<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - Reverse Engineering]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/reverse-engineering.xml]]></link>
<description><![CDATA[Binary Analysis, Disassembly & Reverse Engineering. Technische Anleitungen zu Ghidra, IDA Pro, Malware Decompilation und Firmware-Untersuchungen.]]></description>
<language>de-DE</language>
<lastBuildDate>Sun, 20 Sep 2026 05:30:50 +0200</lastBuildDate>
<pubDate>Sun, 20 Sep 2026 05:30:50 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - Reverse Engineering</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - Reverse Engineering]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/reverse-engineering.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[AI Didn't Hack OpenAI. A Missed Debian Backport and an SSO Misconfiguration Did]]></title>
<description><![CDATA[The headline that circulated this week sounds like a movie trailer: hackers breached OpenAI's internal codebase in 72 hours, and an AI model wrote the exploit. Three researchers, a Claude model, a pull request inside OpenAI's private monorepo. The real story is more useful and more uncomfortable....]]></description>
<link>https://tsecurity.de/de/4158557/sicherheitsluecken-cve/ai-didnt-hack-openai-a-missed-debian-backport-and-an-sso-misconfiguration-did/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4158557/sicherheitsluecken-cve/ai-didnt-hack-openai-a-missed-debian-backport-and-an-sso-misconfiguration-did/</guid>
<pubDate>Sun, 20 Sep 2026 05:28:08 +0200</pubDate>
<content:encoded><![CDATA[<p>The headline that circulated this week sounds like a movie trailer: hackers breached OpenAI&#039;s internal codebase in 72 hours, and an AI model wrote the exploit. Three researchers, a Claude model, a pull request inside OpenAI&#039;s private monorepo. The real story is more useful and more uncomfortable. No exotic AI vulnerability was involved. The breach... <a href="https://dev.to/jamilxt/ai-didnt-hack-openai-a-missed-debian-backport-and-an-sso-misconfiguration-did-4mj2" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your AI Agent Should Be a Guest, Not a Tenant]]></title>
<description><![CDATA[Why standing credentials are the quiet root cause behind this week's agent security headlines, and what zero standing privilege looks like in practice. On Thursday, researchers reported a zero-click remote code execution flaw in four major AI coding agents. The attack chain ran through the plugin...]]></description>
<link>https://tsecurity.de/de/4158416/sicherheitsluecken-cve/your-ai-agent-should-be-a-guest-not-a-tenant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4158416/sicherheitsluecken-cve/your-ai-agent-should-be-a-guest-not-a-tenant/</guid>
<pubDate>Sun, 20 Sep 2026 04:28:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Why standing credentials are the quiet root cause behind this week&#039;s agent security headlines, and what zero standing privilege looks like in practice. On Thursday, researchers reported a zero-click remote code execution flaw in four major AI coding agents. The attack chain ran through the plugin supply chain, and reports put the number of... <a href="https://dev.to/anusha_mukka/your-ai-agent-should-be-a-guest-not-a-tenant-3bfc" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical 9.8 vulnerability in Unbound up to and including version 1.26.0]]></title>
<description><![CDATA[submitted by /u/anh0516 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4158259/sicherheitsluecken-cve/critical-98-vulnerability-in-unbound-up-to-and-including-version-1260/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4158259/sicherheitsluecken-cve/critical-98-vulnerability-in-unbound-up-to-and-including-version-1260/</guid>
<pubDate>Sun, 20 Sep 2026 02:33:12 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/anh0516 [link] [comments] <a href="https://www.reddit.com/r/linux/comments/1wl1thy/critical_98_vulnerability_in_unbound_up_to_and/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[xalgorix v4.6.78]]></title>
<description><![CDATA[Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4157984/sicherheitsluecken-cve/xalgorix-v4678/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157984/sicherheitsluecken-cve/xalgorix-v4678/</guid>
<pubDate>Sun, 20 Sep 2026 00:28:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript. <a href="https://kitploit.com/en/posts/github-xalgord-xalgorix-v4678" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento]]></title>
<description><![CDATA[StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento A storefront can pass every routine security check and still be running an exploitable template engine. That is the situation Adobe Commerce and Magento Open Source merchants faced in September 2026, when at...]]></description>
<link>https://tsecurity.de/de/4157858/sicherheitsluecken-cve/stylesmuggler-how-a-payment-failure-email-became-a-remote-code-execution-path-in-magento/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157858/sicherheitsluecken-cve/stylesmuggler-how-a-payment-failure-email-became-a-remote-code-execution-path-in-magento/</guid>
<pubDate>Sat, 19 Sep 2026 22:13:24 +0200</pubDate>
<content:encoded><![CDATA[<p>StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento A storefront can pass every routine security check and still be running an exploitable template engine. That is the situation Adobe Commerce and Magento Open Source merchants faced in September 2026, when attackers turned an ordinary transactional email into... <a href="https://dev.to/stark_zhuang_df5076f35c68/stylesmuggler-how-a-payment-failure-email-became-a-remote-code-execution-path-in-magento-2ho0" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New weekly CTF challenge is now live. Ranking is based on solve order.]]></title>
<description><![CDATA[submitted by /u/Electronic-Part6194 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4157558/reverse-engineering/new-weekly-ctf-challenge-is-now-live-ranking-is-based-on-solve-order/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157558/reverse-engineering/new-weekly-ctf-challenge-is-now-live-ranking-is-based-on-solve-order/</guid>
<pubDate>Sat, 19 Sep 2026 21:15:01 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Electronic-Part6194 [link] [comments] <a href="https://www.reddit.com/r/ReverseEngineering/comments/1wko5uy/new_weekly_ctf_challenge_is_now_live_ranking_is/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Poisoning the Context: Securing RAG Pipelines Against Knowledge Injection Attacks]]></title>
<description><![CDATA[Originally published on tamiz.pro. The Silent Vulnerability in Retrieval-Augmented Generation Retrieval-Augmented Generation (RAG) has become the de facto standard for grounding Large Language Models (LLMs) in proprietary data. By fetching relevant documents from a vector database and injecting t...]]></description>
<link>https://tsecurity.de/de/4157446/sicherheitsluecken-cve/poisoning-the-context-securing-rag-pipelines-against-knowledge-injection-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157446/sicherheitsluecken-cve/poisoning-the-context-securing-rag-pipelines-against-knowledge-injection-attacks/</guid>
<pubDate>Sat, 19 Sep 2026 20:29:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Originally published on tamiz.pro. The Silent Vulnerability in Retrieval-Augmented Generation Retrieval-Augmented Generation (RAG) has become the de facto standard for grounding Large Language Models (LLMs) in proprietary data. By fetching relevant documents from a vector database and injecting them into the model&#039;s context window, RAG mitigates... <a href="https://dev.to/tamizuddin/poisoning-the-context-securing-rag-pipelines-against-knowledge-injection-attacks-184h" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[vigolium v0.4.8]]></title>
<description><![CDATA[Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision Weiterlesen]]></description>
<link>https://tsecurity.de/de/4157332/sicherheitsluecken-cve/vigolium-v048/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157332/sicherheitsluecken-cve/vigolium-v048/</guid>
<pubDate>Sat, 19 Sep 2026 19:55:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision <a href="https://kitploit.com/en/posts/github-vigolium-vigolium-v048" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reversecore_MCP v3.0.4]]></title>
<description><![CDATA[A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4157331/sicherheitsluecken-cve/reversecoremcp-v304/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4157331/sicherheitsluecken-cve/reversecoremcp-v304/</guid>
<pubDate>Sat, 19 Sep 2026 19:55:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more. <a href="https://kitploit.com/en/posts/github-sjkim1127-reversecore_mcp-v304" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90605 | Totolink A3002MU Hh-B20211125.1046 boa /boafrm/formFilter ip6addr buffer overflow]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. This vulnerability is ...]]></description>
<link>https://tsecurity.de/de/4156802/sicherheitsluecken-cve/cve-2026-90605-totolink-a3002mu-hh-b202111251046-boa-boafrmformfilter-ip6addr-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156802/sicherheitsluecken-cve/cve-2026-90605-totolink-a3002mu-hh-b202111251046-boa-boafrmformfilter-ip6addr-buffer-overflow/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical was found in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. This vulnerability is handled as CVE-2026-90605. The attack can be... <a href="https://vuldb.com/vuln/403187" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90600 | itsourcecode Sales and Inventory System 1.0 /pages/inv_edit1.php ID sql injection]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. This vulnerability is documented as CVE-2026-90600. The attack ca...]]></description>
<link>https://tsecurity.de/de/4156801/sicherheitsluecken-cve/cve-2026-90600-itsourcecode-sales-and-inventory-system-10-pagesinvedit1php-id-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156801/sicherheitsluecken-cve/cve-2026-90600-itsourcecode-sales-and-inventory-system-10-pagesinvedit1php-id-sql-injection/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. This vulnerability is documented as CVE-2026-90600. The attack can be initiated remotely. Additionally, an exploit... <a href="https://vuldb.com/vuln/403182" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90596 | embedded-graphics up to 0.8.2 on 32-bit src/image/image_raw.rs new/bytes_per_row integer overflow (Issue 820)]]></title>
<description><![CDATA[A vulnerability was found in embedded-graphics up to 0.8.2 on 32-bit. It has been classified as critical. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. This vulnerability is tracked as CVE-2026-90596. The attack...]]></description>
<link>https://tsecurity.de/de/4156800/sicherheitsluecken-cve/cve-2026-90596-embedded-graphics-up-to-082-on-32-bit-srcimageimagerawrs-newbytesperrow-integer-overflow-issue-820/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156800/sicherheitsluecken-cve/cve-2026-90596-embedded-graphics-up-to-082-on-32-bit-srcimageimagerawrs-newbytesperrow-integer-overflow-issue-820/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in embedded-graphics up to 0.8.2 on 32-bit. It has been classified as critical. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. This vulnerability is tracked as CVE-2026-90596. The attack is possible to be carried out remotely. No exploit... <a href="https://vuldb.com/vuln/403178" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90595 | wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 OnlineController.java OnlineController.getOnlineInfo authorization (Issue 65)]]></title>
<description><![CDATA[A vulnerability was found in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 and classified as critical. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. This vulnera...]]></description>
<link>https://tsecurity.de/de/4156799/sicherheitsluecken-cve/cve-2026-90595-wxiaoqi-spring-cloud-platform-102230-onlinecontrollerjava-onlinecontrollergetonlineinfo-authorization-issue-65/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156799/sicherheitsluecken-cve/cve-2026-90595-wxiaoqi-spring-cloud-platform-102230-onlinecontrollerjava-onlinecontrollergetonlineinfo-authorization-issue-65/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0 and classified as critical. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. This vulnerability is identified as CVE-2026-90595. The attack... <a href="https://vuldb.com/vuln/403177" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90582 | evanchiu serverless-todo 1.0.3/2.0.0 API Todo Endpoint src/index.js saveTodos event.body resource consumption (Issue 10)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. This vulnerability is...]]></description>
<link>https://tsecurity.de/de/4156798/sicherheitsluecken-cve/cve-2026-90582-evanchiu-serverless-todo-103200-api-todo-endpoint-srcindexjs-savetodos-eventbody-resource-consumption-issue-10/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156798/sicherheitsluecken-cve/cve-2026-90582-evanchiu-serverless-todo-103200-api-todo-endpoint-srcindexjs-savetodos-eventbody-resource-consumption-issue-10/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. This vulnerability is documented as CVE-2026-90582. The attack can be... <a href="https://vuldb.com/vuln/403167" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90583 | kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf Query String Rendering app/sw.py index qs cross site scripting (Issue 854)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cros...]]></description>
<link>https://tsecurity.de/de/4156797/sicherheitsluecken-cve/cve-2026-90583-kagisearch-smallweb-up-to-0ecb9c48edbf98dc7e934b54fbac43869e64b4cf-query-string-rendering-appswpy-index-qs-cross-site-scripting-issue-854/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156797/sicherheitsluecken-cve/cve-2026-90583-kagisearch-smallweb-up-to-0ecb9c48edbf98dc7e934b54fbac43869e64b4cf-query-string-rendering-appswpy-index-qs-cross-site-scripting-issue-854/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. This vulnerability is reported as... <a href="https://vuldb.com/vuln/403168" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90577 | GPAC up to f1219cde MP4Box base_scenegraph.c gf_node_get_field heap-based overflow (Issue 3816)]]></title>
<description><![CDATA[A vulnerability has been found in GPAC up to f1219cde and classified as problematic. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. This vulnerabili...]]></description>
<link>https://tsecurity.de/de/4156796/sicherheitsluecken-cve/cve-2026-90577-gpac-up-to-f1219cde-mp4box-basescenegraphc-gfnodegetfield-heap-based-overflow-issue-3816/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156796/sicherheitsluecken-cve/cve-2026-90577-gpac-up-to-f1219cde-mp4box-basescenegraphc-gfnodegetfield-heap-based-overflow-issue-3816/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in GPAC up to f1219cde and classified as problematic. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. This vulnerability is identified as CVE-2026-90577. The attack is... <a href="https://vuldb.com/vuln/403162" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90601 | getzep graphiti up to 0.30.2 REST API main.py improper authentication (Issue 1716)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. This vulnerability is reported as CVE-2026-90601. The attack...]]></description>
<link>https://tsecurity.de/de/4156795/sicherheitsluecken-cve/cve-2026-90601-getzep-graphiti-up-to-0302-rest-api-mainpy-improper-authentication-issue-1716/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156795/sicherheitsluecken-cve/cve-2026-90601-getzep-graphiti-up-to-0302-rest-api-mainpy-improper-authentication-issue-1716/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. This vulnerability is reported as CVE-2026-90601. The attack can be launched remotely. No exploit exists. The... <a href="https://vuldb.com/vuln/403183" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-6710 | Apache HTTP Server mod_proxy_cluster alias cross site scripting (EUVD-2023-58930 / EDB-52010)]]></title>
<description><![CDATA[A vulnerability was found in Apache HTTP Server. It has been declared as problematic. Affected by this issue is some unknown functionality of the component mod_proxy_cluster. The manipulation of the argument alias results in cross site scripting. This vulnerability is reported as CVE-2023-6710. T...]]></description>
<link>https://tsecurity.de/de/4156794/sicherheitsluecken-cve/cve-2023-6710-apache-http-server-modproxycluster-alias-cross-site-scripting-euvd-2023-58930-edb-52010/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156794/sicherheitsluecken-cve/cve-2023-6710-apache-http-server-modproxycluster-alias-cross-site-scripting-euvd-2023-58930-edb-52010/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:56 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apache HTTP Server. It has been declared as problematic. Affected by this issue is some unknown functionality of the component mod_proxy_cluster. The manipulation of the argument alias results in cross site scripting. This vulnerability is reported as CVE-2023-6710. The attack can be launched remotely. Moreover, an... <a href="https://vuldb.com/vuln/247513" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63349: CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module]]></title>
<description><![CDATA[CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module Vulnerability ID: CVE-2026-63349 CVSS Score: 7.0 Published: 2026-09-18 CVE-2026-63349 is a critical privilege-dropping bypass vulnerability in the AnyIO asynchronous framework (versions 4.14.0 and 4.14.1) o...]]></description>
<link>https://tsecurity.de/de/4156782/sicherheitsluecken-cve/cve-2026-63349-cve-2026-63349-privilege-dropping-bypass-and-denial-of-service-in-anyio-subprocess-module/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156782/sicherheitsluecken-cve/cve-2026-63349-cve-2026-63349-privilege-dropping-bypass-and-denial-of-service-in-anyio-subprocess-module/</guid>
<pubDate>Sat, 19 Sep 2026 15:42:19 +0200</pubDate>
<content:encoded><![CDATA[<p>CVE-2026-63349: Privilege Dropping Bypass and Denial of Service in AnyIO Subprocess Module Vulnerability ID: CVE-2026-63349 CVSS Score: 7.0 Published: 2026-09-18 CVE-2026-63349 is a critical privilege-dropping bypass vulnerability in the AnyIO asynchronous framework (versions 4.14.0 and 4.14.1) on POSIX platforms. Due to a variable assignment... <a href="https://dev.to/cverports/cve-2026-63349-cve-2026-63349-privilege-dropping-bypass-and-denial-of-service-in-anyio-subprocess-2ojb" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90716 | marcobambini Gravity up to 0.9.7 Number Parser gravity_parser.c parse_number_expression out-of-bounds (Issue 446)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bounds read. This vulnerability is ...]]></description>
<link>https://tsecurity.de/de/4156698/sicherheitsluecken-cve/cve-2026-90716-marcobambini-gravity-up-to-097-number-parser-gravityparserc-parsenumberexpression-out-of-bounds-issue-446/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156698/sicherheitsluecken-cve/cve-2026-90716-marcobambini-gravity-up-to-097-number-parser-gravityparserc-parsenumberexpression-out-of-bounds-issue-446/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bounds read. This vulnerability is cataloged as CVE-2026-90716. It is possible to... <a href="https://vuldb.com/vuln/403270" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-78299 | Eclipse Embedded CDT up to 5.x/6.7 path traversal]]></title>
<description><![CDATA[A vulnerability has been found in Eclipse Embedded CDT up to 5.x/6.7 and classified as critical. This issue affects some unknown processing. Performing a manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-78299. It is possible to initiate the attack remotely. Ther...]]></description>
<link>https://tsecurity.de/de/4156697/sicherheitsluecken-cve/cve-2026-78299-eclipse-embedded-cdt-up-to-5x67-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156697/sicherheitsluecken-cve/cve-2026-78299-eclipse-embedded-cdt-up-to-5x67-path-traversal/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Eclipse Embedded CDT up to 5.x/6.7 and classified as critical. This issue affects some unknown processing. Performing a manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-78299. It is possible to initiate the attack remotely. There is no exploit available. The affected component... <a href="https://vuldb.com/vuln/403540" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9812 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Playbooks authorization]]></title>
<description><![CDATA[A vulnerability has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Playbooks. This manipulation causes authorization bypass. This vulnerability is registered as CVE-2026-9812. Remote...]]></description>
<link>https://tsecurity.de/de/4156696/sicherheitsluecken-cve/cve-2026-9812-mattermost-up-to-101122117711841190-playbooks-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156696/sicherheitsluecken-cve/cve-2026-9812-mattermost-up-to-101122117711841190-playbooks-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Playbooks. This manipulation causes authorization bypass. This vulnerability is registered as CVE-2026-9812. Remote exploitation of the attack is possible. No exploit... <a href="https://vuldb.com/vuln/403526" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13417 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Boards fields.properties unusual condition]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. This issue affects some unknown processing of the component Boards. The manipulation of the argument fields.properties leads to improper check for unusual conditions. This vulnerability ...]]></description>
<link>https://tsecurity.de/de/4156695/sicherheitsluecken-cve/cve-2026-13417-mattermost-up-to-101122117711841190-boards-fieldsproperties-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156695/sicherheitsluecken-cve/cve-2026-13417-mattermost-up-to-101122117711841190-boards-fieldsproperties-unusual-condition/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. This issue affects some unknown processing of the component Boards. The manipulation of the argument fields.properties leads to improper check for unusual conditions. This vulnerability is uniquely identified as CVE-2026-13417. The attack... <a href="https://vuldb.com/vuln/403518" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10556 | Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0 Calendar Plugin unusual condition]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. The impacted element is an unknown function of the component Calendar Plugin. Performing a manipulation results in improper check for unusual conditions. This vulnerability is c...]]></description>
<link>https://tsecurity.de/de/4156694/sicherheitsluecken-cve/cve-2026-10556-mattermost-up-to-101122117711841190-calendar-plugin-unusual-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156694/sicherheitsluecken-cve/cve-2026-10556-mattermost-up-to-101122117711841190-calendar-plugin-unusual-condition/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0. The impacted element is an unknown function of the component Calendar Plugin. Performing a manipulation results in improper check for unusual conditions. This vulnerability is cataloged as CVE-2026-10556. It is possible to... <a href="https://vuldb.com/vuln/403510" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90705 | D-Link DWR-M921 1.1.52 Boa Dispatch Table /boafrm/formsysCmd os command injection]]></title>
<description><![CDATA[A vulnerability was found in D-Link DWR-M921 1.1.52 and classified as critical. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. This vulnerability is handled ...]]></description>
<link>https://tsecurity.de/de/4156693/sicherheitsluecken-cve/cve-2026-90705-d-link-dwr-m921-1152-boa-dispatch-table-boafrmformsyscmd-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156693/sicherheitsluecken-cve/cve-2026-90705-d-link-dwr-m921-1152-boa-dispatch-table-boafrmformsyscmd-os-command-injection/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in D-Link DWR-M921 1.1.52 and classified as critical. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. This vulnerability is handled as CVE-2026-90705. The attack can be executed... <a href="https://vuldb.com/vuln/403247" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90710 | taisan tarzan-cms 1.0.0 Theme Download Function ThemeService.java openConnection httpUrl server-side request forgery (IK768M)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl ...]]></description>
<link>https://tsecurity.de/de/4156692/sicherheitsluecken-cve/cve-2026-90710-taisan-tarzan-cms-100-theme-download-function-themeservicejava-openconnection-httpurl-server-side-request-forgery-ik768m/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156692/sicherheitsluecken-cve/cve-2026-90710-taisan-tarzan-cms-100-theme-download-function-themeservicejava-openconnection-httpurl-server-side-request-forgery-ik768m/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery. The... <a href="https://vuldb.com/vuln/403265" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90695 | SourceCodester Inventory Management System 1.0 Vendor Management /api/vendors_handler.php cross site scripting]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting...]]></description>
