<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - Sicherheitslücken (CVE)]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/sicherheitsluecken-cve.xml]]></link>
<description><![CDATA[ENISA EUVD & CISA KEV Vulnerability Database. Dokumentierte CVEs, Severity Heatmaps, NIS-2 Relevant Advisories und Vendor Patch Bulletins.]]></description>
<language>de-DE</language>
<lastBuildDate>Fri, 18 Sep 2026 07:10:19 +0200</lastBuildDate>
<pubDate>Fri, 18 Sep 2026 07:10:19 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - Sicherheitslücken (CVE)</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - Sicherheitslücken (CVE)]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/sicherheitsluecken-cve.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-93375 | Google Chrome up to 153.0.8010.47 Tracing sandbox (Nessus ID 346979)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Tracing. This manipulation causes sandbox issue. This vulnerability appears as CVE-2026-93375. The attack requires local access. There is no av...]]></description>
<link>https://tsecurity.de/de/4153535/sicherheitsluecken-cve/cve-2026-93375-google-chrome-up-to-1530801047-tracing-sandbox-nessus-id-346979/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153535/sicherheitsluecken-cve/cve-2026-93375-google-chrome-up-to-1530801047-tracing-sandbox-nessus-id-346979/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Tracing. This manipulation causes sandbox issue. This vulnerability appears as CVE-2026-93375. The attack requires local access. There is no available exploit. You should upgrade the affected... <a href="https://vuldb.com/vuln/407144" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92987 | RazrFalcon roxmltree up to 0.21.1 XML Parsing resource consumption (Nessus ID 346976)]]></title>
<description><![CDATA[A vulnerability was found in RazrFalcon roxmltree up to 0.21.1. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component XML Parsing. This manipulation causes resource consumption. This vulnerability appears as CVE-2026-92987. The attack may be...]]></description>
<link>https://tsecurity.de/de/4153534/sicherheitsluecken-cve/cve-2026-92987-razrfalcon-roxmltree-up-to-0211-xml-parsing-resource-consumption-nessus-id-346976/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153534/sicherheitsluecken-cve/cve-2026-92987-razrfalcon-roxmltree-up-to-0211-xml-parsing-resource-consumption-nessus-id-346976/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in RazrFalcon roxmltree up to 0.21.1. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component XML Parsing. This manipulation causes resource consumption. This vulnerability appears as CVE-2026-92987. The attack may be initiated remotely. There is no available exploit. <a href="https://vuldb.com/vuln/406484" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-87278 | Oracle VirtualBox 7.2.16 Core denial of service (Nessus ID 346977)]]></title>
<description><![CDATA[A vulnerability was found in Oracle VirtualBox 7.2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Core. Such manipulation leads to denial of service. This vulnerability is uniquely identified as CVE-2026-87278. Local access is requir...]]></description>
<link>https://tsecurity.de/de/4153533/sicherheitsluecken-cve/cve-2026-87278-oracle-virtualbox-7216-core-denial-of-service-nessus-id-346977/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153533/sicherheitsluecken-cve/cve-2026-87278-oracle-virtualbox-7216-core-denial-of-service-nessus-id-346977/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Oracle VirtualBox 7.2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Core. Such manipulation leads to denial of service. This vulnerability is uniquely identified as CVE-2026-87278. Local access is required to approach this attack. No exploit exists. It is... <a href="https://vuldb.com/vuln/405363" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92413 | Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9 PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference (Bug 709610 / Nessus ID 346975)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointe...]]></description>
<link>https://tsecurity.de/de/4153532/sicherheitsluecken-cve/cve-2026-92413-artifex-mupdf-up-to-b6d17493700c621c0e70036980a6ebd06d2202c9-pdf-xref-loading-pdf-streamc-pdfopenfilter-null-pointer-dereference-bug-709610-nessus-id-346975/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153532/sicherheitsluecken-cve/cve-2026-92413-artifex-mupdf-up-to-b6d17493700c621c0e70036980a6ebd06d2202c9-pdf-xref-loading-pdf-streamc-pdfopenfilter-null-pointer-dereference-bug-709610-nessus-id-346975/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. This vulnerability is tracked as... <a href="https://vuldb.com/vuln/405593" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-87283 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346974)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Oracle VirtualBox 7.2.16. This vulnerability affects unknown code of the component Core. The manipulation leads to improper privilege management. This vulnerability is listed as CVE-2026-87283. The attack must be carried out locally. Ther...]]></description>
