.0 TFA Collector deserialization (ID 176909 / BID-107585)
A vulnerability was found in Oracle Clusterware 12.1.0.2.0. It has been classified as critical. This affects an unknown function of the component TFA Collector. This manipulation causes deserialization. This vulnerability is tracked as CVE-
Why API Gateways Keep Failing Authentication: Lessons From Cisco ISE CVE-2026-76460
Why API Gateways Keep Failing Authentication: Lessons From Cisco ISE CVE-2026-76460 A maximum severity score is rare enough to draw attention, and CVE-2026-76460 earned it. The flaw in Cisco Identity Services Engine combined unauthenticated
CVE-2018-14718 | Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0 jackson-databind deserialization (ID 176635 / BID-106601)
A vulnerability, which was classified as critical, has been found in Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0. This affects an unknown function of the component jackson-databind. This manipulation causes deserialization. This vulnerability a
CVE-2026-103427 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers may also exploit this
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possib
CVE-2026-3717 | The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to upload arbitrary content to the WordPress uploads directory as png files.
The CV Builder – Professional Resume Builder SaaS plugin for WordPress is vulnerable to unauthorized arbitrary file upload due to a missing capability check on the 'wp_save_signature_image' function in all versions up to, and including, 1.3
CVE-2026-107742 | The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because a co
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 2.34.8 due to insufficient input
CVE-2026-104006 | The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes it
CVE-2026-102402 | The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ttp_filter_taxonomy (meta of the attacker-chosen post)' parameter in all versions up to, and including, 6.0.2 due to insuffic
CVE-2026-100196 | The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Word
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content (rendered inline into the page HTML)' parameter in all versions up to, and including, 2.4
CVE-2026-6243 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing tex
CVE-2026-5725 | The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. Th
CVE-2026-107712 | The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_month' parameter in all versions up to, and including, 2.1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries t
The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_month' parameter in all versions up to, and including, 2.1.0.1 due to insufficient escaping on the user supplied parame
CVE-2026-94538 | The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete any file managed by WP File Download, empty the entire trash, move files between categories, and publish or unpublish arbitrary
The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it poss
CVE-2026-100161 | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The publicly-emitted `wcpr_image_upload` nonce prin
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all versions up to, and including, 1.2.30 due to insufficient input sanitization and o
CVE-2026-89100 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unc
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output esca
CVE-2026-104801 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The relocated file is moved b
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This
CVE-2026-103897 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the plugin's 'Comm
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.7.9 due to insufficient input sanitization and output escaping. This mak
CVE-2026-97348 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The widget's normal update()/sanitize_field_input() pipeline — which would reject non-hex color values — i
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.74.3 via the get_instance_css function. This makes it possible for authenticated attackers, with contributor-lev
CVE-2026-12626 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes it possible for authenticated attackers, with custom-level access and above, to inject a PHP Object. No known gadget chain is available.
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 28.2 via deserialization of untrusted input via the ‘value’ parameter. This makes
CVE-2026-96840 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress core's pre_user_display_name filter encodes &, <, and > but l
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via display_name User Field in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. Thi
CVE-2026-96574 | The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpuf_payment_method' parameter in all versions up to, and including, 4.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scri
The User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpuf_payment_method' parameter in
CVE-2026-95684 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output esc
CVE-2026-96558 | The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacke
The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficie
CVE-2026-15178 | The Fluent Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.2.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Custom-level access and above, to read private form submissions, change submission statuses, permanently delete submissions, and modify global plugin settings.
The Fluent Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.2.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible
CVE-2026-108502 | ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.
ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.
DFN-CERT-2026-5584 hpack: Eine Schwachstelle ermöglicht einen Denial-of-Service-Angriff
Bücher über Cybersicherheit und Computerspiele. Bücher/04. Bücher über Staat und IT sowie Programmierung von KI. Bücher/01. Ein Buch über die ... Weiterlesen
CVE-2026-17025 | The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output
CVE-2026-14335 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PayPal IPN Parameters in all versions up to, and including, 3.6.9 due to insufficient input sa
CVE-2026-12054 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'REFERRER' parameter in all versions up to, and including, 3.3.57 due to insufficient input sanitization and output escaping. This makes it possib
CVE-2026-14882 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'brizy-compiled-sections' parameter in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping.
CVE-2026-103912 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '<attacker-chosen query var name matching the preset's query_var setting>' parameter in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the '
CVE-2026-93775 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint wit
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possi
CVE-2026-14877 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id attribute in all versions up to, and including, 1.12.03 due to insufficient input sanitization and output escaping. This mak
CVE-2026-103482 | The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[<custom_field_merge_tag>] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The attack chain req
The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noptin_fields[] (e.g. first_name)' parameter in all versions up to, and including, 4.3.10 due to insufficient input sanitizatio