<link>https://tsecurity.de/de/4156691/sicherheitsluecken-cve/cve-2026-90695-sourcecodester-inventory-management-system-10-vendor-management-apivendorshandlerphp-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156691/sicherheitsluecken-cve/cve-2026-90695-sourcecodester-inventory-management-system-10-vendor-management-apivendorshandlerphp-cross-site-scripting/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. This vulnerability is reported as CVE-2026-90695.... <a href="https://vuldb.com/vuln/403228" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90700 | itsourcecode Sales and Inventory System 1.0 /pages/pro_edit1.php prodcode sql injection]]></title>
<description><![CDATA[A vulnerability was found in itsourcecode Sales and Inventory System 1.0 and classified as critical. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. This vulnerability is uniquely identified as CVE-2026-90700. Th...]]></description>
<link>https://tsecurity.de/de/4156690/sicherheitsluecken-cve/cve-2026-90700-itsourcecode-sales-and-inventory-system-10-pagesproedit1php-prodcode-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156690/sicherheitsluecken-cve/cve-2026-90700-itsourcecode-sales-and-inventory-system-10-pagesproedit1php-prodcode-sql-injection/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in itsourcecode Sales and Inventory System 1.0 and classified as critical. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. This vulnerability is uniquely identified as CVE-2026-90700. The attack can be launched remotely. Moreover, an... <a href="https://vuldb.com/vuln/403233" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90690 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection (Issue 224)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument... ...]]></description>
<link>https://tsecurity.de/de/4156689/sicherheitsluecken-cve/cve-2026-90690-0x4m4-hexstrike-ai-up-to-d689933ff579d839c676c82b231f8e98326c5f04-api-tools-endpoint-hexstrikeserverpy-subprocesspopen-os-command-injection-issue-224/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156689/sicherheitsluecken-cve/cve-2026-90690-0x4m4-hexstrike-ai-up-to-d689933ff579d839c676c82b231f8e98326c5f04-api-tools-endpoint-hexstrikeserverpy-subprocesspopen-os-command-injection-issue-224/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as critical has been discovered in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument... <a href="https://vuldb.com/vuln/403223" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-78030 | DBI up to 1.652 require dbm_type/dbm_mldbm code injection (EUVD-2026-83584)]]></title>
<description><![CDATA[A vulnerability was found in DBI up to 1.652. It has been rated as critical. This issue affects the function require. The manipulation of the argument dbm_type/dbm_mldbm leads to code injection. This vulnerability is traded as CVE-2026-78030. It is possible to initiate the attack remotely. There ...]]></description>
<link>https://tsecurity.de/de/4156688/sicherheitsluecken-cve/cve-2026-78030-dbi-up-to-1652-require-dbmtypedbmmldbm-code-injection-euvd-2026-83584/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156688/sicherheitsluecken-cve/cve-2026-78030-dbi-up-to-1652-require-dbmtypedbmmldbm-code-injection-euvd-2026-83584/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in DBI up to 1.652. It has been rated as critical. This issue affects the function require. The manipulation of the argument dbm_type/dbm_mldbm leads to code injection. This vulnerability is traded as CVE-2026-78030. It is possible to initiate the attack remotely. There is no exploit available. Upgrading the affected... <a href="https://vuldb.com/vuln/407940" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9858 | wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress AJAX handlers woocommerce-partial-shipment.php order_id improper authorization (EUVD-2026-83570)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress. Affected by this vulnerability is an unknown functionality of the file woocommerce-partial-shipment.php of the component AJAX handlers. Executing a manipulatio...]]></description>
<link>https://tsecurity.de/de/4156687/sicherheitsluecken-cve/cve-2026-9858-wpexpertshub-partial-shipment-for-woocommerce-plugin-up-to-34-on-wordpress-ajax-handlers-woocommerce-partial-shipmentphp-orderid-improper-authorization-euvd-2026-83570/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156687/sicherheitsluecken-cve/cve-2026-9858-wpexpertshub-partial-shipment-for-woocommerce-plugin-up-to-34-on-wordpress-ajax-handlers-woocommerce-partial-shipmentphp-orderid-improper-authorization-euvd-2026-83570/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in wpexpertshub Partial Shipment for WooCommerce Plugin up to 3.4 on WordPress. Affected by this vulnerability is an unknown functionality of the file woocommerce-partial-shipment.php of the component AJAX handlers. Executing a manipulation of the argument order_id can lead to improper... <a href="https://vuldb.com/vuln/407903" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93742 | Totolink A3002MU Hh-B20211125.1046 /boafrm/formWsc localPin command injection (EUVD-2026-83583)]]></title>
<description><![CDATA[A vulnerability marked as very critical has been reported in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. This vulnerability is handled as CVE-2026-93742. The at...]]></description>
<link>https://tsecurity.de/de/4156686/sicherheitsluecken-cve/cve-2026-93742-totolink-a3002mu-hh-b202111251046-boafrmformwsc-localpin-command-injection-euvd-2026-83583/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156686/sicherheitsluecken-cve/cve-2026-93742-totolink-a3002mu-hh-b202111251046-boafrmformwsc-localpin-command-injection-euvd-2026-83583/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as very critical has been reported in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. This vulnerability is handled as CVE-2026-93742. The attack can be initiated remotely. Additionally, an... <a href="https://vuldb.com/vuln/407552" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9613 | Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress authorization (EUVD-2026-83569)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress. This issue affects some unknown processing. Such manipulation leads to authorization bypass. This vulnerability is documented as CVE-2026-9613. The attack can be execute...]]></description>
<link>https://tsecurity.de/de/4156685/sicherheitsluecken-cve/cve-2026-9613-datalogics-ecommerce-delivery-plugin-up-to-2665-on-wordpress-authorization-euvd-2026-83569/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156685/sicherheitsluecken-cve/cve-2026-9613-datalogics-ecommerce-delivery-plugin-up-to-2665-on-wordpress-authorization-euvd-2026-83569/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in Datalogics Ecommerce Delivery Plugin up to 2.6.65 on WordPress. This issue affects some unknown processing. Such manipulation leads to authorization bypass. This vulnerability is documented as CVE-2026-9613. The attack can be executed remotely. There is not any exploit available. <a href="https://vuldb.com/vuln/407907" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-1256 | ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress cross site scripting (EUVD-2026-83567)]]></title>
<description><![CDATA[A vulnerability was found in ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress. It has been rated as problematic. This impacts an unknown function. This manipulation causes cross site scripting. This vulnerability is handled as CVE-2026-1256. The attack can be initiated remotely. There is ...]]></description>
<link>https://tsecurity.de/de/4156684/sicherheitsluecken-cve/cve-2026-1256-ysinnovations-ys-leadgen-plugin-up-to-214-on-wordpress-cross-site-scripting-euvd-2026-83567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156684/sicherheitsluecken-cve/cve-2026-1256-ysinnovations-ys-leadgen-plugin-up-to-214-on-wordpress-cross-site-scripting-euvd-2026-83567/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in ysinnovations YS LeadGen Plugin up to 2.1.4 on WordPress. It has been rated as problematic. This impacts an unknown function. This manipulation causes cross site scripting. This vulnerability is handled as CVE-2026-1256. The attack can be initiated remotely. There is not any exploit available. <a href="https://vuldb.com/vuln/407912" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-76579 | LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress ESI esi cross site scripting (EUVD-2026-83568)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress. Affected by this issue is some unknown functionality of the component ESI. The manipulation of the argument esi leads to cross site scripting. This vulnerability is li...]]></description>
<link>https://tsecurity.de/de/4156683/sicherheitsluecken-cve/cve-2026-76579-litespeed-technologies-litespeed-cache-plugin-up-to-79-on-wordpress-esi-esi-cross-site-scripting-euvd-2026-83568/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156683/sicherheitsluecken-cve/cve-2026-76579-litespeed-technologies-litespeed-cache-plugin-up-to-79-on-wordpress-esi-esi-cross-site-scripting-euvd-2026-83568/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in LiteSpeed Technologies LiteSpeed Cache Plugin up to 7.9 on WordPress. Affected by this issue is some unknown functionality of the component ESI. The manipulation of the argument esi leads to cross site scripting. This vulnerability is listed as CVE-2026-76579. The attack may be initiated... <a href="https://vuldb.com/vuln/407904" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9289 | WordLift Plugin up to 3.54.10 on WordPress JSON-LD REST API /wordlift/v1/jsonld get_post access control (EUVD-2026-83565)]]></title>
<description><![CDATA[A vulnerability was found in WordLift Plugin up to 3.54.10 on WordPress. It has been classified as problematic. The impacted element is the function get_post of the file /wordlift/v1/jsonld of the component JSON-LD REST API. The manipulation leads to improper access controls. This vulnerability i...]]></description>
<link>https://tsecurity.de/de/4156682/sicherheitsluecken-cve/cve-2026-9289-wordlift-plugin-up-to-35410-on-wordpress-json-ld-rest-api-wordliftv1jsonld-getpost-access-control-euvd-2026-83565/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156682/sicherheitsluecken-cve/cve-2026-9289-wordlift-plugin-up-to-35410-on-wordpress-json-ld-rest-api-wordliftv1jsonld-getpost-access-control-euvd-2026-83565/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in WordLift Plugin up to 3.54.10 on WordPress. It has been classified as problematic. The impacted element is the function get_post of the file /wordlift/v1/jsonld of the component JSON-LD REST API. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2026-9289. It is possible to... <a href="https://vuldb.com/vuln/407910" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9766 | Empik for Woocommerce Plugin up to 1.5.1 on WordPress authorization (EUVD-2026-83566)]]></title>
<description><![CDATA[A vulnerability has been found in Empik for Woocommerce Plugin up to 1.5.1 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument _empik_logistic_klass/_empik_product_state/_empik_product_state_all_variants results in authorization b...]]></description>
<link>https://tsecurity.de/de/4156681/sicherheitsluecken-cve/cve-2026-9766-empik-for-woocommerce-plugin-up-to-151-on-wordpress-authorization-euvd-2026-83566/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156681/sicherheitsluecken-cve/cve-2026-9766-empik-for-woocommerce-plugin-up-to-151-on-wordpress-authorization-euvd-2026-83566/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Empik for Woocommerce Plugin up to 1.5.1 on WordPress and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument _empik_logistic_klass/_empik_product_state/_empik_product_state_all_variants results in authorization bypass. This vulnerability is reported as... <a href="https://vuldb.com/vuln/407908" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-1255 | YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress ysleadgen_get_captured_data information disclosure (EUVD-2026-83564)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress. This vulnerability affects the function ysleadgen_get_captured_data. This manipulation causes information disclosure. This vulnerability is registered as CVE-2026-125...]]></description>
<link>https://tsecurity.de/de/4156680/sicherheitsluecken-cve/cve-2026-1255-ys-innovations-ys-leadgen-plugin-up-to-214-on-wordpress-ysleadgengetcaptureddata-information-disclosure-euvd-2026-83564/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156680/sicherheitsluecken-cve/cve-2026-1255-ys-innovations-ys-leadgen-plugin-up-to-214-on-wordpress-ysleadgengetcaptureddata-information-disclosure-euvd-2026-83564/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in YS Innovations YS LeadGen Plugin up to 2.1.4 on WordPress. This vulnerability affects the function ysleadgen_get_captured_data. This manipulation causes information disclosure. This vulnerability is registered as CVE-2026-1255. Remote exploitation of the attack is possible. No... <a href="https://vuldb.com/vuln/407906" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8354 | celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress pop_tag cross site scripting (EUVD-2026-83562)]]></title>
<description><![CDATA[A vulnerability was found in celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress. It has been declared as problematic. This affects an unknown function. The manipulation of the argument pop_tag results in cross site scripting. This vulnerability is known as CVE-2026-8354. It is pos...]]></description>
<link>https://tsecurity.de/de/4156679/sicherheitsluecken-cve/cve-2026-8354-celomitan-gum-addon-for-elementor-plugin-up-to-1315-on-wordpress-poptag-cross-site-scripting-euvd-2026-83562/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156679/sicherheitsluecken-cve/cve-2026-8354-celomitan-gum-addon-for-elementor-plugin-up-to-1315-on-wordpress-poptag-cross-site-scripting-euvd-2026-83562/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in celomitan Gum Addon for Elementor Plugin up to 1.3.15 on WordPress. It has been declared as problematic. This affects an unknown function. The manipulation of the argument pop_tag results in cross site scripting. This vulnerability is known as CVE-2026-8354. It is possible to launch the attack remotely. No exploit is... <a href="https://vuldb.com/vuln/407911" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18346 | TikTok Plugin up to 1.4.1 on WordPress authorization (EUVD-2026-83563)]]></title>
<description><![CDATA[A vulnerability was found in TikTok Plugin up to 1.4.1 on WordPress and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to authorization bypass. This vulnerability appears as CVE-2026-18346. The attack may be performed from remote. There is n...]]></description>
<link>https://tsecurity.de/de/4156678/sicherheitsluecken-cve/cve-2026-18346-tiktok-plugin-up-to-141-on-wordpress-authorization-euvd-2026-83563/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156678/sicherheitsluecken-cve/cve-2026-18346-tiktok-plugin-up-to-141-on-wordpress-authorization-euvd-2026-83563/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in TikTok Plugin up to 1.4.1 on WordPress and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to authorization bypass. This vulnerability appears as CVE-2026-18346. The attack may be performed from remote. There is no available exploit. <a href="https://vuldb.com/vuln/407909" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5410 | davidanderson Redux Framework Plugin up to 4.5.13 on WordPress Spinner class-redux-spinner.php user_meta_save spinner cross site scripting (EUVD-2026-83561)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in davidanderson Redux Framework Plugin up to 4.5.13 on WordPress. This affects the function user_meta_save of the file class-redux-spinner.php of the component Spinner. The manipulation of the argument spinner results in cross site scripting. T...]]></description>
<link>https://tsecurity.de/de/4156677/sicherheitsluecken-cve/cve-2026-5410-davidanderson-redux-framework-plugin-up-to-4513-on-wordpress-spinner-class-redux-spinnerphp-usermetasave-spinner-cross-site-scripting-euvd-2026-83561/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156677/sicherheitsluecken-cve/cve-2026-5410-davidanderson-redux-framework-plugin-up-to-4513-on-wordpress-spinner-class-redux-spinnerphp-usermetasave-spinner-cross-site-scripting-euvd-2026-83561/</guid>
<pubDate>Sat, 19 Sep 2026 14:16:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in davidanderson Redux Framework Plugin up to 4.5.13 on WordPress. This affects the function user_meta_save of the file class-redux-spinner.php of the component Spinner. The manipulation of the argument spinner results in cross site scripting. This vulnerability is cataloged as CVE-2026-5410. The... <a href="https://vuldb.com/vuln/407905" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-19 14h : 3 posts]]></title>
<description><![CDATA[3 posts published in the last hour 11:31SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE 11:31Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening 11:31Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws The post IT Security...]]></description>
<link>https://tsecurity.de/de/4156658/sicherheitsluecken-cve/it-security-news-hourly-summary-2026-09-19-14h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156658/sicherheitsluecken-cve/it-security-news-hourly-summary-2026-09-19-14h-3-posts/</guid>
<pubDate>Sat, 19 Sep 2026 14:08:51 +0200</pubDate>
<content:encoded><![CDATA[<p>3 posts published in the last hour 11:31SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE 11:31Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening 11:31Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws The post IT Security News Hourly Summary 2026-09-19 14h : 3 posts... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-19-14h-3-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE]]></title>
<description><![CDATA[SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring...]]></description>
<link>https://tsecurity.de/de/4156655/sicherheitsluecken-cve/solarwinds-patches-arm-hard-coded-key-flaw-enabling-unauthenticated-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156655/sicherheitsluecken-cve/solarwinds-patches-arm-hard-coded-key-flaw-enabling-unauthenticated-rce/</guid>
<pubDate>Sat, 19 Sep 2026 14:04:55 +0200</pubDate>
<content:encoded><![CDATA[<p>SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access... <a href="https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-91147 | Red Hat Enterprise Linux/OpenShift Dev Spaces cockpit-ws denial of service (Nessus ID 348262)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Red Hat Enterprise Linux and OpenShift Dev Spaces. This affects an unknown part of the component cockpit-ws. The manipulation results in denial of service. This vulnerability is known as CVE-2026-91147. It is possible to launch the a...]]></description>
<link>https://tsecurity.de/de/4156633/sicherheitsluecken-cve/cve-2026-91147-red-hat-enterprise-linuxopenshift-dev-spaces-cockpit-ws-denial-of-service-nessus-id-348262/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156633/sicherheitsluecken-cve/cve-2026-91147-red-hat-enterprise-linuxopenshift-dev-spaces-cockpit-ws-denial-of-service-nessus-id-348262/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in Red Hat Enterprise Linux and OpenShift Dev Spaces. This affects an unknown part of the component cockpit-ws. The manipulation results in denial of service. This vulnerability is known as CVE-2026-91147. It is possible to launch the attack remotely. No exploit is available. <a href="https://vuldb.com/vuln/407641" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81000 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Tun tun_get_user align allocation of resources (Nessus ID 348261)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. This affects the function tun_get_user of the component Tun. The manipulation of the argument align leads to allocation of resources. This vulnerability is listed as CVE-2026-81000. The att...]]></description>
<link>https://tsecurity.de/de/4156632/sicherheitsluecken-cve/cve-2026-81000-linux-kernel-up-to-61210861849723-tun-tungetuser-align-allocation-of-resources-nessus-id-348261/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156632/sicherheitsluecken-cve/cve-2026-81000-linux-kernel-up-to-61210861849723-tun-tungetuser-align-allocation-of-resources-nessus-id-348261/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. This affects the function tun_get_user of the component Tun. The manipulation of the argument align leads to allocation of resources. This vulnerability is listed as CVE-2026-81000. The attack may be initiated remotely. There is no available... <a href="https://vuldb.com/vuln/402774" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-88859 | Red Hat Enterprise Linux Trusted JavaScript cross site scripting (Nessus ID 348257)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Red Hat Enterprise Linux. This affects an unknown part of the component Trusted JavaScript Handler. This manipulation causes cross site scripting. The identification of this vulnerability is CVE-2026-88859. It is possible to initiate ...]]></description>
<link>https://tsecurity.de/de/4156631/sicherheitsluecken-cve/cve-2026-88859-red-hat-enterprise-linux-trusted-javascript-cross-site-scripting-nessus-id-348257/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156631/sicherheitsluecken-cve/cve-2026-88859-red-hat-enterprise-linux-trusted-javascript-cross-site-scripting-nessus-id-348257/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Red Hat Enterprise Linux. This affects an unknown part of the component Trusted JavaScript Handler. This manipulation causes cross site scripting. The identification of this vulnerability is CVE-2026-88859. It is possible to initiate the attack remotely. There is no exploit available. <a href="https://vuldb.com/vuln/402020" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-80844 | Linux Kernel up to 7.2.2 xfrm ipv6_rearrange_rthdr out-of-bounds (Nessus ID 348261)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.2. Affected is the function ipv6_rearrange_rthdr of the component xfrm. Executing a manipulation can lead to out-of-bounds read. This vulnerability is registered as CVE-2026-80844. It is possible to launch ...]]></description>
<link>https://tsecurity.de/de/4156630/sicherheitsluecken-cve/cve-2026-80844-linux-kernel-up-to-722-xfrm-ipv6rearrangerthdr-out-of-bounds-nessus-id-348261/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156630/sicherheitsluecken-cve/cve-2026-80844-linux-kernel-up-to-722-xfrm-ipv6rearrangerthdr-out-of-bounds-nessus-id-348261/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.2.2. Affected is the function ipv6_rearrange_rthdr of the component xfrm. Executing a manipulation can lead to out-of-bounds read. This vulnerability is registered as CVE-2026-80844. It is possible to launch the attack remotely. No exploit is available. It is... <a href="https://vuldb.com/vuln/398981" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-43818 | lxml up to 4.6.4 lxml.html cross site scripting (GHSA-55x5-fj6c-h6m8 / Nessus ID 348247)]]></title>
<description><![CDATA[A vulnerability was found in lxml up to 4.6.4. It has been rated as problematic. This affects an unknown part of the file lxml.html. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2021-43818. It is possible to initiate the attack remotely. There is no exploit ...]]></description>
<link>https://tsecurity.de/de/4156629/sicherheitsluecken-cve/cve-2021-43818-lxml-up-to-464-lxmlhtml-cross-site-scripting-ghsa-55x5-fj6c-h6m8-nessus-id-348247/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156629/sicherheitsluecken-cve/cve-2021-43818-lxml-up-to-464-lxmlhtml-cross-site-scripting-ghsa-55x5-fj6c-h6m8-nessus-id-348247/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in lxml up to 4.6.4. It has been rated as problematic. This affects an unknown part of the file lxml.html. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2021-43818. It is possible to initiate the attack remotely. There is no exploit available. Upgrading the affected component is... <a href="https://vuldb.com/vuln/188070" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90496 | Fengoffice Feng Office up to 3.11.13.11 Reorder Handlers MoreController.class.php update_system_module_order/update_dimension_order modules/dims sql injection]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulat...]]></description>
<link>https://tsecurity.de/de/4156628/sicherheitsluecken-cve/cve-2026-90496-fengoffice-feng-office-up-to-3111311-reorder-handlers-morecontrollerclassphp-updatesystemmoduleorderupdatedimensionorder-modulesdims-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156628/sicherheitsluecken-cve/cve-2026-90496-fengoffice-feng-office-up-to-3111311-reorder-handlers-morecontrollerclassphp-updatesystemmoduleorderupdatedimensionorder-modulesdims-sql-injection/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql... <a href="https://vuldb.com/vuln/403084" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90506 | vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46 Save Account Job race condition]]></title>
<description><![CDATA[A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. It has been classified as problematic. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. This vulnerability only affects products that ar...]]></description>
<link>https://tsecurity.de/de/4156627/sicherheitsluecken-cve/cve-2026-90506-vvbbnn00-warp-clash-api-up-to-c7bf2360073959861219b422e51ae86411051b46-save-account-job-race-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156627/sicherheitsluecken-cve/cve-2026-90506-vvbbnn00-warp-clash-api-up-to-c7bf2360073959861219b422e51ae86411051b46-save-account-job-race-condition/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. It has been classified as problematic. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. This vulnerability only affects products that are no longer supported by the maintainer. This... <a href="https://vuldb.com/vuln/403094" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90511 | GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea listSplit Interface BooksServlet.java column sql injection]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument col...]]></description>
<link>https://tsecurity.de/de/4156626/sicherheitsluecken-cve/cve-2026-90511-gongshengyue-onlinebooks-up-to-dfc5eacc08d3b0396c266049548618f6fb9587ea-listsplit-interface-booksservletjava-column-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156626/sicherheitsluecken-cve/cve-2026-90511-gongshengyue-onlinebooks-up-to-dfc5eacc08d3b0396c266049548618f6fb9587ea-listsplit-interface-booksservletjava-column-sql-injection/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. This vulnerability was... <a href="https://vuldb.com/vuln/403099" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90501 | lenve vhr 1.0-SNAPSHOT HrMapper.xml HrInfoController.updateHr Password privileges management]]></title>
<description><![CDATA[A vulnerability classified as critical was found in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. This vulnerability is listed as CVE-2026-90501. The at...]]></description>
<link>https://tsecurity.de/de/4156625/sicherheitsluecken-cve/cve-2026-90501-lenve-vhr-10-snapshot-hrmapperxml-hrinfocontrollerupdatehr-password-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156625/sicherheitsluecken-cve/cve-2026-90501-lenve-vhr-10-snapshot-hrmapperxml-hrinfocontrollerupdatehr-password-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. This vulnerability is listed as CVE-2026-90501. The attack may be performed from remote. In addition, an... <a href="https://vuldb.com/vuln/403089" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90508 | Chengdu Qilu Technology Ludashi 6.1026.4715.714 Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorization]]></title>
<description><![CDATA[A vulnerability was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. It has been rated as problematic. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in m...]]></description>
<link>https://tsecurity.de/de/4156624/sicherheitsluecken-cve/cve-2026-90508-chengdu-qilu-technology-ludashi-610264715714-message-dispatch-protectfilter64sys-messagenotifycallback-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156624/sicherheitsluecken-cve/cve-2026-90508-chengdu-qilu-technology-ludashi-610264715714-message-dispatch-protectfilter64sys-messagenotifycallback-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. It has been rated as problematic. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. This vulnerability is known as... <a href="https://vuldb.com/vuln/403096" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90514 | SourceCodester School Registration and Fee System 1.0 save_stud.php Status sql injection]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. This vulnerability is referenced as CVE-202...]]></description>
<link>https://tsecurity.de/de/4156623/sicherheitsluecken-cve/cve-2026-90514-sourcecodester-school-registration-and-fee-system-10-savestudphp-status-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156623/sicherheitsluecken-cve/cve-2026-90514-sourcecodester-school-registration-and-fee-system-10-savestudphp-status-sql-injection/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. This vulnerability is referenced as CVE-2026-90514. It is possible to launch the attack... <a href="https://vuldb.com/vuln/403101" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90503 | Chengdu Qilu Technology Ludashi 6.1026.4715.714 ComputerZ_x64.sys sub_11008 PhysicalAddress information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. This vu...]]></description>
<link>https://tsecurity.de/de/4156622/sicherheitsluecken-cve/cve-2026-90503-chengdu-qilu-technology-ludashi-610264715714-computerzx64sys-sub11008-physicaladdress-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156622/sicherheitsluecken-cve/cve-2026-90503-chengdu-qilu-technology-ludashi-610264715714-computerzx64sys-sub11008-physicaladdress-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. This vulnerability is registered as CVE-2026-90503. The... <a href="https://vuldb.com/vuln/403091" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90498 | lenve vhr 1.0-SNAPSHOT vhr.sql default credentials]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. This vulnerability is referenced as CVE-2026-90498. Remote exploitation of the attack is ...]]></description>
<link>https://tsecurity.de/de/4156621/sicherheitsluecken-cve/cve-2026-90498-lenve-vhr-10-snapshot-vhrsql-default-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156621/sicherheitsluecken-cve/cve-2026-90498-lenve-vhr-10-snapshot-vhrsql-default-credentials/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. This vulnerability is referenced as CVE-2026-90498. Remote exploitation of the attack is possible. Furthermore, an exploit is available. The... <a href="https://vuldb.com/vuln/403086" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-29811 | CyberPanel up to 2.4.3 comparison using wrong factors]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in CyberPanel up to 2.4.3. Affected is an unknown function. Executing a manipulation can lead to comparison using wrong factors. This vulnerability is handled as CVE-2026-29811. The attack can be executed remotely. There is not any exploit ava...]]></description>
<link>https://tsecurity.de/de/4156620/sicherheitsluecken-cve/cve-2026-29811-cyberpanel-up-to-243-comparison-using-wrong-factors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156620/sicherheitsluecken-cve/cve-2026-29811-cyberpanel-up-to-243-comparison-using-wrong-factors/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in CyberPanel up to 2.4.3. Affected is an unknown function. Executing a manipulation can lead to comparison using wrong factors. This vulnerability is handled as CVE-2026-29811. The attack can be executed remotely. There is not any exploit available. The affected component should be upgraded. <a href="https://vuldb.com/vuln/403337" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90573 | GPAC up to f1219cde MP4Box scenegraph/vrml_tools.c gf_sg_mfurl_del null pointer dereference (Issue 3814)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. This vulnerability is uniquely identified as CVE-2...]]></description>
<link>https://tsecurity.de/de/4156619/sicherheitsluecken-cve/cve-2026-90573-gpac-up-to-f1219cde-mp4box-scenegraphvrmltoolsc-gfsgmfurldel-null-pointer-dereference-issue-3814/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156619/sicherheitsluecken-cve/cve-2026-90573-gpac-up-to-f1219cde-mp4box-scenegraphvrmltoolsc-gfsgmfurldel-null-pointer-dereference-issue-3814/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. This vulnerability is uniquely identified as CVE-2026-90573. Local access is required to approach this... <a href="https://vuldb.com/vuln/403158" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90575 | PHPGurukul Small CRM 4.0 Login Success /crm/login.php unserialize geopluginURL deserialization]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. The identification of t...]]></description>
<link>https://tsecurity.de/de/4156618/sicherheitsluecken-cve/cve-2026-90575-phpgurukul-small-crm-40-login-success-crmloginphp-unserialize-geopluginurl-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156618/sicherheitsluecken-cve/cve-2026-90575-phpgurukul-small-crm-40-login-success-crmloginphp-unserialize-geopluginurl-deserialization/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. The identification of this vulnerability is CVE-2026-90575. It is possible... <a href="https://vuldb.com/vuln/403160" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90619 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 Execute Endpoint hexstrike_server.py code/script os command injection (Issue 222)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection...]]></description>
<link>https://tsecurity.de/de/4156617/sicherheitsluecken-cve/cve-2026-90619-0x4m4-hexstrike-ai-up-to-d689933ff579d839c676c82b231f8e98326c5f04-execute-endpoint-hexstrikeserverpy-codescript-os-command-injection-issue-222/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156617/sicherheitsluecken-cve/cve-2026-90619-0x4m4-hexstrike-ai-up-to-d689933ff579d839c676c82b231f8e98326c5f04-execute-endpoint-hexstrikeserverpy-codescript-os-command-injection-issue-222/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. This vulnerability is traded as CVE-2026-90619. It... <a href="https://vuldb.com/vuln/403200" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90613 | GPAC up to f1219cde MP4Box isomedia/stbl_read.c stbl_GetSampleInfos assertion (Issue 3822)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. This vulnerability is cataloged as C...]]></description>
<link>https://tsecurity.de/de/4156616/sicherheitsluecken-cve/cve-2026-90613-gpac-up-to-f1219cde-mp4box-isomediastblreadc-stblgetsampleinfos-assertion-issue-3822/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156616/sicherheitsluecken-cve/cve-2026-90613-gpac-up-to-f1219cde-mp4box-isomediastblreadc-stblgetsampleinfos-assertion-issue-3822/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. This vulnerability is cataloged as CVE-2026-90613. The attack must be initiated from a... <a href="https://vuldb.com/vuln/403195" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90608 | Totolink A3002MU Hh-B20211125.1046 boa /boafrm/formPortFw service_type buffer overflow]]></title>
<description><![CDATA[A vulnerability has been found in Totolink A3002MU Hh-B20211125.1046 and classified as very critical. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. The identification of t...]]></description>
<link>https://tsecurity.de/de/4156615/sicherheitsluecken-cve/cve-2026-90608-totolink-a3002mu-hh-b202111251046-boa-boafrmformportfw-servicetype-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156615/sicherheitsluecken-cve/cve-2026-90608-totolink-a3002mu-hh-b202111251046-boa-boafrmformportfw-servicetype-buffer-overflow/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Totolink A3002MU Hh-B20211125.1046 and classified as very critical. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. The identification of this vulnerability is CVE-2026-90608. It is possible... <a href="https://vuldb.com/vuln/403190" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90598 | jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2 UserController.java UserController.updateUser userid authorization (Issue 172)]]></title>
<description><![CDATA[A vulnerability was found in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. It has been rated as critical. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid re...]]></description>
<link>https://tsecurity.de/de/4156614/sicherheitsluecken-cve/cve-2026-90598-jaygajera17-e-commerce-project-springboot-up-to-5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2-usercontrollerjava-usercontrollerupdateuser-userid-authorization-issue-172/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156614/sicherheitsluecken-cve/cve-2026-90598-jaygajera17-e-commerce-project-springboot-up-to-5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2-usercontrollerjava-usercontrollerupdateuser-userid-authorization-issue-172/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. It has been rated as critical. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. This vulnerability is... <a href="https://vuldb.com/vuln/403180" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90603 | Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0 S3 Upload /api/upload-binary x-proxy-target-url unrestricted upload (Issue 310)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricte...]]></description>
<link>https://tsecurity.de/de/4156613/sicherheitsluecken-cve/cve-2026-90603-anil-matcha-open-generative-ai-up-to-1011200-s3-upload-apiupload-binary-x-proxy-target-url-unrestricted-upload-issue-310/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156613/sicherheitsluecken-cve/cve-2026-90603-anil-matcha-open-generative-ai-up-to-1011200-s3-upload-apiupload-binary-x-proxy-target-url-unrestricted-upload-issue-310/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. This vulnerability is traded as... <a href="https://vuldb.com/vuln/403185" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90580 | FlowiseAI Flowise up to 3.0.2 Evaluations Endpoint index.ts axios.post Host/X-Forwarded-Proto server-side request forgery (Issue 6687)]]></title>
<description><![CDATA[A vulnerability was found in FlowiseAI Flowise up to 3.0.2. It has been declared as critical. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarde...]]></description>
<link>https://tsecurity.de/de/4156612/sicherheitsluecken-cve/cve-2026-90580-flowiseai-flowise-up-to-302-evaluations-endpoint-indexts-axiospost-hostx-forwarded-proto-server-side-request-forgery-issue-6687/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156612/sicherheitsluecken-cve/cve-2026-90580-flowiseai-flowise-up-to-302-evaluations-endpoint-indexts-axiospost-hostx-forwarded-proto-server-side-request-forgery-issue-6687/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in FlowiseAI Flowise up to 3.0.2. It has been declared as critical. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. This... <a href="https://vuldb.com/vuln/403165" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90593 | embedded-graphics up to 0.8.2 src/image/image_raw.rs ImageRaw::draw_sub_image width integer overflow (Issue 821)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The identification of this vulnerabili...]]></description>
<link>https://tsecurity.de/de/4156611/sicherheitsluecken-cve/cve-2026-90593-embedded-graphics-up-to-082-srcimageimagerawrs-imagerawdrawsubimage-width-integer-overflow-issue-821/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156611/sicherheitsluecken-cve/cve-2026-90593-embedded-graphics-up-to-082-srcimageimagerawrs-imagerawdrawsubimage-width-integer-overflow-issue-821/</guid>
<pubDate>Sat, 19 Sep 2026 13:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The identification of this vulnerability is CVE-2026-90593. The attack may be launched... <a href="https://vuldb.com/vuln/403175" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave]]></title>
<description><![CDATA[Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave Three of the seven vulnerabilities CISA added to its Known Exploited Vulnerabilities catalog on September 2, 2026 targeted AI and workflow tooling: BerriAI LiteLLM's authentication flaw CVE-2026-59822, th...]]></description>
<link>https://tsecurity.de/de/4156605/sicherheitsluecken-cve/rotating-secrets-after-an-ai-tooling-compromise-a-checklist-for-the-september-2026-kev-wave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156605/sicherheitsluecken-cve/rotating-secrets-after-an-ai-tooling-compromise-a-checklist-for-the-september-2026-kev-wave/</guid>
<pubDate>Sat, 19 Sep 2026 13:29:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave Three of the seven vulnerabilities CISA added to its Known Exploited Vulnerabilities catalog on September 2, 2026 targeted AI and workflow tooling: BerriAI LiteLLM&#039;s authentication flaw CVE-2026-59822, the Kestra orchestrator&#039;s unauthenticated... <a href="https://dev.to/kozhevniko/rotating-secrets-after-an-ai-tooling-compromise-a-checklist-for-the-september-2026-kev-wave-4l38" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SolarWinds fixt ARM-Fall mit Hard-Coded-Key: Patch für CVE-2026-28326]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – SolarWinds hat Sicherheitsupdates für den Access Rights Manager (ARM) veröffentlicht, um eine kritische Schwachstelle zu schließen. Die Lücke mit der Kennung CVE-2026-28326 beruht auf einem hard-codierten statischen Schlüssel und könnte bei erfolgreicher Ausnutzung zu einer...]]></description>
<link>https://tsecurity.de/de/4156585/sicherheitsluecken-cve/solarwinds-fixt-arm-fall-mit-hard-coded-key-patch-fuer-cve-2026-28326/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156585/sicherheitsluecken-cve/solarwinds-fixt-arm-fall-mit-hard-coded-key-patch-fuer-cve-2026-28326/</guid>
<pubDate>Sat, 19 Sep 2026 13:23:13 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – SolarWinds hat Sicherheitsupdates für den Access Rights Manager (ARM) veröffentlicht, um eine kritische Schwachstelle zu schließen. Die Lücke mit der Kennung CVE-2026-28326 beruht auf einem hard-codierten statischen Schlüssel und könnte bei erfolgreicher Ausnutzung zu einer Remote-Code-Execution ohne Authentifizierung... <a href="https://www.it-boltwise.de/solarwinds-fixt-arm-fall-mit-hard-coded-key-patch-fuer-cve-2026-28326.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-19 12h : 5 posts]]></title>
<description><![CDATA[5 posts published in the last hour 09:316 Best VPN Services (2026), Tested and Reviewed 09:31Drug trafficking investigation leads to some of the world’s biggest underground bankers 09:31North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto 09:02Critical P...]]></description>
<link>https://tsecurity.de/de/4156576/sicherheitsluecken-cve/it-security-news-hourly-summary-2026-09-19-12h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156576/sicherheitsluecken-cve/it-security-news-hourly-summary-2026-09-19-12h-5-posts/</guid>
<pubDate>Sat, 19 Sep 2026 13:23:06 +0200</pubDate>
<content:encoded><![CDATA[<p>5 posts published in the last hour 09:316 Best VPN Services (2026), Tested and Reviewed 09:31Drug trafficking investigation leads to some of the world’s biggest underground bankers 09:31North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto 09:02Critical Pre-Auth RCE in Orkes Conductor Workflow Platform... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-19-12h-5-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening]]></title>
<description><![CDATA[AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156531/sicherheitsluecken-cve/forget-the-ai-slowdown-the-vulnerability-explosion-is-already-happening/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156531/sicherheitsluecken-cve/forget-the-ai-slowdown-the-vulnerability-explosion-is-already-happening/</guid>
<pubDate>Sat, 19 Sep 2026 13:15:32 +0200</pubDate>
<content:encoded><![CDATA[<p>AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws. <a href="https://www.wired.com/story/kernel-panic-ai-vulnerability-explosion/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-72708 | SPIP up to 4.4.17 Sitemap Endpoint ecrire/req/mysql.php spip_mysql_cite annee sql injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in SPIP up to 4.4.17. The affected element is the function spip_mysql_cite of the file ecrire/req/mysql.php of the component Sitemap Endpoint. The manipulation of the argument annee results in sql injection. This vulnerability is catalo...]]></description>
<link>https://tsecurity.de/de/4156524/sicherheitsluecken-cve/cve-2026-72708-spip-up-to-4417-sitemap-endpoint-ecrirereqmysqlphp-spipmysqlcite-annee-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156524/sicherheitsluecken-cve/cve-2026-72708-spip-up-to-4417-sitemap-endpoint-ecrirereqmysqlphp-spipmysqlcite-annee-sql-injection/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in SPIP up to 4.4.17. The affected element is the function spip_mysql_cite of the file ecrire/req/mysql.php of the component Sitemap Endpoint. The manipulation of the argument annee results in sql injection. This vulnerability is cataloged as CVE-2026-72708. The attack may be launched... <a href="https://vuldb.com/vuln/402475" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90533 | FlowiseAI Flowise up to 3.1.3 /api/v1/organizationuser access control]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in FlowiseAI Flowise up to 3.1.3. This affects an unknown part of the file /api/v1/organizationuser. This manipulation causes improper access controls. This vulnerability is handled as CVE-2026-90533. The attack can be initiated remotely. Th...]]></description>
<link>https://tsecurity.de/de/4156523/sicherheitsluecken-cve/cve-2026-90533-flowiseai-flowise-up-to-313-apiv1organizationuser-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156523/sicherheitsluecken-cve/cve-2026-90533-flowiseai-flowise-up-to-313-apiv1organizationuser-access-control/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in FlowiseAI Flowise up to 3.1.3. This affects an unknown part of the file /api/v1/organizationuser. This manipulation causes improper access controls. This vulnerability is handled as CVE-2026-90533. The attack can be initiated remotely. There is not any exploit available. It is suggested to... <a href="https://vuldb.com/vuln/403142" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90535 | FlowiseAI Flowise up to 3.1.3 Text To Speech Abort abort chatflowId/chatId denial of service]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in FlowiseAI Flowise up to 3.1.3. Affected is an unknown function of the file /api/v1/text-to-speech/abort of the component Text To Speech Abort. Executing a manipulation of the argument chatflowId/chatId can lead to denial of service...]]></description>
<link>https://tsecurity.de/de/4156522/sicherheitsluecken-cve/cve-2026-90535-flowiseai-flowise-up-to-313-text-to-speech-abort-abort-chatflowidchatid-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156522/sicherheitsluecken-cve/cve-2026-90535-flowiseai-flowise-up-to-313-text-to-speech-abort-abort-chatflowidchatid-denial-of-service/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in FlowiseAI Flowise up to 3.1.3. Affected is an unknown function of the file /api/v1/text-to-speech/abort of the component Text To Speech Abort. Executing a manipulation of the argument chatflowId/chatId can lead to denial of service. This vulnerability appears as CVE-2026-90535. The... <a href="https://vuldb.com/vuln/403139" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67211 | Apache OpenNLP up to 3.0.0-M5 opennlp-spellcheck extension SymSpellModelSerializer.create unigramCount/bigramCount allocation of resources]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Apache OpenNLP up to 3.0.0-M5. This affects the function SymSpellModelSerializer.create of the component opennlp-spellcheck extension. This manipulation of the argument unigramCount/bigramCount causes allocation of resources....]]></description>
<link>https://tsecurity.de/de/4156521/sicherheitsluecken-cve/cve-2026-67211-apache-opennlp-up-to-300-m5-opennlp-spellcheck-extension-symspellmodelserializercreate-unigramcountbigramcount-allocation-of-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156521/sicherheitsluecken-cve/cve-2026-67211-apache-opennlp-up-to-300-m5-opennlp-spellcheck-extension-symspellmodelserializercreate-unigramcountbigramcount-allocation-of-resources/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in Apache OpenNLP up to 3.0.0-M5. This affects the function SymSpellModelSerializer.create of the component opennlp-spellcheck extension. This manipulation of the argument unigramCount/bigramCount causes allocation of resources. This vulnerability is tracked as CVE-2026-67211.... <a href="https://vuldb.com/vuln/402488" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-82617 | Apache OpenNLP up to 2.5.11/3.0.0-M5 RegexNameFinder RegexNameFinderFactory.java RegexNameFinder.find String[] resource consumption]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Apache OpenNLP up to 2.5.11/3.0.0-M5. This impacts the function RegexNameFinder.find of the file RegexNameFinderFactory.java of the component RegexNameFinder. Such manipulation of the argument String[] leads to resource consumptio...]]></description>
<link>https://tsecurity.de/de/4156520/sicherheitsluecken-cve/cve-2026-82617-apache-opennlp-up-to-2511300-m5-regexnamefinder-regexnamefinderfactoryjava-regexnamefinderfind-string-resource-consumption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156520/sicherheitsluecken-cve/cve-2026-82617-apache-opennlp-up-to-2511300-m5-regexnamefinder-regexnamefinderfactoryjava-regexnamefinderfind-string-resource-consumption/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Apache OpenNLP up to 2.5.11/3.0.0-M5. This impacts the function RegexNameFinder.find of the file RegexNameFinderFactory.java of the component RegexNameFinder. Such manipulation of the argument String[] leads to resource consumption. This vulnerability is listed as CVE-2026-82617.... <a href="https://vuldb.com/vuln/402489" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90534 | FlowiseAI Flowise up to 3.1.3 Credential Resolution /api/v1/node-load-method getCredentialData nodeName permission]]></title>
<description><![CDATA[A vulnerability was found in FlowiseAI Flowise up to 3.1.3. It has been rated as critical. This impacts the function getCredentialData of the file /api/v1/node-load-method of the component Credential Resolution. Performing a manipulation of the argument nodeName results in permission issues. This...]]></description>
<link>https://tsecurity.de/de/4156519/sicherheitsluecken-cve/cve-2026-90534-flowiseai-flowise-up-to-313-credential-resolution-apiv1node-load-method-getcredentialdata-nodename-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156519/sicherheitsluecken-cve/cve-2026-90534-flowiseai-flowise-up-to-313-credential-resolution-apiv1node-load-method-getcredentialdata-nodename-permission/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in FlowiseAI Flowise up to 3.1.3. It has been rated as critical. This impacts the function getCredentialData of the file /api/v1/node-load-method of the component Credential Resolution. Performing a manipulation of the argument nodeName results in permission issues. This vulnerability is reported as CVE-2026-90534. The... <a href="https://vuldb.com/vuln/403138" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-79035 | Zeta Marketing Platform 1.0 p.rfihub.com ca cross site scripting]]></title>
<description><![CDATA[A vulnerability has been found in Zeta Marketing Platform 1.0 and classified as problematic. The affected element is an unknown function of the component p.rfihub.com. Performing a manipulation of the argument ca results in cross site scripting. This vulnerability was named CVE-2026-79035. The at...]]></description>
<link>https://tsecurity.de/de/4156518/sicherheitsluecken-cve/cve-2026-79035-zeta-marketing-platform-10-prfihubcom-ca-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156518/sicherheitsluecken-cve/cve-2026-79035-zeta-marketing-platform-10-prfihubcom-ca-cross-site-scripting/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Zeta Marketing Platform 1.0 and classified as problematic. The affected element is an unknown function of the component p.rfihub.com. Performing a manipulation of the argument ca results in cross site scripting. This vulnerability was named CVE-2026-79035. The attack may be initiated remotely. There is no... <a href="https://vuldb.com/vuln/402574" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89332 | AWS Kiro IDE up to 0.8.134 Kiro Powers redirect]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in AWS Kiro IDE up to 0.8.134. Affected by this vulnerability is an unknown functionality of the component Kiro Powers. This manipulation causes open redirect. This vulnerability appears as CVE-2026-89332. The attack may be initiated rem...]]></description>
<link>https://tsecurity.de/de/4156517/sicherheitsluecken-cve/cve-2026-89332-aws-kiro-ide-up-to-08134-kiro-powers-redirect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156517/sicherheitsluecken-cve/cve-2026-89332-aws-kiro-ide-up-to-08134-kiro-powers-redirect/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in AWS Kiro IDE up to 0.8.134. Affected by this vulnerability is an unknown functionality of the component Kiro Powers. This manipulation causes open redirect. This vulnerability appears as CVE-2026-89332. The attack may be initiated remotely. There is no available exploit. You should... <a href="https://vuldb.com/vuln/402524" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81910 | Concrete CMS up to 9.5.2 Theme Customizer special elements in template engine]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Concrete CMS up to 9.5.2. This impacts an unknown function of the component Theme Customizer. The manipulation results in improper neutralization of special elements used in a template engine. This vulnerability is known as CVE-2026-81910. ...]]></description>
<link>https://tsecurity.de/de/4156516/sicherheitsluecken-cve/cve-2026-81910-concrete-cms-up-to-952-theme-customizer-special-elements-in-template-engine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156516/sicherheitsluecken-cve/cve-2026-81910-concrete-cms-up-to-952-theme-customizer-special-elements-in-template-engine/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in Concrete CMS up to 9.5.2. This impacts an unknown function of the component Theme Customizer. The manipulation results in improper neutralization of special elements used in a template engine. This vulnerability is known as CVE-2026-81910. It is possible to launch the attack remotely. No... <a href="https://vuldb.com/vuln/402511" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-79394 | XiongMai Sofia IPC daemon up to 0608.1837 RTSP Server access control]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in XiongMai Sofia IPC daemon up to 0608.1837. Affected by this vulnerability is an unknown functionality of the component RTSP Server. Such manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE...]]></description>
<link>https://tsecurity.de/de/4156515/sicherheitsluecken-cve/cve-2026-79394-xiongmai-sofia-ipc-daemon-up-to-06081837-rtsp-server-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156515/sicherheitsluecken-cve/cve-2026-79394-xiongmai-sofia-ipc-daemon-up-to-06081837-rtsp-server-access-control/</guid>
<pubDate>Sat, 19 Sep 2026 11:59:52 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in XiongMai Sofia IPC daemon up to 0608.1837. Affected by this vulnerability is an unknown functionality of the component RTSP Server. Such manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2026-79394. The attack can be launched remotely. No... <a href="https://vuldb.com/vuln/402513" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Orkes Conductor: kritische RCE-Lücke wird aktiv ausgenutzt – Update dringend]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine kritische Sicherheitslücke in Orkes Conductor wird laut Fortinet aktiv ausgenutzt. Betroffen ist CVE-2026-58138 mit 9,8 (CVSS v3.1) bzw. 9,3 (CVSS v4) und einer unauthentifizierten Remote-Code-Execution vor der Anmeldung. Angreifer senden speziell präparierte Workflow-...]]></description>
<link>https://tsecurity.de/de/4156492/sicherheitsluecken-cve/orkes-conductor-kritische-rce-luecke-wird-aktiv-ausgenutzt-update-dringend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156492/sicherheitsluecken-cve/orkes-conductor-kritische-rce-luecke-wird-aktiv-ausgenutzt-update-dringend/</guid>
<pubDate>Sat, 19 Sep 2026 11:53:09 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Eine kritische Sicherheitslücke in Orkes Conductor wird laut Fortinet aktiv ausgenutzt. Betroffen ist CVE-2026-58138 mit 9,8 (CVSS v3.1) bzw. 9,3 (CVSS v4) und einer unauthentifizierten Remote-Code-Execution vor der Anmeldung. Angreifer senden speziell präparierte Workflow-Definitionen an die Conductor-Workflow-API, um über... <a href="https://www.it-boltwise.de/orkes-conductor-kritische-rce-luecke-wird-aktiv-ausgenutzt-update-dringend.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild]]></title>
<description><![CDATA[A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 ...]]></description>
<link>https://tsecurity.de/de/4156482/sicherheitsluecken-cve/critical-pre-auth-rce-in-orkes-conductor-workflow-platform-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156482/sicherheitsluecken-cve/critical-pre-auth-rce-in-orkes-conductor-workflow-platform-exploited-in-the-wild/</guid>
<pubDate>Sat, 19 Sep 2026 11:49:14 +0200</pubDate>
<content:encoded><![CDATA[<p>A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. &quot;Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote... <a href="https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93741 | Totolink A3002MU Hh-B20211125.1046 /boafrm/formWlWds submit-url buffer overflow (EUVD-2026-83497)]]></title>
<description><![CDATA[A vulnerability labeled as very critical has been found in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. This vulnerability is known as CVE-2026-93...]]></description>
<link>https://tsecurity.de/de/4156429/sicherheitsluecken-cve/cve-2026-93741-totolink-a3002mu-hh-b202111251046-boafrmformwlwds-submit-url-buffer-overflow-euvd-2026-83497/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156429/sicherheitsluecken-cve/cve-2026-93741-totolink-a3002mu-hh-b202111251046-boafrmformwlwds-submit-url-buffer-overflow-euvd-2026-83497/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as very critical has been found in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. This vulnerability is known as CVE-2026-93741. It is possible to launch the attack remotely.... <a href="https://vuldb.com/vuln/407551" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92435 | WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress Permission Callback authorization (EUVD-2026-83517)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress. This issue affects some unknown processing of the component Permission Callback. The manipulation leads to missing authorization. This vulnerability is listed as CVE-2026...]]></description>
<link>https://tsecurity.de/de/4156428/sicherheitsluecken-cve/cve-2026-92435-woocommerce-mailchimp-for-woocommerce-plugin-up-to-610-on-wordpress-permission-callback-authorization-euvd-2026-83517/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156428/sicherheitsluecken-cve/cve-2026-92435-woocommerce-mailchimp-for-woocommerce-plugin-up-to-610-on-wordpress-permission-callback-authorization-euvd-2026-83517/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress. This issue affects some unknown processing of the component Permission Callback. The manipulation leads to missing authorization. This vulnerability is listed as CVE-2026-92435. The attack may be initiated remotely. There... <a href="https://vuldb.com/vuln/407874" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92430 | Rede Itaú for WooCommerce Plugin up to 5.4.6 on WordPress authorization (EUVD-2026-83516)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Rede Itaú for WooCommerce Plugin up to 5.4.6 on WordPress. This affects an unknown part. Executing a manipulation can lead to missing authorization. This vulnerability is registered as CVE-2026-92430. It is possible to launch the att...]]></description>
<link>https://tsecurity.de/de/4156427/sicherheitsluecken-cve/cve-2026-92430-rede-ita-for-woocommerce-plugin-up-to-546-on-wordpress-authorization-euvd-2026-83516/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156427/sicherheitsluecken-cve/cve-2026-92430-rede-ita-for-woocommerce-plugin-up-to-546-on-wordpress-authorization-euvd-2026-83516/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Rede Itaú for WooCommerce Plugin up to 5.4.6 on WordPress. This affects an unknown part. Executing a manipulation can lead to missing authorization. This vulnerability is registered as CVE-2026-92430. It is possible to launch the attack remotely. No exploit is available. Upgrading the... <a href="https://vuldb.com/vuln/407861" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92425 | Hydra Booking Plugin up to 1.2.3 on WordPress authorization (EUVD-2026-83515)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Hydra Booking Plugin up to 1.2.3 on WordPress. Affected by this issue is some unknown functionality. Performing a manipulation results in authorization bypass. This vulnerability is cataloged as CVE-2026-92425. It is possible to initiate ...]]></description>
<link>https://tsecurity.de/de/4156426/sicherheitsluecken-cve/cve-2026-92425-hydra-booking-plugin-up-to-123-on-wordpress-authorization-euvd-2026-83515/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156426/sicherheitsluecken-cve/cve-2026-92425-hydra-booking-plugin-up-to-123-on-wordpress-authorization-euvd-2026-83515/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Hydra Booking Plugin up to 1.2.3 on WordPress. Affected by this issue is some unknown functionality. Performing a manipulation results in authorization bypass. This vulnerability is cataloged as CVE-2026-92425. It is possible to initiate the attack remotely. There is no exploit available.... <a href="https://vuldb.com/vuln/407860" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92421 | Hydra Booking Plugin up to 1.2.2 on WordPress authorization (EUVD-2026-83514)]]></title>
<description><![CDATA[A vulnerability was found in Hydra Booking Plugin up to 1.2.2 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes authorization bypass. The identification of this vulnerability is CVE-2026-92421. It is possible to initi...]]></description>
<link>https://tsecurity.de/de/4156425/sicherheitsluecken-cve/cve-2026-92421-hydra-booking-plugin-up-to-122-on-wordpress-authorization-euvd-2026-83514/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156425/sicherheitsluecken-cve/cve-2026-92421-hydra-booking-plugin-up-to-122-on-wordpress-authorization-euvd-2026-83514/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Hydra Booking Plugin up to 1.2.2 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes authorization bypass. The identification of this vulnerability is CVE-2026-92421. It is possible to initiate the attack remotely. There is no exploit... <a href="https://vuldb.com/vuln/407870" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92420 | Hydra Booking Plugin up to 1.2.1 on WordPress authorization (EUVD-2026-83513)]]></title>
<description><![CDATA[A vulnerability was found in Hydra Booking Plugin up to 1.2.1 on WordPress. It has been declared as problematic. Affected is an unknown function. The manipulation results in authorization bypass. This vulnerability was named CVE-2026-92420. The attack may be performed from remote. There is no ava...]]></description>
<link>https://tsecurity.de/de/4156424/sicherheitsluecken-cve/cve-2026-92420-hydra-booking-plugin-up-to-121-on-wordpress-authorization-euvd-2026-83513/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156424/sicherheitsluecken-cve/cve-2026-92420-hydra-booking-plugin-up-to-121-on-wordpress-authorization-euvd-2026-83513/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Hydra Booking Plugin up to 1.2.1 on WordPress. It has been declared as problematic. Affected is an unknown function. The manipulation results in authorization bypass. This vulnerability was named CVE-2026-92420. The attack may be performed from remote. There is no available exploit. It is recommended to upgrade the... <a href="https://vuldb.com/vuln/407869" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92404 | MgoSync Plugin up to 2.1.6 on WordPress REST API Endpoint information disclosure (EUVD-2026-83512)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in MgoSync Plugin up to 2.1.6 on WordPress. Affected by this vulnerability is an unknown functionality of the component REST API Endpoint. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-2026-92404. The a...]]></description>
<link>https://tsecurity.de/de/4156423/sicherheitsluecken-cve/cve-2026-92404-mgosync-plugin-up-to-216-on-wordpress-rest-api-endpoint-information-disclosure-euvd-2026-83512/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156423/sicherheitsluecken-cve/cve-2026-92404-mgosync-plugin-up-to-216-on-wordpress-rest-api-endpoint-information-disclosure-euvd-2026-83512/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:25 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in MgoSync Plugin up to 2.1.6 on WordPress. Affected by this vulnerability is an unknown functionality of the component REST API Endpoint. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-2026-92404. The attack may be performed from remote. There is no... <a href="https://vuldb.com/vuln/407859" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92403 | Secure Custom Fields Plugin up to 6.9.3 on WordPress authorization (EUVD-2026-83511)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Secure Custom Fields Plugin up to 6.9.3 on WordPress. Affected is an unknown function. This manipulation causes incorrect authorization. This vulnerability is tracked as CVE-2026-92403. The attack is possible to be carried out remotel...]]></description>
<link>https://tsecurity.de/de/4156422/sicherheitsluecken-cve/cve-2026-92403-secure-custom-fields-plugin-up-to-693-on-wordpress-authorization-euvd-2026-83511/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156422/sicherheitsluecken-cve/cve-2026-92403-secure-custom-fields-plugin-up-to-693-on-wordpress-authorization-euvd-2026-83511/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:24 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Secure Custom Fields Plugin up to 6.9.3 on WordPress. Affected is an unknown function. This manipulation causes incorrect authorization. This vulnerability is tracked as CVE-2026-92403. The attack is possible to be carried out remotely. No exploit exists. You should upgrade the... <a href="https://vuldb.com/vuln/407858" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92099 | WPGraphQL Smart Cache Plugin up to 2.3.1 on WordPress access control (EUVD-2026-83510)]]></title>
<description><![CDATA[A vulnerability was found in WPGraphQL Smart Cache Plugin up to 2.3.1 on WordPress. It has been classified as problematic. This impacts an unknown function. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2026-92099. The attack is possible to b...]]></description>
<link>https://tsecurity.de/de/4156421/sicherheitsluecken-cve/cve-2026-92099-wpgraphql-smart-cache-plugin-up-to-231-on-wordpress-access-control-euvd-2026-83510/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156421/sicherheitsluecken-cve/cve-2026-92099-wpgraphql-smart-cache-plugin-up-to-231-on-wordpress-access-control-euvd-2026-83510/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:24 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in WPGraphQL Smart Cache Plugin up to 2.3.1 on WordPress. It has been classified as problematic. This impacts an unknown function. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2026-92099. The attack is possible to be carried out remotely. No exploit exists. Upgrading... <a href="https://vuldb.com/vuln/407868" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-91847 | Online Scheduling and Appointment Booking System Plugin authorization (EUVD-2026-83509)]]></title>
<description><![CDATA[A vulnerability was found in Online Scheduling and Appointment Booking System Plugin up to 28.1 on WordPress and classified as critical. This affects an unknown function. Executing a manipulation can lead to authorization bypass. This vulnerability is handled as CVE-2026-91847. The attack can be ...]]></description>
<link>https://tsecurity.de/de/4156420/sicherheitsluecken-cve/cve-2026-91847-online-scheduling-and-appointment-booking-system-plugin-authorization-euvd-2026-83509/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156420/sicherheitsluecken-cve/cve-2026-91847-online-scheduling-and-appointment-booking-system-plugin-authorization-euvd-2026-83509/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:17 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Online Scheduling and Appointment Booking System Plugin up to 28.1 on WordPress and classified as critical. This affects an unknown function. Executing a manipulation can lead to authorization bypass. This vulnerability is handled as CVE-2026-91847. The attack can be executed remotely. There is not any exploit... <a href="https://vuldb.com/vuln/407867" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-88926 | VikRentItems Flexible Rental Management System Plugin sql injection (EUVD-2026-83508)]]></title>
<description><![CDATA[A vulnerability has been found in VikRentItems Flexible Rental Management System Plugin up to 1.2.3 on WordPress and classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is known as CVE-2026-88926. Remote explo...]]></description>
<link>https://tsecurity.de/de/4156419/sicherheitsluecken-cve/cve-2026-88926-vikrentitems-flexible-rental-management-system-plugin-sql-injection-euvd-2026-83508/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156419/sicherheitsluecken-cve/cve-2026-88926-vikrentitems-flexible-rental-management-system-plugin-sql-injection-euvd-2026-83508/</guid>
<pubDate>Sat, 19 Sep 2026 10:43:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in VikRentItems Flexible Rental Management System Plugin up to 1.2.3 on WordPress and classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is known as CVE-2026-88926. Remote exploitation of the attack is possible. No exploit is... <a href="https://vuldb.com/vuln/407866" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Never installable]]></title>
<description><![CDATA[For three days of real-device testing, the app worked, or seemed to. Every test passed. Every review came back clean. On a real phone, it had never once been installable, and nothing had ever said so. This is a proof-of-concept, not an NHS product. It was built by one technical person working alo...]]></description>
<link>https://tsecurity.de/de/4156415/proof-of-concept-poc/never-installable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156415/proof-of-concept-poc/never-installable/</guid>
<pubDate>Sat, 19 Sep 2026 10:41:53 +0200</pubDate>
<content:encoded><![CDATA[<p>For three days of real-device testing, the app worked, or seemed to. Every test passed. Every review came back clean. On a real phone, it had never once been installable, and nothing had ever said so. This is a proof-of-concept, not an NHS product. It was built by one technical person working alongside an NHS dietetic team. No patient data exists... <a href="https://dev.to/thekilteddev/never-installable-2fh4" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)]]></title>
<description><![CDATA[submitted by /u/natcoba [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156406/sicherheitsluecken-cve/cve-2026-77179-dockers-hypervisor-for-mac-compromised-docker-desktop-docker-sandboxes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156406/sicherheitsluecken-cve/cve-2026-77179-dockers-hypervisor-for-mac-compromised-docker-desktop-docker-sandboxes/</guid>
<pubDate>Sat, 19 Sep 2026 10:41:01 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/natcoba [link] [comments] <a href="https://www.reddit.com/r/ReverseEngineering/comments/1wkehjs/cve202677179_dockers_hypervisor_for_mac/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44427 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47370)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. This issue affects some unknown processing of the component WLAN Driver. This manipulation causes denial of service. This ...]]></description>
<link>https://tsecurity.de/de/4156352/sicherheitsluecken-cve/cve-2022-44427-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47370/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156352/sicherheitsluecken-cve/cve-2022-44427-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47370/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. This issue affects some unknown processing of the component WLAN Driver. This manipulation causes denial of service. This vulnerability is registered as CVE-2022-44427. The... <a href="https://vuldb.com/vuln/217376" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44429 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47372)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. The affected element is an unknown function of the component WLAN Driver. Performing a manipulation results in denial of ...]]></description>
<link>https://tsecurity.de/de/4156351/sicherheitsluecken-cve/cve-2022-44429-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47372/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156351/sicherheitsluecken-cve/cve-2022-44429-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47372/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. The affected element is an unknown function of the component WLAN Driver. Performing a manipulation results in denial of service. This vulnerability is reported as... <a href="https://vuldb.com/vuln/217378" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44428 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47371)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. Impacted is an unknown function of the component WLAN Driver. Such manipulation leads to denial of service. This vuln...]]></description>
<link>https://tsecurity.de/de/4156350/sicherheitsluecken-cve/cve-2022-44428-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47371/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156350/sicherheitsluecken-cve/cve-2022-44428-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47371/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. Impacted is an unknown function of the component WLAN Driver. Such manipulation leads to denial of service. This vulnerability is documented as CVE-2022-44428. The... <a href="https://vuldb.com/vuln/217377" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44430 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47373)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. The impacted element is an unknown function of the component WLAN Driver. Executing a manipulation can lead to denial of servi...]]></description>
<link>https://tsecurity.de/de/4156349/sicherheitsluecken-cve/cve-2022-44430-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47373/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156349/sicherheitsluecken-cve/cve-2022-44430-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47373/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. The impacted element is an unknown function of the component WLAN Driver. Executing a manipulation can lead to denial of service. This vulnerability appears as CVE-2022-44430.... <a href="https://vuldb.com/vuln/217379" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44431 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47374)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. This affects an unknown function of the component WLAN Driver. The manipulation leads to denial of service. T...]]></description>
<link>https://tsecurity.de/de/4156348/sicherheitsluecken-cve/cve-2022-44431-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47374/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156348/sicherheitsluecken-cve/cve-2022-44431-unisoc-s8000-wlan-driver-denial-of-service-euvd-2022-47374/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. This affects an unknown function of the component WLAN Driver. The manipulation leads to denial of service. This vulnerability is traded as CVE-2022-44431. An... <a href="https://vuldb.com/vuln/217380" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65381 | Apple macOS up to 15.7/26/26.6 Entitlement Verification sandbox]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 15.7/26/26.6 and classified as critical. This affects an unknown function of the component Entitlement Verification. Such manipulation leads to sandbox issue. This vulnerability is uniquely identified as CVE-2026-65381. Local access is required to ap...]]></description>
<link>https://tsecurity.de/de/4156347/sicherheitsluecken-cve/cve-2026-65381-apple-macos-up-to-15726266-entitlement-verification-sandbox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156347/sicherheitsluecken-cve/cve-2026-65381-apple-macos-up-to-15726266-entitlement-verification-sandbox/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 15.7/26/26.6 and classified as critical. This affects an unknown function of the component Entitlement Verification. Such manipulation leads to sandbox issue. This vulnerability is uniquely identified as CVE-2026-65381. Local access is required to approach this attack. No exploit exists. It is... <a href="https://vuldb.com/vuln/403863" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65377 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.7/27/15.8 memory corruption]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Impacted is an unknown function. The manipulation leads to memory corruption. This vulnerability is traded as CVE-2026-65377. It is possible to initiate the attack remot...]]></description>
<link>https://tsecurity.de/de/4156346/sicherheitsluecken-cve/cve-2026-65377-apple-iosipadosmacostvosvisionoswatchos-prior-26727158-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156346/sicherheitsluecken-cve/cve-2026-65377-apple-iosipadosmacostvosvisionoswatchos-prior-26727158-memory-corruption/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, has been found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Impacted is an unknown function. The manipulation leads to memory corruption. This vulnerability is traded as CVE-2026-65377. It is possible to initiate the attack remotely. There is no exploit available. It is advisable... <a href="https://vuldb.com/vuln/403860" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65376 | Apple macOS up to 15.7/26/26.6 out-of-bounds]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. This issue affects some unknown processing. Executing a manipulation can lead to out-of-bounds read. This vulnerability appears as CVE-2026-65376. The attack requires local access. There is no available exploit...]]></description>
<link>https://tsecurity.de/de/4156345/sicherheitsluecken-cve/cve-2026-65376-apple-macos-up-to-15726266-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156345/sicherheitsluecken-cve/cve-2026-65376-apple-macos-up-to-15726266-out-of-bounds/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. This issue affects some unknown processing. Executing a manipulation can lead to out-of-bounds read. This vulnerability appears as CVE-2026-65376. The attack requires local access. There is no available exploit. Upgrading the affected component is advised. <a href="https://vuldb.com/vuln/403859" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65375 | Apple macOS up to 15.7/26/26.5 improper authentication]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Apple macOS up to 15.7/26/26.5. This vulnerability affects unknown code. Performing a manipulation results in improper authentication. This vulnerability is reported as CVE-2026-65375. The attack requires a local approach. No exploit exi...]]></description>
<link>https://tsecurity.de/de/4156344/sicherheitsluecken-cve/cve-2026-65375-apple-macos-up-to-15726265-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156344/sicherheitsluecken-cve/cve-2026-65375-apple-macos-up-to-15726265-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in Apple macOS up to 15.7/26/26.5. This vulnerability affects unknown code. Performing a manipulation results in improper authentication. This vulnerability is reported as CVE-2026-65375. The attack requires a local approach. No exploit exists. It is recommended to upgrade the affected... <a href="https://vuldb.com/vuln/403858" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65369 | Apple macOS up to 15.7/26/26.6 Gatekeeper state issue]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as very critical. The impacted element is an unknown function of the component Gatekeeper. Such manipulation leads to state issue. This vulnerability is referenced as CVE-2026-65369. It is possible to launch the att...]]></description>
<link>https://tsecurity.de/de/4156343/sicherheitsluecken-cve/cve-2026-65369-apple-macos-up-to-15726266-gatekeeper-state-issue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156343/sicherheitsluecken-cve/cve-2026-65369-apple-macos-up-to-15726266-gatekeeper-state-issue/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as very critical. The impacted element is an unknown function of the component Gatekeeper. Such manipulation leads to state issue. This vulnerability is referenced as CVE-2026-65369. It is possible to launch the attack remotely. No exploit is available. It is... <a href="https://vuldb.com/vuln/403851" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65371 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS Kernel information disclosure]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this vulnerability is an unknown functionality of the component Kernel. The manipulation results in information disclosure. This vulnerability is cataloged as CVE-2026-65371....]]></description>
<link>https://tsecurity.de/de/4156342/sicherheitsluecken-cve/cve-2026-65371-apple-ipadosiosmacostvosvisionoswatchos-kernel-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156342/sicherheitsluecken-cve/cve-2026-65371-apple-ipadosiosmacostvosvisionoswatchos-kernel-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this vulnerability is an unknown functionality of the component Kernel. The manipulation results in information disclosure. This vulnerability is cataloged as CVE-2026-65371. The attack may be launched remotely. There is no... <a href="https://vuldb.com/vuln/403855" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65360 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior 26.7/15.8/27 race condition]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this issue is some unknown functionality. Such manipulation leads to race condition. This vulnerability is traded as CVE-2026-65360. An attack has to be approached locally. The...]]></description>
<link>https://tsecurity.de/de/4156341/sicherheitsluecken-cve/cve-2026-65360-apple-ipadosiosmacostvosvisionoswatchos-prior-26715827-race-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156341/sicherheitsluecken-cve/cve-2026-65360-apple-ipadosiosmacostvosvisionoswatchos-prior-26715827-race-condition/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this issue is some unknown functionality. Such manipulation leads to race condition. This vulnerability is traded as CVE-2026-65360. An attack has to be approached locally. There is no exploit available. Upgrading the affected... <a href="https://vuldb.com/vuln/403845" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65361 | Apple macOS up to 15.7/26/26.6 information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Apple macOS up to 15.7/26/26.6. This vulnerability affects unknown code. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-2026-65361. It is possible to launch the attack on the loca...]]></description>
<link>https://tsecurity.de/de/4156340/sicherheitsluecken-cve/cve-2026-65361-apple-macos-up-to-15726266-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156340/sicherheitsluecken-cve/cve-2026-65361-apple-macos-up-to-15726266-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Apple macOS up to 15.7/26/26.6. This vulnerability affects unknown code. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-2026-65361. It is possible to launch the attack on the local host. There is not any exploit available. You... <a href="https://vuldb.com/vuln/403847" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65359 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.7/27/15.8/Golden Gate 27/Tahoe 26.7 out-of-bounds]]></title>
<description><![CDATA[A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. It has been classified as problematic. This vulnerability affects unknown code. The manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-65359. The attack can only be performed fro...]]></description>
<link>https://tsecurity.de/de/4156339/sicherheitsluecken-cve/cve-2026-65359-apple-iosipadosmacostvosvisionoswatchos-prior-26727158golden-gate-27tahoe-267-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156339/sicherheitsluecken-cve/cve-2026-65359-apple-iosipadosmacostvosvisionoswatchos-prior-26727158golden-gate-27tahoe-267-out-of-bounds/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. It has been classified as problematic. This vulnerability affects unknown code. The manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-65359. The attack can only be performed from a local environment. No exploit is available.... <a href="https://vuldb.com/vuln/403836" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65358 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior 27 race condition]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this vulnerability is an unknown functionality. This manipulation causes race condition. This vulnerability appears as CVE-2026-65358. The attack requires local access. Th...]]></description>
<link>https://tsecurity.de/de/4156338/sicherheitsluecken-cve/cve-2026-65358-apple-ipadosiosmacostvosvisionoswatchos-prior-27-race-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156338/sicherheitsluecken-cve/cve-2026-65358-apple-ipadosiosmacostvosvisionoswatchos-prior-27-race-condition/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this vulnerability is an unknown functionality. This manipulation causes race condition. This vulnerability appears as CVE-2026-65358. The attack requires local access. There is no available exploit. It is recommended to... <a href="https://vuldb.com/vuln/403844" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65378 | Apple macOS up to 15.7/26/26.6 privileges management]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. The manipulation results in improper privilege management. This vulnerability is known as CVE-2026-65378. It is possible to launch the attack remotely. N...]]></description>
<link>https://tsecurity.de/de/4156337/sicherheitsluecken-cve/cve-2026-65378-apple-macos-up-to-15726266-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156337/sicherheitsluecken-cve/cve-2026-65378-apple-macos-up-to-15726266-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. The manipulation results in improper privilege management. This vulnerability is known as CVE-2026-65378. It is possible to launch the attack remotely. No exploit is available. You should upgrade the... <a href="https://vuldb.com/vuln/403861" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65357 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS up to 26.5 memory corruption]]></title>
<description><![CDATA[A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS up to 26.5 and classified as very critical. This affects an unknown part. Executing a manipulation can lead to memory corruption. The identification of this vulnerability is CVE-2026-65357. The attack can only be ex...]]></description>
<link>https://tsecurity.de/de/4156336/sicherheitsluecken-cve/cve-2026-65357-apple-ipadosiosmacostvosvisionoswatchos-up-to-265-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156336/sicherheitsluecken-cve/cve-2026-65357-apple-ipadosiosmacostvosvisionoswatchos-up-to-265-memory-corruption/</guid>
<pubDate>Sat, 19 Sep 2026 09:42:00 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS up to 26.5 and classified as very critical. This affects an unknown part. Executing a manipulation can lead to memory corruption. The identification of this vulnerability is CVE-2026-65357. The attack can only be executed locally. There is no exploit available. It is... <a href="https://vuldb.com/vuln/403835" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - ...]]></description>
<link>https://tsecurity.de/de/4156303/sicherheitsluecken-cve/cisa-flags-three-linux-kernel-vulnerabilities-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156303/sicherheitsluecken-cve/cisa-flags-three-linux-kernel-vulnerabilities-exploited-in-the-wild/</guid>
<pubDate>Sat, 19 Sep 2026 09:33:12 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional... <a href="https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-71641 | ZJU-FAST-Lab EGO-Planner-v2 EGOReplanFSM denial of service]]></title>
<description><![CDATA[A vulnerability was found in ZJU-FAST-Lab EGO-Planner-v2 and classified as problematic. Affected is an unknown function of the component EGOReplanFSM. Such manipulation leads to denial of service. This vulnerability is traded as CVE-2026-71641. The attack may be launched remotely. There is no exp...]]></description>
<link>https://tsecurity.de/de/4156273/sicherheitsluecken-cve/cve-2026-71641-zju-fast-lab-ego-planner-v2-egoreplanfsm-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156273/sicherheitsluecken-cve/cve-2026-71641-zju-fast-lab-ego-planner-v2-egoreplanfsm-denial-of-service/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in ZJU-FAST-Lab EGO-Planner-v2 and classified as problematic. Affected is an unknown function of the component EGOReplanFSM. Such manipulation leads to denial of service. This vulnerability is traded as CVE-2026-71641. The attack may be launched remotely. There is no exploit available. A patch should be applied to... <a href="https://vuldb.com/vuln/402435" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89060 | Red Hat Advanced Cluster Management for Kubernetes multicluster-observability-addon information disclosure]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Red Hat Advanced Cluster Management for Kubernetes. Affected by this issue is some unknown functionality of the component multicluster-observability-addon. The manipulation results in information disclosure. This vulnerability was...]]></description>
<link>https://tsecurity.de/de/4156272/sicherheitsluecken-cve/cve-2026-89060-red-hat-advanced-cluster-management-for-kubernetes-multicluster-observability-addon-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156272/sicherheitsluecken-cve/cve-2026-89060-red-hat-advanced-cluster-management-for-kubernetes-multicluster-observability-addon-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Red Hat Advanced Cluster Management for Kubernetes. Affected by this issue is some unknown functionality of the component multicluster-observability-addon. The manipulation results in information disclosure. This vulnerability was named CVE-2026-89060. The attack may be performed... <a href="https://vuldb.com/vuln/402349" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-82100 | IBM DataStage on Cloud Pak for Data 5.4.0.0 path traversal]]></title>
<description><![CDATA[A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0. It has been classified as problematic. This vulnerability affects unknown code. This manipulation causes path traversal. This vulnerability is registered as CVE-2026-82100. Remote exploitation of the attack is possible. No ...]]></description>
<link>https://tsecurity.de/de/4156271/sicherheitsluecken-cve/cve-2026-82100-ibm-datastage-on-cloud-pak-for-data-5400-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156271/sicherheitsluecken-cve/cve-2026-82100-ibm-datastage-on-cloud-pak-for-data-5400-path-traversal/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0. It has been classified as problematic. This vulnerability affects unknown code. This manipulation causes path traversal. This vulnerability is registered as CVE-2026-82100. Remote exploitation of the attack is possible. No exploit is available. <a href="https://vuldb.com/vuln/402296" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-78135 | strongSwan up to 6.0.7 libcharon improper authentication]]></title>
<description><![CDATA[A vulnerability was found in strongSwan up to 6.0.7. It has been declared as very critical. Affected is an unknown function of the component libcharon. The manipulation results in improper authentication. This vulnerability is cataloged as CVE-2026-78135. The attack may be launched remotely. Ther...]]></description>
<link>https://tsecurity.de/de/4156270/sicherheitsluecken-cve/cve-2026-78135-strongswan-up-to-607-libcharon-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156270/sicherheitsluecken-cve/cve-2026-78135-strongswan-up-to-607-libcharon-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in strongSwan up to 6.0.7. It has been declared as very critical. Affected is an unknown function of the component libcharon. The manipulation results in improper authentication. This vulnerability is cataloged as CVE-2026-78135. The attack may be launched remotely. There is no exploit available. It is recommended to... <a href="https://vuldb.com/vuln/402325" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43696 | Apple macOS up to 26 improper authorization]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Apple macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026-43696. An attack has to be approached locally. There is no exploi...]]></description>
<link>https://tsecurity.de/de/4156269/sicherheitsluecken-cve/cve-2026-43696-apple-macos-up-to-26-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156269/sicherheitsluecken-cve/cve-2026-43696-apple-macos-up-to-26-improper-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Apple macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026-43696. An attack has to be approached locally. There is no exploit available. It is suggested to upgrade the affected... <a href="https://vuldb.com/vuln/403800" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43674 | Apple iOS/iPadOS up to 26 improper authentication]]></title>
<description><![CDATA[A vulnerability was found in Apple iOS and iPadOS up to 26. It has been classified as problematic. Affected is an unknown function. This manipulation causes improper authentication. This vulnerability is registered as CVE-2026-43674. The attack needs to be launched locally. No exploit is availabl...]]></description>
<link>https://tsecurity.de/de/4156268/sicherheitsluecken-cve/cve-2026-43674-apple-iosipados-up-to-26-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156268/sicherheitsluecken-cve/cve-2026-43674-apple-iosipados-up-to-26-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iOS and iPadOS up to 26. It has been classified as problematic. Affected is an unknown function. This manipulation causes improper authentication. This vulnerability is registered as CVE-2026-43674. The attack needs to be launched locally. No exploit is available. Upgrading the affected component is recommended. <a href="https://vuldb.com/vuln/403766" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43762 | Apple iOS/iPadOS/macOS/visionOS up to 26.5 information disclosure]]></title>
<description><![CDATA[A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS up to 26.5. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-2026-43762. The attack must be carried out locally. There is...]]></description>
<link>https://tsecurity.de/de/4156267/sicherheitsluecken-cve/cve-2026-43762-apple-iosipadosmacosvisionos-up-to-265-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156267/sicherheitsluecken-cve/cve-2026-43762-apple-iosipadosmacosvisionos-up-to-265-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS up to 26.5. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-2026-43762. The attack must be carried out locally. There is no available exploit. It is recommended to upgrade... <a href="https://vuldb.com/vuln/403809" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43737 | Apple iOS/iPadOS/macOS/tvOS/watchOS prior 26.7/27/15.8 improper authorization]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Apple iOS, iPadOS, macOS, tvOS and watchOS. Impacted is an unknown function. Executing a manipulation can lead to improper authorization. The identification of this vulnerability is CVE-2026-43737. The attack can only be executed ...]]></description>
<link>https://tsecurity.de/de/4156266/sicherheitsluecken-cve/cve-2026-43737-apple-iosipadosmacostvoswatchos-prior-26727158-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156266/sicherheitsluecken-cve/cve-2026-43737-apple-iosipadosmacostvoswatchos-prior-26727158-improper-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Apple iOS, iPadOS, macOS, tvOS and watchOS. Impacted is an unknown function. Executing a manipulation can lead to improper authorization. The identification of this vulnerability is CVE-2026-43737. The attack can only be executed locally. There is no exploit available. You should... <a href="https://vuldb.com/vuln/403805" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43702 | Apple iPadOS/iOS/macOS/tvOS/watchOS Video File memory corruption]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Apple iPadOS, iOS, macOS, tvOS and watchOS. This issue affects some unknown processing of the component Video File Handler. Performing a manipulation results in memory corruption. This vulnerability was named CVE-2026-43702...]]></description>
<link>https://tsecurity.de/de/4156265/sicherheitsluecken-cve/cve-2026-43702-apple-ipadosiosmacostvoswatchos-video-file-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156265/sicherheitsluecken-cve/cve-2026-43702-apple-ipadosiosmacostvoswatchos-video-file-memory-corruption/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, has been found in Apple iPadOS, iOS, macOS, tvOS and watchOS. This issue affects some unknown processing of the component Video File Handler. Performing a manipulation results in memory corruption. This vulnerability was named CVE-2026-43702. The attack may be initiated remotely. There is no... <a href="https://vuldb.com/vuln/403804" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43719 | Apple macOS up to 15.7/26/26.6 SMB use after free]]></title>
<description><![CDATA[A vulnerability classified as very critical has been found in Apple macOS up to 15.7/26/26.6. This affects an unknown part of the component SMB Handler. This manipulation causes use after free. This vulnerability is handled as CVE-2026-43719. The attack can be initiated remotely. There is not any...]]></description>
<link>https://tsecurity.de/de/4156264/sicherheitsluecken-cve/cve-2026-43719-apple-macos-up-to-15726266-smb-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156264/sicherheitsluecken-cve/cve-2026-43719-apple-macos-up-to-15726266-smb-use-after-free/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical has been found in Apple macOS up to 15.7/26/26.6. This affects an unknown part of the component SMB Handler. This manipulation causes use after free. This vulnerability is handled as CVE-2026-43719. The attack can be initiated remotely. There is not any exploit available. It is recommended to upgrade the... <a href="https://vuldb.com/vuln/403802" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43695 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior prior iOS 27 improper authorization]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected is an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2026-43695. The attack may be performed from remote. There...]]></description>
<link>https://tsecurity.de/de/4156263/sicherheitsluecken-cve/cve-2026-43695-apple-ipadosiosmacostvosvisionoswatchos-prior-prior-ios-27-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156263/sicherheitsluecken-cve/cve-2026-43695-apple-ipadosiosmacostvosvisionoswatchos-prior-prior-ios-27-improper-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected is an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2026-43695. The attack may be performed from remote. There is no available exploit. The affected component... <a href="https://vuldb.com/vuln/403799" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43697 | Apple macOS up to 15.7/26/26.6 out-of-bounds]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes out-of-bounds read. This vulnerability is registered as CVE-2026-43697. Remote exploitation of the attack is possible. No exploit is...]]></description>
<link>https://tsecurity.de/de/4156262/sicherheitsluecken-cve/cve-2026-43697-apple-macos-up-to-15726266-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156262/sicherheitsluecken-cve/cve-2026-43697-apple-macos-up-to-15726266-out-of-bounds/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes out-of-bounds read. This vulnerability is registered as CVE-2026-43697. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component is... <a href="https://vuldb.com/vuln/403796" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43690 | Apple macOS up to 15.7/26/26.6 race condition]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Apple macOS up to 15.7/26/26.6. Affected by this issue is some unknown functionality. This manipulation causes race condition. The identification of this vulnerability is CVE-2026-43690. The attack can only be executed locall...]]></description>
<link>https://tsecurity.de/de/4156261/sicherheitsluecken-cve/cve-2026-43690-apple-macos-up-to-15726266-race-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156261/sicherheitsluecken-cve/cve-2026-43690-apple-macos-up-to-15726266-race-condition/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in Apple macOS up to 15.7/26/26.6. Affected by this issue is some unknown functionality. This manipulation causes race condition. The identification of this vulnerability is CVE-2026-43690. The attack can only be executed locally. There is no exploit available. It is advisable to... <a href="https://vuldb.com/vuln/403790" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43688 | Apple iOS/iPadOS/macOS up to 26 memory corruption]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Apple iOS, iPadOS and macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation results in memory corruption. This vulnerability was named CVE-2026-43688. The attack may be performed from remote. There is ...]]></description>
<link>https://tsecurity.de/de/4156260/sicherheitsluecken-cve/cve-2026-43688-apple-iosipadosmacos-up-to-26-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156260/sicherheitsluecken-cve/cve-2026-43688-apple-iosipadosmacos-up-to-26-memory-corruption/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical was found in Apple iOS, iPadOS and macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation results in memory corruption. This vulnerability was named CVE-2026-43688. The attack may be performed from remote. There is no available exploit. Upgrading the affected... <a href="https://vuldb.com/vuln/403789" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43683 | Apple macOS up to 15.7/26.6/26.x out-of-bounds]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Apple macOS up to 15.7/26.6/26.x. This affects an unknown function. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2026-43683. Attacking locally is a requirement. No exploit is available. It is...]]></description>
<link>https://tsecurity.de/de/4156259/sicherheitsluecken-cve/cve-2026-43683-apple-macos-up-to-15726626x-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156259/sicherheitsluecken-cve/cve-2026-43683-apple-macos-up-to-15726626x-out-of-bounds/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Apple macOS up to 15.7/26.6/26.x. This affects an unknown function. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2026-43683. Attacking locally is a requirement. No exploit is available. It is suggested to upgrade the affected component. <a href="https://vuldb.com/vuln/403786" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65348 | Apple iOS/iPadOS/macOS prior 26.7/27/15.8 permission]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Apple iOS, iPadOS and macOS. This affects an unknown function. Executing a manipulation can lead to permission issues. This vulnerability is registered as CVE-2026-65348. The attack needs to be launched locally. No exploit is available. The af...]]></description>
<link>https://tsecurity.de/de/4156258/sicherheitsluecken-cve/cve-2026-65348-apple-iosipadosmacos-prior-26727158-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156258/sicherheitsluecken-cve/cve-2026-65348-apple-iosipadosmacos-prior-26727158-permission/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in Apple iOS, iPadOS and macOS. This affects an unknown function. Executing a manipulation can lead to permission issues. This vulnerability is registered as CVE-2026-65348. The attack needs to be launched locally. No exploit is available. The affected component should be upgraded. <a href="https://vuldb.com/vuln/403841" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65354 | Apple iOS/iPadOS/macOS up to 26 sandbox]]></title>
<description><![CDATA[A vulnerability described as very critical has been identified in Apple iOS, iPadOS and macOS up to 26. Affected is an unknown function. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-65354. The attack can be launched remotely. No exploit exists. Upgrading t...]]></description>
<link>https://tsecurity.de/de/4156257/sicherheitsluecken-cve/cve-2026-65354-apple-iosipadosmacos-up-to-26-sandbox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156257/sicherheitsluecken-cve/cve-2026-65354-apple-iosipadosmacos-up-to-26-sandbox/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as very critical has been identified in Apple iOS, iPadOS and macOS up to 26. Affected is an unknown function. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-65354. The attack can be launched remotely. No exploit exists. Upgrading the affected component is recommended. <a href="https://vuldb.com/vuln/403843" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43785 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 27 privileges management]]></title>
<description><![CDATA[A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-43785. The attack can be executed remotely. The...]]></description>
<link>https://tsecurity.de/de/4156256/sicherheitsluecken-cve/cve-2026-43785-apple-iosipadosmacostvosvisionos-prior-27-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156256/sicherheitsluecken-cve/cve-2026-43785-apple-iosipadosmacostvosvisionos-prior-27-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-43785. The attack can be executed remotely. There is not any exploit available. It is suggested to... <a href="https://vuldb.com/vuln/403807" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43790 | Apple macOS up to 15.7/26/26.6 Kernel memory corruption]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Apple macOS up to 15.7/26/26.6. Affected by this vulnerability is an unknown functionality of the component Kernel. Executing a manipulation can lead to memory corruption. This vulnerability is registered as CVE-2026-43790. It is...]]></description>
<link>https://tsecurity.de/de/4156255/sicherheitsluecken-cve/cve-2026-43790-apple-macos-up-to-15726266-kernel-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156255/sicherheitsluecken-cve/cve-2026-43790-apple-macos-up-to-15726266-kernel-memory-corruption/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as very critical has been discovered in Apple macOS up to 15.7/26/26.6. Affected by this vulnerability is an unknown functionality of the component Kernel. Executing a manipulation can lead to memory corruption. This vulnerability is registered as CVE-2026-43790. It is possible to launch the attack remotely. No exploit... <a href="https://vuldb.com/vuln/403811" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65345 | Apple iOS/iPadOS/macOS prior 26.7/27/15.8 permission]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Apple iOS, iPadOS and macOS. The impacted element is an unknown function. Performing a manipulation results in permission issues. This vulnerability is cataloged as CVE-2026-65345. The attack must be initiated from a local position. T...]]></description>
<link>https://tsecurity.de/de/4156254/sicherheitsluecken-cve/cve-2026-65345-apple-iosipadosmacos-prior-26727158-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156254/sicherheitsluecken-cve/cve-2026-65345-apple-iosipadosmacos-prior-26727158-permission/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Apple iOS, iPadOS and macOS. The impacted element is an unknown function. Performing a manipulation results in permission issues. This vulnerability is cataloged as CVE-2026-65345. The attack must be initiated from a local position. There is no exploit available. You should upgrade the... <a href="https://vuldb.com/vuln/403840" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65344 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 26.7/27/15.8 out-of-bounds write]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Apple iOS, iPadOS, macOS, tvOS and visionOS. The affected element is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-65344. The attack may be performed from remote. Th...]]></description>
<link>https://tsecurity.de/de/4156253/sicherheitsluecken-cve/cve-2026-65344-apple-iosipadosmacostvosvisionos-prior-26727158-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156253/sicherheitsluecken-cve/cve-2026-65344-apple-iosipadosmacostvosvisionos-prior-26727158-out-of-bounds-write/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as very critical has been discovered in Apple iOS, iPadOS, macOS, tvOS and visionOS. The affected element is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-65344. The attack may be performed from remote. There is no available exploit. It is advisable to... <a href="https://vuldb.com/vuln/403839" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65342 | Apple macOS up to 15.7/26/26.6 permission]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. Impacted is an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2026-65342. The attack is restricted to local execution. No exploit exists. Upgrading th...]]></description>
<link>https://tsecurity.de/de/4156252/sicherheitsluecken-cve/cve-2026-65342-apple-macos-up-to-15726266-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156252/sicherheitsluecken-cve/cve-2026-65342-apple-macos-up-to-15726266-permission/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. Impacted is an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2026-65342. The attack is restricted to local execution. No exploit exists. Upgrading the affected component is advised. <a href="https://vuldb.com/vuln/403838" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43791 | Apple macOS up to 15.7/26/26.6 information disclosure]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to information disclosure. This vulnerability is tracked as CVE-2026-43791. The attack can be launched remotely...]]></description>
<link>https://tsecurity.de/de/4156251/sicherheitsluecken-cve/cve-2026-43791-apple-macos-up-to-15726266-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156251/sicherheitsluecken-cve/cve-2026-43791-apple-macos-up-to-15726266-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to information disclosure. This vulnerability is tracked as CVE-2026-43791. The attack can be launched remotely. No exploit exists. It is recommended to upgrade... <a href="https://vuldb.com/vuln/403823" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43808 | Apple iPadOS/iOS/macOS/tvOS/watchOS up to 26.5 use after free]]></title>
<description><![CDATA[A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS and watchOS up to 26.5. It has been rated as very critical. This affects an unknown part. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-43808. The attack may be initiated remotely. There is no availab...]]></description>
<link>https://tsecurity.de/de/4156250/sicherheitsluecken-cve/cve-2026-43808-apple-ipadosiosmacostvoswatchos-up-to-265-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156250/sicherheitsluecken-cve/cve-2026-43808-apple-ipadosiosmacostvoswatchos-up-to-265-use-after-free/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS and watchOS up to 26.5. It has been rated as very critical. This affects an unknown part. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-43808. The attack may be initiated remotely. There is no available exploit. Upgrading the affected component is... <a href="https://vuldb.com/vuln/403824" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43787 | Apple macOS up to 15.7/26/26.6 information disclosure]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-2026-43787. The attack can be executed remotely. There is not any e...]]></description>
<link>https://tsecurity.de/de/4156249/sicherheitsluecken-cve/cve-2026-43787-apple-macos-up-to-15726266-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156249/sicherheitsluecken-cve/cve-2026-43787-apple-macos-up-to-15726266-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-2026-43787. The attack can be executed remotely. There is not any exploit available. Upgrading the affected component... <a href="https://vuldb.com/vuln/403817" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43789 | Apple macOS up to 15.7/26/26.6 Sandbox privileges management]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Sandbox. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-43...]]></description>
<link>https://tsecurity.de/de/4156248/sicherheitsluecken-cve/cve-2026-43789-apple-macos-up-to-15726266-sandbox-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156248/sicherheitsluecken-cve/cve-2026-43789-apple-macos-up-to-15726266-sandbox-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 08:39:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Sandbox. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-43789. The attack can be initiated remotely. There is... <a href="https://vuldb.com/vuln/403822" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-80434 | IBM DataStage on Cloud Pak for Data 5.4.0.0 resource injection]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in IBM DataStage on Cloud Pak for Data 5.4.0.0. The affected element is an unknown function. Performing a manipulation results in improper control of resource identifiers. This vulnerability was named CVE-2026-80434. The attack may be initi...]]></description>
<link>https://tsecurity.de/de/4156193/sicherheitsluecken-cve/cve-2026-80434-ibm-datastage-on-cloud-pak-for-data-5400-resource-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156193/sicherheitsluecken-cve/cve-2026-80434-ibm-datastage-on-cloud-pak-for-data-5400-resource-injection/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in IBM DataStage on Cloud Pak for Data 5.4.0.0. The affected element is an unknown function. Performing a manipulation results in improper control of resource identifiers. This vulnerability was named CVE-2026-80434. The attack may be initiated remotely. There is no available exploit. <a href="https://vuldb.com/vuln/402244" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-88011 | Traefik up to 2.11.55/3.7.11 Header Normalization improper authentication]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Traefik up to 2.11.55/3.7.11. This issue affects some unknown processing of the component Header Normalization. The manipulation results in improper authentication. This vulnerability is known as CVE-2026-88011. It is possible to launch...]]></description>
<link>https://tsecurity.de/de/4156192/sicherheitsluecken-cve/cve-2026-88011-traefik-up-to-211553711-header-normalization-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156192/sicherheitsluecken-cve/cve-2026-88011-traefik-up-to-211553711-header-normalization-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in Traefik up to 2.11.55/3.7.11. This issue affects some unknown processing of the component Header Normalization. The manipulation results in improper authentication. This vulnerability is known as CVE-2026-88011. It is possible to launch the attack remotely. No exploit is available.... <a href="https://vuldb.com/vuln/402121" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-82092 | IBM DataStage on Cloud Pak for Data 5.4.0.0 path traversal]]></title>
<description><![CDATA[A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0 and classified as critical. This affects an unknown part. The manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-82092. The attack may be launched remotely. There is no exploit available. Wei...]]></description>
<link>https://tsecurity.de/de/4156191/sicherheitsluecken-cve/cve-2026-82092-ibm-datastage-on-cloud-pak-for-data-5400-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156191/sicherheitsluecken-cve/cve-2026-82092-ibm-datastage-on-cloud-pak-for-data-5400-path-traversal/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0 and classified as critical. This affects an unknown part. The manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-82092. The attack may be launched remotely. There is no exploit available. <a href="https://vuldb.com/vuln/402295" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81554 | IBM DataStage 5.4.0.0 path traversal]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, was found in IBM DataStage 5.4.0.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CVE-2026-81554. The attack can be launched remotely. No exp...]]></description>
<link>https://tsecurity.de/de/4156190/sicherheitsluecken-cve/cve-2026-81554-ibm-datastage-5400-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156190/sicherheitsluecken-cve/cve-2026-81554-ibm-datastage-5400-path-traversal/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, was found in IBM DataStage 5.4.0.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CVE-2026-81554. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/402293" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81551 | IBM DataStage on Cloud Pak for Data 5.4.0.0 path traversal]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in IBM DataStage on Cloud Pak for Data 5.4.0.0. Affected is an unknown function. Performing a manipulation results in path traversal. This vulnerability is identified as CVE-2026-81551. The attack can be initiated remotely. Th...]]></description>
<link>https://tsecurity.de/de/4156189/sicherheitsluecken-cve/cve-2026-81551-ibm-datastage-on-cloud-pak-for-data-5400-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156189/sicherheitsluecken-cve/cve-2026-81551-ibm-datastage-on-cloud-pak-for-data-5400-path-traversal/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, has been found in IBM DataStage on Cloud Pak for Data 5.4.0.0. Affected is an unknown function. Performing a manipulation results in path traversal. This vulnerability is identified as CVE-2026-81551. The attack can be initiated remotely. There is not any exploit available. <a href="https://vuldb.com/vuln/402292" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-80378 | IBM DataStage on Cloud Pak for Data 5.4.0.0 improper authorization]]></title>
<description><![CDATA[A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0 and classified as critical. This issue affects some unknown processing. The manipulation results in improper authorization. This vulnerability is reported as CVE-2026-80378. The attack can be launched remotely. No exploit ex...]]></description>
<link>https://tsecurity.de/de/4156188/sicherheitsluecken-cve/cve-2026-80378-ibm-datastage-on-cloud-pak-for-data-5400-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156188/sicherheitsluecken-cve/cve-2026-80378-ibm-datastage-on-cloud-pak-for-data-5400-improper-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0 and classified as critical. This issue affects some unknown processing. The manipulation results in improper authorization. This vulnerability is reported as CVE-2026-80378. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/402253" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9327 | IBM WebSphere Application Server 8.5/9.0 privileges management (WID-SEC-2026-3255)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in IBM WebSphere Application Server 8.5/9.0. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is reported as CVE-2026-9327. The attack can be launched remotely. N...]]></description>
<link>https://tsecurity.de/de/4156187/sicherheitsluecken-cve/cve-2026-9327-ibm-websphere-application-server-8590-privileges-management-wid-sec-2026-3255/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156187/sicherheitsluecken-cve/cve-2026-9327-ibm-websphere-application-server-8590-privileges-management-wid-sec-2026-3255/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in IBM WebSphere Application Server 8.5/9.0. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is reported as CVE-2026-9327. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/402223" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-52098 | FlowiseAI Flowise 3.1.2 /api/v1/prediction code injection]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in FlowiseAI Flowise 3.1.2. This vulnerability affects unknown code of the file /api/v1/prediction. Such manipulation leads to code injection. This vulnerability is uniquely identified as CVE-2026-52098. The attack can be launched remot...]]></description>
<link>https://tsecurity.de/de/4156186/sicherheitsluecken-cve/cve-2026-52098-flowiseai-flowise-312-apiv1prediction-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156186/sicherheitsluecken-cve/cve-2026-52098-flowiseai-flowise-312-apiv1prediction-code-injection/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in FlowiseAI Flowise 3.1.2. This vulnerability affects unknown code of the file /api/v1/prediction. Such manipulation leads to code injection. This vulnerability is uniquely identified as CVE-2026-52098. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/402153" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14276 | IBM i Access Family up to 1.1.9.15 Emulator Macro RunProgram os command injection]]></title>
<description><![CDATA[A vulnerability classified as critical was found in IBM i Access Family up to 1.1.9.15. This affects the function RunProgram of the component Emulator Macro. Executing a manipulation can lead to os command injection. The identification of this vulnerability is CVE-2026-14276. The attack may be la...]]></description>
<link>https://tsecurity.de/de/4156185/sicherheitsluecken-cve/cve-2026-14276-ibm-i-access-family-up-to-11915-emulator-macro-runprogram-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156185/sicherheitsluecken-cve/cve-2026-14276-ibm-i-access-family-up-to-11915-emulator-macro-runprogram-os-command-injection/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in IBM i Access Family up to 1.1.9.15. This affects the function RunProgram of the component Emulator Macro. Executing a manipulation can lead to os command injection. The identification of this vulnerability is CVE-2026-14276. The attack may be launched remotely. There is no exploit available. <a href="https://vuldb.com/vuln/403775" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19542 | GNU glibc tdelete memory corruption (WID-SEC-2026-3014)]]></title>
<description><![CDATA[A vulnerability identified as very critical has been detected in GNU glibc. Impacted is the function tdelete. The manipulation leads to memory corruption. This vulnerability is traded as CVE-2026-19542. It is possible to initiate the attack remotely. There is no exploit available. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4156184/sicherheitsluecken-cve/cve-2026-19542-gnu-glibc-tdelete-memory-corruption-wid-sec-2026-3014/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156184/sicherheitsluecken-cve/cve-2026-19542-gnu-glibc-tdelete-memory-corruption-wid-sec-2026-3014/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as very critical has been detected in GNU glibc. Impacted is the function tdelete. The manipulation leads to memory corruption. This vulnerability is traded as CVE-2026-19542. It is possible to initiate the attack remotely. There is no exploit available. <a href="https://vuldb.com/vuln/394950" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13285 | IBM MQ up to 10.0.0.0 xml external entity reference]]></title>
<description><![CDATA[A vulnerability was found in IBM MQ up to 10.0.0.0 and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to xml external entity reference. This vulnerability is listed as CVE-2026-13285. The attack may be performed from remote. There is no avail...]]></description>
<link>https://tsecurity.de/de/4156183/sicherheitsluecken-cve/cve-2026-13285-ibm-mq-up-to-10000-xml-external-entity-reference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156183/sicherheitsluecken-cve/cve-2026-13285-ibm-mq-up-to-10000-xml-external-entity-reference/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in IBM MQ up to 10.0.0.0 and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to xml external entity reference. This vulnerability is listed as CVE-2026-13285. The attack may be performed from remote. There is no available exploit. <a href="https://vuldb.com/vuln/403779" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18119 | Concrete CMS up to 9.5.2 Block Design Dialog cross site scripting]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Concrete CMS up to 9.5.2. Affected is an unknown function of the component Block Design Dialog. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2026-18119. The attack can be launched remotely. N...]]></description>
<link>https://tsecurity.de/de/4156182/sicherheitsluecken-cve/cve-2026-18119-concrete-cms-up-to-952-block-design-dialog-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156182/sicherheitsluecken-cve/cve-2026-18119-concrete-cms-up-to-952-block-design-dialog-cross-site-scripting/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Concrete CMS up to 9.5.2. Affected is an unknown function of the component Block Design Dialog. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2026-18119. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/403733" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28836 | Apple macOS up to 14.8.7 privileges management]]></title>
<description><![CDATA[A vulnerability was found in Apple macOS up to 14.8.7. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to improper privilege management. This vulnerability is documented as CVE-2026-28836. The attack needs to be performed locally. There i...]]></description>
<link>https://tsecurity.de/de/4156181/sicherheitsluecken-cve/cve-2026-28836-apple-macos-up-to-1487-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156181/sicherheitsluecken-cve/cve-2026-28836-apple-macos-up-to-1487-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple macOS up to 14.8.7. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to improper privilege management. This vulnerability is documented as CVE-2026-28836. The attack needs to be performed locally. There is not any exploit available. Upgrading the affected... <a href="https://vuldb.com/vuln/403752" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14275 | IBM i Access Family up to 1.1.9.15 os command injection]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in IBM i Access Family up to 1.1.9.15. The impacted element is an unknown function. Performing a manipulation results in os command injection. This vulnerability was named CVE-2026-14275. The attack may be initiated remotely. There is no avail...]]></description>
<link>https://tsecurity.de/de/4156180/sicherheitsluecken-cve/cve-2026-14275-ibm-i-access-family-up-to-11915-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156180/sicherheitsluecken-cve/cve-2026-14275-ibm-i-access-family-up-to-11915-os-command-injection/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in IBM i Access Family up to 1.1.9.15. The impacted element is an unknown function. Performing a manipulation results in os command injection. This vulnerability was named CVE-2026-14275. The attack may be initiated remotely. There is no available exploit. <a href="https://vuldb.com/vuln/403774" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28938 | Apple iOS/iPadOS up to 26.5 information disclosure]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Apple iOS and iPadOS up to 26.5. This issue affects some unknown processing. The manipulation results in information disclosure. This vulnerability is known as CVE-2026-28938. Attacking locally is a requirement. No exploit is available. The...]]></description>
<link>https://tsecurity.de/de/4156179/sicherheitsluecken-cve/cve-2026-28938-apple-iosipados-up-to-265-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156179/sicherheitsluecken-cve/cve-2026-28938-apple-iosipados-up-to-265-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in Apple iOS and iPadOS up to 26.5. This issue affects some unknown processing. The manipulation results in information disclosure. This vulnerability is known as CVE-2026-28938. Attacking locally is a requirement. No exploit is available. The affected component should be upgraded. <a href="https://vuldb.com/vuln/403771" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28937 | Apple macOS up to 26 information disclosure]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Apple macOS up to 26. This vulnerability affects unknown code. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2026-28937. It is possible to initiate the attack remotely. There is no exploit avail...]]></description>
<link>https://tsecurity.de/de/4156178/sicherheitsluecken-cve/cve-2026-28937-apple-macos-up-to-26-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156178/sicherheitsluecken-cve/cve-2026-28937-apple-macos-up-to-26-information-disclosure/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Apple macOS up to 26. This vulnerability affects unknown code. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2026-28937. It is possible to initiate the attack remotely. There is no exploit available. You should upgrade the affected component. <a href="https://vuldb.com/vuln/403770" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28899 | Apple macOS up to 15.7/26/26.5/26.6 Gatekeeper privileges management]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Apple macOS up to 15.7/26/26.5/26.6. The affected element is an unknown function of the component Gatekeeper. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/4156177/sicherheitsluecken-cve/cve-2026-28899-apple-macos-up-to-15726265266-gatekeeper-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156177/sicherheitsluecken-cve/cve-2026-28899-apple-macos-up-to-15726265266-gatekeeper-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, has been found in Apple macOS up to 15.7/26/26.5/26.6. The affected element is an unknown function of the component Gatekeeper. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-28899. The attack can be initiated remotely. There... <a href="https://vuldb.com/vuln/403762" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28966 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 26.7/27/15.8 out-of-bounds write]]></title>
<description><![CDATA[A vulnerability has been found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. This affects an unknown function. The manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-28966. The attack may be initiated remotely. There is no available ex...]]></description>
<link>https://tsecurity.de/de/4156176/sicherheitsluecken-cve/cve-2026-28966-apple-iosipadosmacostvosvisionos-prior-26727158-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156176/sicherheitsluecken-cve/cve-2026-28966-apple-iosipadosmacostvosvisionos-prior-26727158-out-of-bounds-write/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. This affects an unknown function. The manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-28966. The attack may be initiated remotely. There is no available exploit. The affected component should be upgraded. <a href="https://vuldb.com/vuln/403764" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28935 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior 27 memory corruption]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. This issue affects some unknown processing. This manipulation causes memory corruption. The identification of this vulnerability is CVE-2026-28935. The attack can only be executed locall...]]></description>
<link>https://tsecurity.de/de/4156175/sicherheitsluecken-cve/cve-2026-28935-apple-ipadosiosmacostvosvisionoswatchos-prior-27-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156175/sicherheitsluecken-cve/cve-2026-28935-apple-ipadosiosmacostvosvisionoswatchos-prior-27-memory-corruption/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. This issue affects some unknown processing. This manipulation causes memory corruption. The identification of this vulnerability is CVE-2026-28935. The attack can only be executed locally. There is no exploit available. It is recommended... <a href="https://vuldb.com/vuln/403760" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28968 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.7/27 out-of-bounds write]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Impacted is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is referenced as CVE-2026-28968. It is possible to launch the attack remotely. No expl...]]></description>
<link>https://tsecurity.de/de/4156174/sicherheitsluecken-cve/cve-2026-28968-apple-iosipadosmacostvosvisionoswatchos-prior-26727-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156174/sicherheitsluecken-cve/cve-2026-28968-apple-iosipadosmacostvosvisionoswatchos-prior-26727-out-of-bounds-write/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Impacted is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is referenced as CVE-2026-28968. It is possible to launch the attack remotely. No exploit is available. Upgrading the affected component... <a href="https://vuldb.com/vuln/403761" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20683 | Apple iOS/iPadOS/macOS/visionOS prior 27/15.8/26.7 improper authentication]]></title>
<description><![CDATA[A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS. It has been declared as critical. This affects an unknown function. The manipulation results in improper authentication. This vulnerability is reported as CVE-2026-20683. The attack can be launched remotely. No exploit exists. It...]]></description>
<link>https://tsecurity.de/de/4156173/sicherheitsluecken-cve/cve-2026-20683-apple-iosipadosmacosvisionos-prior-27158267-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156173/sicherheitsluecken-cve/cve-2026-20683-apple-iosipadosmacosvisionos-prior-27158267-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 07:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS. It has been declared as critical. This affects an unknown function. The manipulation results in improper authentication. This vulnerability is reported as CVE-2026-20683. The attack can be launched remotely. No exploit exists. It is recommended to upgrade the affected component. <a href="https://vuldb.com/vuln/403753" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link]]></title>
<description><![CDATA[WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-...]]></description>
<link>https://tsecurity.de/de/4156152/sicherheitsluecken-cve/click2shell-wordpress-flaw-lets-attackers-gain-rce-with-a-single-malicious-link/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156152/sicherheitsluecken-cve/click2shell-wordpress-flaw-lets-attackers-gain-rce-with-a-single-malicious-link/</guid>
<pubDate>Sat, 19 Sep 2026 07:21:25 +0200</pubDate>
<content:encoded><![CDATA[<p>WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then... <a href="https://cybersecuritynews.com/click2shell-wordpress-vulnerability/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-47753 | LXC Incus up to 7.0.x Backup backend.go (*backend).CreateInstanceFromBackup null pointer dereference]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in LXC Incus up to 7.0.x. This affects the function (*backend).CreateInstanceFromBackup of the file internal/server/storage/backend.go of the component Backup Handler. The manipulation results in null pointer dereference. This vulnerabi...]]></description>
<link>https://tsecurity.de/de/4156126/sicherheitsluecken-cve/cve-2026-47753-lxc-incus-up-to-70x-backup-backendgo-backendcreateinstancefrombackup-null-pointer-dereference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156126/sicherheitsluecken-cve/cve-2026-47753-lxc-incus-up-to-70x-backup-backendgo-backendcreateinstancefrombackup-null-pointer-dereference/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in LXC Incus up to 7.0.x. This affects the function (*backend).CreateInstanceFromBackup of the file internal/server/storage/backend.go of the component Backup Handler. The manipulation results in null pointer dereference. This vulnerability is identified as CVE-2026-47753. The attack can... <a href="https://vuldb.com/vuln/394117" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-75033 | SUSE Rancher up to 2.15.0 Namespace Creation authorization]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in SUSE Rancher up to 2.15.0. Affected is an unknown function of the component Namespace Creation. Executing a manipulation can lead to authorization bypass. This vulnerability is tracked as CVE-2026-75033. The attack can be launched re...]]></description>
<link>https://tsecurity.de/de/4156125/sicherheitsluecken-cve/cve-2026-75033-suse-rancher-up-to-2150-namespace-creation-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156125/sicherheitsluecken-cve/cve-2026-75033-suse-rancher-up-to-2150-namespace-creation-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in SUSE Rancher up to 2.15.0. Affected is an unknown function of the component Namespace Creation. Executing a manipulation can lead to authorization bypass. This vulnerability is tracked as CVE-2026-75033. The attack can be launched remotely. No exploit exists. Upgrading the affected... <a href="https://vuldb.com/vuln/398453" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-71403 | SUSE Rancher up to 2.15.0 User Update username/principalIds privileges management]]></title>
<description><![CDATA[A vulnerability was found in SUSE Rancher up to 2.15.0. It has been declared as problematic. This issue affects some unknown processing of the component User Update. Executing a manipulation of the argument username/principalIds can lead to improper privilege management. This vulnerability is han...]]></description>
<link>https://tsecurity.de/de/4156124/sicherheitsluecken-cve/cve-2026-71403-suse-rancher-up-to-2150-user-update-usernameprincipalids-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156124/sicherheitsluecken-cve/cve-2026-71403-suse-rancher-up-to-2150-user-update-usernameprincipalids-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in SUSE Rancher up to 2.15.0. It has been declared as problematic. This issue affects some unknown processing of the component User Update. Executing a manipulation of the argument username/principalIds can lead to improper privilege management. This vulnerability is handled as CVE-2026-71403. The attack can be executed... <a href="https://vuldb.com/vuln/398447" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-85170 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Mail Composer server-side request forgery]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in n8n-io n8n. Impacted is an unknown function of the component Mail Composer. Executing a manipulation can lead to server-side request forgery. This vulnerability is tracked as CVE-2026-85170. The attack can be launched remotely. No exp...]]></description>
<link>https://tsecurity.de/de/4156123/sicherheitsluecken-cve/cve-2026-85170-n8n-io-n8n-prior-11237323542362-mail-composer-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156123/sicherheitsluecken-cve/cve-2026-85170-n8n-io-n8n-prior-11237323542362-mail-composer-server-side-request-forgery/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as critical has been discovered in n8n-io n8n. Impacted is an unknown function of the component Mail Composer. Executing a manipulation can lead to server-side request forgery. This vulnerability is tracked as CVE-2026-85170. The attack can be launched remotely. No exploit exists. It is advisable to upgrade the affected... <a href="https://vuldb.com/vuln/398393" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-85169 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 $fromAI handler sandbox]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in n8n-io n8n. The affected element is the function $fromAI of the component $fromAI handler. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-85169. The attack can be launched remotely. No exploit exis...]]></description>
<link>https://tsecurity.de/de/4156122/sicherheitsluecken-cve/cve-2026-85169-n8n-io-n8n-prior-11237323542362-fromai-handler-sandbox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156122/sicherheitsluecken-cve/cve-2026-85169-n8n-io-n8n-prior-11237323542362-fromai-handler-sandbox/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in n8n-io n8n. The affected element is the function $fromAI of the component $fromAI handler. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-85169. The attack can be launched remotely. No exploit exists. Upgrading the affected component is recommended. <a href="https://vuldb.com/vuln/398383" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48754 | lxc incus up to 7.0.0 createDependentVolumesFromBackup null pointer dereference]]></title>
<description><![CDATA[A vulnerability was found in lxc incus up to 7.0.0 and classified as problematic. Affected by this vulnerability is the function createDependentVolumesFromBackup. Executing a manipulation can lead to null pointer dereference. This vulnerability is registered as CVE-2026-48754. It is possible to l...]]></description>
<link>https://tsecurity.de/de/4156121/sicherheitsluecken-cve/cve-2026-48754-lxc-incus-up-to-700-createdependentvolumesfrombackup-null-pointer-dereference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156121/sicherheitsluecken-cve/cve-2026-48754-lxc-incus-up-to-700-createdependentvolumesfrombackup-null-pointer-dereference/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in lxc incus up to 7.0.0 and classified as problematic. Affected by this vulnerability is the function createDependentVolumesFromBackup. Executing a manipulation can lead to null pointer dereference. This vulnerability is registered as CVE-2026-48754. It is possible to launch the attack remotely. No exploit is available.... <a href="https://vuldb.com/vuln/374771" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44252 | Wazuh up to 4.14.4 Manager ossec.conf privileges management]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Wazuh up to 4.14.4. The affected element is an unknown function of the file ossec.conf of the component Manager. Executing a manipulation can lead to improper privilege management. This vulnerability is registered as CVE-2026-44252. It is p...]]></description>
<link>https://tsecurity.de/de/4156120/sicherheitsluecken-cve/cve-2026-44252-wazuh-up-to-4144-manager-ossecconf-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156120/sicherheitsluecken-cve/cve-2026-44252-wazuh-up-to-4144-manager-ossecconf-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical was found in Wazuh up to 4.14.4. The affected element is an unknown function of the file ossec.conf of the component Manager. Executing a manipulation can lead to improper privilege management. This vulnerability is registered as CVE-2026-44252. It is possible to launch the attack remotely. No exploit is... <a href="https://vuldb.com/vuln/393191" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46343 | Wazuh up to 4.14.5/5.0.0-beta1 Cluster Common common.py WazuhCommon.end_receiving_file path traversal]]></title>
<description><![CDATA[A vulnerability has been found in Wazuh up to 4.14.5/5.0.0-beta1 and classified as very critical. This impacts the function WazuhCommon.end_receiving_file of the file framework/wazuh/core/cluster/common.py of the component Cluster Common. This manipulation causes path traversal. This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/4156119/sicherheitsluecken-cve/cve-2026-46343-wazuh-up-to-4145500-beta1-cluster-common-commonpy-wazuhcommonendreceivingfile-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156119/sicherheitsluecken-cve/cve-2026-46343-wazuh-up-to-4145500-beta1-cluster-common-commonpy-wazuhcommonendreceivingfile-path-traversal/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Wazuh up to 4.14.5/5.0.0-beta1 and classified as very critical. This impacts the function WazuhCommon.end_receiving_file of the file framework/wazuh/core/cluster/common.py of the component Cluster Common. This manipulation causes path traversal. This vulnerability appears as CVE-2026-46343. The attack may be... <a href="https://vuldb.com/vuln/393194" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48756 | lxc incus up to 7.0.0 CreateCustomVolumeFromBackup null pointer dereference]]></title>
<description><![CDATA[A vulnerability was found in lxc incus up to 7.0.0. It has been classified as problematic. Affected by this issue is the function CreateCustomVolumeFromBackup. The manipulation leads to null pointer dereference. This vulnerability is documented as CVE-2026-48756. The attack can be initiated remot...]]></description>
<link>https://tsecurity.de/de/4156118/sicherheitsluecken-cve/cve-2026-48756-lxc-incus-up-to-700-createcustomvolumefrombackup-null-pointer-dereference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156118/sicherheitsluecken-cve/cve-2026-48756-lxc-incus-up-to-700-createcustomvolumefrombackup-null-pointer-dereference/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in lxc incus up to 7.0.0. It has been classified as problematic. Affected by this issue is the function CreateCustomVolumeFromBackup. The manipulation leads to null pointer dereference. This vulnerability is documented as CVE-2026-48756. The attack can be initiated remotely. There is not any exploit available. Upgrading... <a href="https://vuldb.com/vuln/374772" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-70657 | 9001 Copyparty up to 1.20.16 access control]]></title>
<description><![CDATA[A vulnerability was found in 9001 Copyparty up to 1.20.16. It has been classified as problematic. This issue affects some unknown processing. Performing a manipulation results in improper access controls. This vulnerability is known as CVE-2026-70657. Remote exploitation of the attack is possible...]]></description>
<link>https://tsecurity.de/de/4156117/sicherheitsluecken-cve/cve-2026-70657-9001-copyparty-up-to-12016-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156117/sicherheitsluecken-cve/cve-2026-70657-9001-copyparty-up-to-12016-access-control/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in 9001 Copyparty up to 1.20.16. It has been classified as problematic. This issue affects some unknown processing. Performing a manipulation results in improper access controls. This vulnerability is known as CVE-2026-70657. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected... <a href="https://vuldb.com/vuln/391726" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-74761 | Apache ActiveMQ improper authentication]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Apache ActiveMQ. The impacted element is an unknown function. Executing a manipulation can lead to improper authentication. This vulnerability appears as CVE-2026-74761. The attack may be performed from remote. There is no available exploit. Wei...]]></description>
<link>https://tsecurity.de/de/4156116/sicherheitsluecken-cve/cve-2026-74761-apache-activemq-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156116/sicherheitsluecken-cve/cve-2026-74761-apache-activemq-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in Apache ActiveMQ. The impacted element is an unknown function. Executing a manipulation can lead to improper authentication. This vulnerability appears as CVE-2026-74761. The attack may be performed from remote. There is no available exploit. <a href="https://vuldb.com/vuln/399869" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-75035 | SUSE Rancher up to 2.15.0 Token store privileges management]]></title>
<description><![CDATA[A vulnerability was found in SUSE Rancher up to 2.15.0. It has been rated as problematic. This affects an unknown function of the component Token store. This manipulation causes improper privilege management. This vulnerability is handled as CVE-2026-75035. The attack can be initiated remotely. T...]]></description>
<link>https://tsecurity.de/de/4156115/sicherheitsluecken-cve/cve-2026-75035-suse-rancher-up-to-2150-token-store-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156115/sicherheitsluecken-cve/cve-2026-75035-suse-rancher-up-to-2150-token-store-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in SUSE Rancher up to 2.15.0. It has been rated as problematic. This affects an unknown function of the component Token store. This manipulation causes improper privilege management. This vulnerability is handled as CVE-2026-75035. The attack can be initiated remotely. There is not any exploit available. Upgrading the... <a href="https://vuldb.com/vuln/398462" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67593 | Apache ActiveMQ Artemis Openwire Protocol authorization]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Apache ActiveMQ Artemis. This affects an unknown part of the component Openwire Protocol. Executing a manipulation can lead to missing authorization. This vulnerability is registered as CVE-2026-67593. It is possible to launch the att...]]></description>
<link>https://tsecurity.de/de/4156114/sicherheitsluecken-cve/cve-2026-67593-apache-activemq-artemis-openwire-protocol-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156114/sicherheitsluecken-cve/cve-2026-67593-apache-activemq-artemis-openwire-protocol-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as critical has been discovered in Apache ActiveMQ Artemis. This affects an unknown part of the component Openwire Protocol. Executing a manipulation can lead to missing authorization. This vulnerability is registered as CVE-2026-67593. It is possible to launch the attack remotely. No exploit is available. <a href="https://vuldb.com/vuln/401921" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-57967 | Apache ActiveMQ Artemis missing authentication]]></title>
<description><![CDATA[A vulnerability was found in Apache ActiveMQ Artemis. It has been rated as very critical. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authentication. This vulnerability is cataloged as CVE-2026-57967. It is possible to initiate the attack rem...]]></description>
<link>https://tsecurity.de/de/4156113/sicherheitsluecken-cve/cve-2026-57967-apache-activemq-artemis-missing-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156113/sicherheitsluecken-cve/cve-2026-57967-apache-activemq-artemis-missing-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Apache ActiveMQ Artemis. It has been rated as very critical. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authentication. This vulnerability is cataloged as CVE-2026-57967. It is possible to initiate the attack remotely. There is no exploit available. <a href="https://vuldb.com/vuln/401920" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-87544 | Google Chrome up to 152.0.7977.82 Extensions improper authorization]]></title>
<description><![CDATA[A vulnerability was found in Google Chrome. It has been classified as critical. This impacts an unknown function of the component Extensions. This manipulation causes improper authorization. This vulnerability is registered as CVE-2026-87544. Remote exploitation of the attack is possible. No expl...]]></description>
<link>https://tsecurity.de/de/4156112/sicherheitsluecken-cve/cve-2026-87544-google-chrome-up-to-1520797782-extensions-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156112/sicherheitsluecken-cve/cve-2026-87544-google-chrome-up-to-1520797782-extensions-improper-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Google Chrome. It has been classified as critical. This impacts an unknown function of the component Extensions. This manipulation causes improper authorization. This vulnerability is registered as CVE-2026-87544. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component... <a href="https://vuldb.com/vuln/401246" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12647 | Ivanti Neurons for ITSM up to 2026.1 missing authentication]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Ivanti Neurons for ITSM up to 2026.1. Impacted is an unknown function. Such manipulation leads to missing authentication. This vulnerability is documented as CVE-2026-12647. The attack can be executed remotely. There is not any exploit ...]]></description>
<link>https://tsecurity.de/de/4156111/sicherheitsluecken-cve/cve-2026-12647-ivanti-neurons-for-itsm-up-to-20261-missing-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156111/sicherheitsluecken-cve/cve-2026-12647-ivanti-neurons-for-itsm-up-to-20261-missing-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in Ivanti Neurons for ITSM up to 2026.1. Impacted is an unknown function. Such manipulation leads to missing authentication. This vulnerability is documented as CVE-2026-12647. The attack can be executed remotely. There is not any exploit available. Upgrading the affected component is... <a href="https://vuldb.com/vuln/399867" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12650 | Ivanti Neurons for ITSM up to 2026.1 deserialization]]></title>
<description><![CDATA[A vulnerability was found in Ivanti Neurons for ITSM up to 2026.1 and classified as critical. This affects an unknown function. The manipulation results in deserialization. This vulnerability was named CVE-2026-12650. The attack may be performed from remote. There is no available exploit. It is s...]]></description>
<link>https://tsecurity.de/de/4156110/sicherheitsluecken-cve/cve-2026-12650-ivanti-neurons-for-itsm-up-to-20261-deserialization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156110/sicherheitsluecken-cve/cve-2026-12650-ivanti-neurons-for-itsm-up-to-20261-deserialization/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Ivanti Neurons for ITSM up to 2026.1 and classified as critical. This affects an unknown function. The manipulation results in deserialization. This vulnerability was named CVE-2026-12650. The attack may be performed from remote. There is no available exploit. It is suggested to upgrade the affected component. <a href="https://vuldb.com/vuln/399859" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12646 | Ivanti Neurons for ITSM up to 2026.1 missing authentication]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Ivanti Neurons for ITSM up to 2026.1. The affected element is an unknown function. Executing a manipulation can lead to missing authentication. This vulnerability is handled as CVE-2026-12646. The attack can be executed remotely. The...]]></description>
<link>https://tsecurity.de/de/4156109/sicherheitsluecken-cve/cve-2026-12646-ivanti-neurons-for-itsm-up-to-20261-missing-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156109/sicherheitsluecken-cve/cve-2026-12646-ivanti-neurons-for-itsm-up-to-20261-missing-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in Ivanti Neurons for ITSM up to 2026.1. The affected element is an unknown function. Executing a manipulation can lead to missing authentication. This vulnerability is handled as CVE-2026-12646. The attack can be executed remotely. There is not any exploit available. You should upgrade... <a href="https://vuldb.com/vuln/399857" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12645 | Ivanti Neurons for ITSM up to 2026.1 missing authentication (CNNVD-2026-98054320)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Ivanti Neurons for ITSM up to 2026.1. Impacted is an unknown function. Performing a manipulation results in missing authentication. This vulnerability is known as CVE-2026-12645. Remote exploitation of the attack is possible. No...]]></description>
<link>https://tsecurity.de/de/4156108/sicherheitsluecken-cve/cve-2026-12645-ivanti-neurons-for-itsm-up-to-20261-missing-authentication-cnnvd-2026-98054320/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156108/sicherheitsluecken-cve/cve-2026-12645-ivanti-neurons-for-itsm-up-to-20261-missing-authentication-cnnvd-2026-98054320/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, has been found in Ivanti Neurons for ITSM up to 2026.1. Impacted is an unknown function. Performing a manipulation results in missing authentication. This vulnerability is known as CVE-2026-12645. Remote exploitation of the attack is possible. No exploit is available. It is advisable to upgrade... <a href="https://vuldb.com/vuln/399856" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-86426 | LibreNMS up to 26.7.x REST API improper authentication]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in LibreNMS up to 26.7.x. Affected is an unknown function of the component REST API. Performing a manipulation results in improper authentication. This vulnerability is known as CVE-2026-86426. Remote exploitation of the attack is possible. No ...]]></description>
<link>https://tsecurity.de/de/4156107/sicherheitsluecken-cve/cve-2026-86426-librenms-up-to-267x-rest-api-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156107/sicherheitsluecken-cve/cve-2026-86426-librenms-up-to-267x-rest-api-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in LibreNMS up to 26.7.x. Affected is an unknown function of the component REST API. Performing a manipulation results in improper authentication. This vulnerability is known as CVE-2026-86426. Remote exploitation of the attack is possible. No exploit is available. It is suggested to upgrade the... <a href="https://vuldb.com/vuln/399586" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90803 | GNU Binutils 2.47 ld bfd/elf64-x86-64.c elf_x86_64_relocate_section roff buffer overflow (Bug 34444)]]></title>
<description><![CDATA[A vulnerability was found in GNU Binutils 2.47. It has been declared as problematic. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. This vulnerability i...]]></description>
<link>https://tsecurity.de/de/4156106/sicherheitsluecken-cve/cve-2026-90803-gnu-binutils-247-ld-bfdelf64-x86-64c-elfx8664relocatesection-roff-buffer-overflow-bug-34444/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156106/sicherheitsluecken-cve/cve-2026-90803-gnu-binutils-247-ld-bfdelf64-x86-64c-elfx8664relocatesection-roff-buffer-overflow-bug-34444/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in GNU Binutils 2.47. It has been declared as problematic. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. This vulnerability is traded as CVE-2026-90803. An attack has to be... <a href="https://vuldb.com/vuln/403305" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89013 | Dolibarr up to 23.0.4 Document Storage Endpoints htdocs/document.php hashp authorization]]></title>
<description><![CDATA[A vulnerability was found in Dolibarr up to 23.0.4. It has been rated as problematic. This affects an unknown function of the file htdocs/document.php of the component Document Storage Endpoints. Performing a manipulation of the argument hashp results in authorization bypass. This vulnerability i...]]></description>
<link>https://tsecurity.de/de/4156105/sicherheitsluecken-cve/cve-2026-89013-dolibarr-up-to-2304-document-storage-endpoints-htdocsdocumentphp-hashp-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156105/sicherheitsluecken-cve/cve-2026-89013-dolibarr-up-to-2304-document-storage-endpoints-htdocsdocumentphp-hashp-authorization/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Dolibarr up to 23.0.4. It has been rated as problematic. This affects an unknown function of the file htdocs/document.php of the component Document Storage Endpoints. Performing a manipulation of the argument hashp results in authorization bypass. This vulnerability is known as CVE-2026-89013. Remote exploitation of... <a href="https://vuldb.com/vuln/402466" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90802 | GNU Binutils 2.47 ld bfd/libbfd.c bfd_putl64 null pointer dereference (Bug 34443)]]></title>
<description><![CDATA[A vulnerability was found in GNU Binutils 2.47. It has been classified as problematic. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. This vulnerability appears as CVE-2026-90802. The attack requires local acces...]]></description>
<link>https://tsecurity.de/de/4156104/sicherheitsluecken-cve/cve-2026-90802-gnu-binutils-247-ld-bfdlibbfdc-bfdputl64-null-pointer-dereference-bug-34443/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156104/sicherheitsluecken-cve/cve-2026-90802-gnu-binutils-247-ld-bfdlibbfdc-bfdputl64-null-pointer-dereference-bug-34443/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in GNU Binutils 2.47. It has been classified as problematic. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. This vulnerability appears as CVE-2026-90802. The attack requires local access. In addition, an exploit is available. The project... <a href="https://vuldb.com/vuln/403304" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-90801 | GNU Binutils 2.47 ld bfd/cache.c cache_bwrite nbytes buffer overflow (Bug 34442)]]></title>
<description><![CDATA[A vulnerability was found in GNU Binutils 2.47 and classified as problematic. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. This vulnerability is reported as CVE-2026-90801. The attack requir...]]></description>
<link>https://tsecurity.de/de/4156103/sicherheitsluecken-cve/cve-2026-90801-gnu-binutils-247-ld-bfdcachec-cachebwrite-nbytes-buffer-overflow-bug-34442/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156103/sicherheitsluecken-cve/cve-2026-90801-gnu-binutils-247-ld-bfdcachec-cachebwrite-nbytes-buffer-overflow-bug-34442/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in GNU Binutils 2.47 and classified as problematic. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. This vulnerability is reported as CVE-2026-90801. The attack requires a local approach. Moreover, an exploit is... <a href="https://vuldb.com/vuln/403303" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81917 | Concrete CMS up to 9.5.2 Document Library block cross site scripting]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Concrete CMS up to 9.5.2. This vulnerability affects unknown code of the component Document Library block. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2026-81917. The attack can b...]]></description>
<link>https://tsecurity.de/de/4156102/sicherheitsluecken-cve/cve-2026-81917-concrete-cms-up-to-952-document-library-block-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156102/sicherheitsluecken-cve/cve-2026-81917-concrete-cms-up-to-952-document-library-block-cross-site-scripting/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in Concrete CMS up to 9.5.2. This vulnerability affects unknown code of the component Document Library block. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2026-81917. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/402593" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81918 | Concrete CMS up to 9.5.2 Page Attribute Display Block cross site scripting]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Concrete CMS up to 9.5.2. This issue affects some unknown processing of the component Page Attribute Display Block. The manipulation leads to cross site scripting. This vulnerability is listed as CVE-2026-81918. The attack may be init...]]></description>
<link>https://tsecurity.de/de/4156101/sicherheitsluecken-cve/cve-2026-81918-concrete-cms-up-to-952-page-attribute-display-block-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156101/sicherheitsluecken-cve/cve-2026-81918-concrete-cms-up-to-952-page-attribute-display-block-cross-site-scripting/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Concrete CMS up to 9.5.2. This issue affects some unknown processing of the component Page Attribute Display Block. The manipulation leads to cross site scripting. This vulnerability is listed as CVE-2026-81918. The attack may be initiated remotely. There is no available exploit. You... <a href="https://vuldb.com/vuln/402594" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81911 | Concrete CMS up to 9.5.2 Boards canEditBoardContents collection cross site scripting]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Concrete CMS up to 9.5.2. This affects the function canEditBoardContents of the component Boards. Performing a manipulation of the argument collection results in cross site scripting. This vulnerability is known as CVE-2026-81911. Remote ...]]></description>
<link>https://tsecurity.de/de/4156100/sicherheitsluecken-cve/cve-2026-81911-concrete-cms-up-to-952-boards-caneditboardcontents-collection-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156100/sicherheitsluecken-cve/cve-2026-81911-concrete-cms-up-to-952-boards-caneditboardcontents-collection-cross-site-scripting/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Concrete CMS up to 9.5.2. This affects the function canEditBoardContents of the component Boards. Performing a manipulation of the argument collection results in cross site scripting. This vulnerability is known as CVE-2026-81911. Remote exploitation of the attack is possible. No exploit... <a href="https://vuldb.com/vuln/402526" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-81916 | Concrete CMS up to 9.5.2 Express Entry Authorization privileges management]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Concrete CMS up to 9.5.2. Impacted is an unknown function of the component Express Entry Authorization. Such manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2026-81916. The att...]]></description>
<link>https://tsecurity.de/de/4156099/sicherheitsluecken-cve/cve-2026-81916-concrete-cms-up-to-952-express-entry-authorization-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156099/sicherheitsluecken-cve/cve-2026-81916-concrete-cms-up-to-952-express-entry-authorization-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 06:09:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Concrete CMS up to 9.5.2. Impacted is an unknown function of the component Express Entry Authorization. Such manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2026-81916. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/402573" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20325 | Cisco Nexus Dashboard up to 4.2.1 command injection (Nessus ID 348238)]]></title>
<description><![CDATA[A vulnerability classified as very critical has been found in Cisco Nexus Dashboard. This affects an unknown part. This manipulation causes command injection. This vulnerability is handled as CVE-2026-20325. The attack can be initiated remotely. There is not any exploit available. It is recommend...]]></description>
<link>https://tsecurity.de/de/4156065/sicherheitsluecken-cve/cve-2026-20325-cisco-nexus-dashboard-up-to-421-command-injection-nessus-id-348238/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156065/sicherheitsluecken-cve/cve-2026-20325-cisco-nexus-dashboard-up-to-421-command-injection-nessus-id-348238/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical has been found in Cisco Nexus Dashboard. This affects an unknown part. This manipulation causes command injection. This vulnerability is handled as CVE-2026-20325. The attack can be initiated remotely. There is not any exploit available. It is recommended to upgrade the affected component. <a href="https://vuldb.com/vuln/406112" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20322 | Cisco Nexus Dashboard up to 4.2.1 access control (Nessus ID 348238)]]></title>
<description><![CDATA[A vulnerability described as very critical has been identified in Cisco Nexus Dashboard. Affected by this issue is some unknown functionality. The manipulation results in improper access controls. This vulnerability is known as CVE-2026-20322. It is possible to launch the attack remotely. No expl...]]></description>
<link>https://tsecurity.de/de/4156064/sicherheitsluecken-cve/cve-2026-20322-cisco-nexus-dashboard-up-to-421-access-control-nessus-id-348238/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156064/sicherheitsluecken-cve/cve-2026-20322-cisco-nexus-dashboard-up-to-421-access-control-nessus-id-348238/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as very critical has been identified in Cisco Nexus Dashboard. Affected by this issue is some unknown functionality. The manipulation results in improper access controls. This vulnerability is known as CVE-2026-20322. It is possible to launch the attack remotely. No exploit is available. Upgrading the affected component... <a href="https://vuldb.com/vuln/406111" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20361 | Cisco Nexus Dashboard up to 4.2.1 sql injection (Nessus ID 348238)]]></title>
<description><![CDATA[A vulnerability has been found in Cisco Nexus Dashboard and classified as critical. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerability is referenced as CVE-2026-20361. Remote exploitation of the attack is possible. No exploit is available. The...]]></description>
<link>https://tsecurity.de/de/4156063/sicherheitsluecken-cve/cve-2026-20361-cisco-nexus-dashboard-up-to-421-sql-injection-nessus-id-348238/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156063/sicherheitsluecken-cve/cve-2026-20361-cisco-nexus-dashboard-up-to-421-sql-injection-nessus-id-348238/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Cisco Nexus Dashboard and classified as critical. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerability is referenced as CVE-2026-20361. Remote exploitation of the attack is possible. No exploit is available. The affected component should be upgraded. <a href="https://vuldb.com/vuln/406116" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20326 | Cisco Nexus Dashboard up to 4.2.1 missing authentication (Nessus ID 348238)]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Cisco Nexus Dashboard. This vulnerability affects unknown code. Such manipulation leads to missing authentication. This vulnerability is uniquely identified as CVE-2026-20326. The attack can be launched remotely. No exploit exists. Upgradin...]]></description>
<link>https://tsecurity.de/de/4156062/sicherheitsluecken-cve/cve-2026-20326-cisco-nexus-dashboard-up-to-421-missing-authentication-nessus-id-348238/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156062/sicherheitsluecken-cve/cve-2026-20326-cisco-nexus-dashboard-up-to-421-missing-authentication-nessus-id-348238/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical was found in Cisco Nexus Dashboard. This vulnerability affects unknown code. Such manipulation leads to missing authentication. This vulnerability is uniquely identified as CVE-2026-20326. The attack can be launched remotely. No exploit exists. Upgrading the affected component is advised. <a href="https://vuldb.com/vuln/406113" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73428 | Basecamp Trix up to 2.1.17 HTMLParser/StringPiece StringPiece.fromJSON HTML injection]]></title>
<description><![CDATA[A vulnerability has been found in Basecamp Trix up to 2.1.17 and classified as problematic. The affected element is the function StringPiece.fromJSON of the component HTMLParser/StringPiece. The manipulation leads to HTML injection. This vulnerability is referenced as CVE-2026-73428. Remote explo...]]></description>
<link>https://tsecurity.de/de/4156061/sicherheitsluecken-cve/cve-2026-73428-basecamp-trix-up-to-2117-htmlparserstringpiece-stringpiecefromjson-html-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156061/sicherheitsluecken-cve/cve-2026-73428-basecamp-trix-up-to-2117-htmlparserstringpiece-stringpiecefromjson-html-injection/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Basecamp Trix up to 2.1.17 and classified as problematic. The affected element is the function StringPiece.fromJSON of the component HTMLParser/StringPiece. The manipulation leads to HTML injection. This vulnerability is referenced as CVE-2026-73428. Remote exploitation of the attack is possible. No exploit is... <a href="https://vuldb.com/vuln/389946" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73489 | Eugeny Russh up to 0.62.3 Parser encrypted.rs out-of-bounds]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Eugeny Russh up to 0.62.3. This issue affects some unknown processing of the file russh/src/server/encrypted.rs of the component Parser. Performing a manipulation results in out-of-bounds read. This vulnerability was named CV...]]></description>
<link>https://tsecurity.de/de/4156060/sicherheitsluecken-cve/cve-2026-73489-eugeny-russh-up-to-0623-parser-encryptedrs-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156060/sicherheitsluecken-cve/cve-2026-73489-eugeny-russh-up-to-0623-parser-encryptedrs-out-of-bounds/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in Eugeny Russh up to 0.62.3. This issue affects some unknown processing of the file russh/src/server/encrypted.rs of the component Parser. Performing a manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-73489. The attack may be initiated remotely.... <a href="https://vuldb.com/vuln/389944" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73420 | NextAuth.js auth-core-next-auth Email Normalization defaultNormalizer improper authentication]]></title>
<description><![CDATA[A vulnerability classified as critical was found in NextAuth.js auth-core-next-auth. This vulnerability affects the function defaultNormalizer of the component Email Normalization. Such manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2026-73420. The...]]></description>
<link>https://tsecurity.de/de/4156059/sicherheitsluecken-cve/cve-2026-73420-nextauthjs-auth-core-next-auth-email-normalization-defaultnormalizer-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156059/sicherheitsluecken-cve/cve-2026-73420-nextauthjs-auth-core-next-auth-email-normalization-defaultnormalizer-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in NextAuth.js auth-core-next-auth. This vulnerability affects the function defaultNormalizer of the component Email Normalization. Such manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2026-73420. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/389943" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73417 | Jupyter JupyterLab up to 4.5.9/4.6.1 Notebook Extension index.ts code injection]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Jupyter JupyterLab up to 4.5.9/4.6.1. Affected is an unknown function of the file packages/notebook-extension/src/index.ts of the component Notebook Extension. Executing a manipulation of the argument sideBySideLeftMarginOverride/sideBySide...]]></description>
<link>https://tsecurity.de/de/4156058/sicherheitsluecken-cve/cve-2026-73417-jupyter-jupyterlab-up-to-459461-notebook-extension-indexts-code-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156058/sicherheitsluecken-cve/cve-2026-73417-jupyter-jupyterlab-up-to-459461-notebook-extension-indexts-code-injection/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in Jupyter JupyterLab up to 4.5.9/4.6.1. Affected is an unknown function of the file packages/notebook-extension/src/index.ts of the component Notebook Extension. Executing a manipulation of the argument sideBySideLeftMarginOverride/sideBySideRightMarginOverride can lead to code injection. This... <a href="https://vuldb.com/vuln/389939" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73660 | FreePBX prior 16.0.6/17.0.5.4 Text-To-Speech module agi-bin/propolys-tts.agi os command injection]]></title>
<description><![CDATA[A vulnerability has been found in FreePBX and classified as problematic. This affects an unknown function of the file agi-bin/propolys-tts.agi of the component Text-To-Speech module. The manipulation leads to os command injection. This vulnerability is listed as CVE-2026-73660. The attack may be ...]]></description>
<link>https://tsecurity.de/de/4156057/sicherheitsluecken-cve/cve-2026-73660-freepbx-prior-160617054-text-to-speech-module-agi-binpropolys-ttsagi-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156057/sicherheitsluecken-cve/cve-2026-73660-freepbx-prior-160617054-text-to-speech-module-agi-binpropolys-ttsagi-os-command-injection/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in FreePBX and classified as problematic. This affects an unknown function of the file agi-bin/propolys-tts.agi of the component Text-To-Speech module. The manipulation leads to os command injection. This vulnerability is listed as CVE-2026-73660. The attack may be initiated remotely. There is no available exploit.... <a href="https://vuldb.com/vuln/389904" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73416 | JupyterLab up to 4.5.9/4.6.1 PyPI Extension Manager manager.py privileges management]]></title>
<description><![CDATA[A vulnerability was found in JupyterLab up to 4.5.9/4.6.1 and classified as problematic. This issue affects some unknown processing of the file jupyterlab/extensions/manager.py of the component PyPI Extension Manager. Executing a manipulation can lead to improper privilege management. This vulner...]]></description>
<link>https://tsecurity.de/de/4156056/sicherheitsluecken-cve/cve-2026-73416-jupyterlab-up-to-459461-pypi-extension-manager-managerpy-privileges-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156056/sicherheitsluecken-cve/cve-2026-73416-jupyterlab-up-to-459461-pypi-extension-manager-managerpy-privileges-management/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in JupyterLab up to 4.5.9/4.6.1 and classified as problematic. This issue affects some unknown processing of the file jupyterlab/extensions/manager.py of the component PyPI Extension Manager. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as CVE-2026-73416. The attack can... <a href="https://vuldb.com/vuln/389933" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73661 | FreePBX up to 16.0.46/17.0.29 Framework Restore.php runRestore improper authentication]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in FreePBX up to 16.0.46/17.0.29. Impacted is the function runRestore of the file amp_conf/htdocs/admin/libraries/Builtin/Restore.php of the component Framework Module. Such manipulation leads to improper authentication. This vulnerability is re...]]></description>
<link>https://tsecurity.de/de/4156055/sicherheitsluecken-cve/cve-2026-73661-freepbx-up-to-1604617029-framework-restorephp-runrestore-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4156055/sicherheitsluecken-cve/cve-2026-73661-freepbx-up-to-1604617029-framework-restorephp-runrestore-improper-authentication/</guid>
<pubDate>Sat, 19 Sep 2026 05:08:37 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in FreePBX up to 16.0.46/17.0.29. Impacted is the function runRestore of the file amp_conf/htdocs/admin/libraries/Builtin/Restore.php of the component Framework Module. Such manipulation leads to improper authentication. This vulnerability is referenced as CVE-2026-73661. It is possible to launch... <a href="https://vuldb.com/vuln/389901" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 1,72ms -->