<link>https://tsecurity.de/de/4153531/sicherheitsluecken-cve/cve-2026-87283-oracle-virtualbox-7216-core-privileges-management-nessus-id-346974/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153531/sicherheitsluecken-cve/cve-2026-87283-oracle-virtualbox-7216-core-privileges-management-nessus-id-346974/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Oracle VirtualBox 7.2.16. This vulnerability affects unknown code of the component Core. The manipulation leads to improper privilege management. This vulnerability is listed as CVE-2026-87283. The attack must be carried out locally. There is no available exploit. It is suggested to... <a href="https://vuldb.com/vuln/405354" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-77170 | Nextcloud Deck up to 1.18.0 Deck config API permission (EUVD-2026-82620)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Nextcloud Deck up to 1.18.0. This affects an unknown function of the component Deck config API. The manipulation leads to permission issues. This vulnerability is uniquely identified as CVE-2026-77170. The attack is possible to be carried...]]></description>
<link>https://tsecurity.de/de/4153530/sicherheitsluecken-cve/cve-2026-77170-nextcloud-deck-up-to-1180-deck-config-api-permission-euvd-2026-82620/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153530/sicherheitsluecken-cve/cve-2026-77170-nextcloud-deck-up-to-1180-deck-config-api-permission-euvd-2026-82620/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Nextcloud Deck up to 1.18.0. This affects an unknown function of the component Deck config API. The manipulation leads to permission issues. This vulnerability is uniquely identified as CVE-2026-77170. The attack is possible to be carried out remotely. No exploit exists. <a href="https://vuldb.com/vuln/407328" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-82980 | Nextcloud Files Lock up to 33.0.0 WebDAV Plugin improper authorization (EUVD-2026-82617)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Nextcloud Files Lock up to 33.0.0. Affected by this issue is some unknown functionality of the component WebDAV Plugin. Performing a manipulation results in improper authorization. This vulnerability is identified as CVE-2026-82...]]></description>
<link>https://tsecurity.de/de/4153529/sicherheitsluecken-cve/cve-2026-82980-nextcloud-files-lock-up-to-3300-webdav-plugin-improper-authorization-euvd-2026-82617/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153529/sicherheitsluecken-cve/cve-2026-82980-nextcloud-files-lock-up-to-3300-webdav-plugin-improper-authorization-euvd-2026-82617/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, has been found in Nextcloud Files Lock up to 33.0.0. Affected by this issue is some unknown functionality of the component WebDAV Plugin. Performing a manipulation results in improper authorization. This vulnerability is identified as CVE-2026-82980. The attack can be initiated remotely. There is... <a href="https://vuldb.com/vuln/407332" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-77169 | Nextcloud Team Folders up to 21.x improper authorization (EUVD-2026-82618)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Nextcloud Team Folders up to 21.x. Affected is an unknown function. This manipulation causes improper authorization. The identification of this vulnerability is CVE-2026-77169. It is possible to initiate the attack remotely. There is no ...]]></description>
<link>https://tsecurity.de/de/4153528/sicherheitsluecken-cve/cve-2026-77169-nextcloud-team-folders-up-to-21x-improper-authorization-euvd-2026-82618/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153528/sicherheitsluecken-cve/cve-2026-77169-nextcloud-team-folders-up-to-21x-improper-authorization-euvd-2026-82618/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in Nextcloud Team Folders up to 21.x. Affected is an unknown function. This manipulation causes improper authorization. The identification of this vulnerability is CVE-2026-77169. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the... <a href="https://vuldb.com/vuln/407330" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-82982 | Nextcloud Approval up to 3.0.0 etag improper authentication (EUVD-2026-82619)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Nextcloud Approval up to 3.0.0. The affected element is an unknown function. Performing a manipulation of the argument etag results in improper authentication. This vulnerability is known as CVE-2026-82982. Remote exploitation of the ...]]></description>
<link>https://tsecurity.de/de/4153527/sicherheitsluecken-cve/cve-2026-82982-nextcloud-approval-up-to-300-etag-improper-authentication-euvd-2026-82619/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153527/sicherheitsluecken-cve/cve-2026-82982-nextcloud-approval-up-to-300-etag-improper-authentication-euvd-2026-82619/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Nextcloud Approval up to 3.0.0. The affected element is an unknown function. Performing a manipulation of the argument etag results in improper authentication. This vulnerability is known as CVE-2026-82982. Remote exploitation of the attack is possible. No exploit is available. <a href="https://vuldb.com/vuln/407326" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93456 | batiste django-page-cms up to 2.0.13 Admin Views pages/admin/views.py cross site scripting (EUVD-2026-82616)]]></title>
<description><![CDATA[A vulnerability has been found in batiste django-page-cms up to 2.0.13 and classified as problematic. This vulnerability affects unknown code of the file pages/admin/views.py of the component Admin Views. The manipulation leads to cross site scripting. This vulnerability is listed as CVE-2026-934...]]></description>
<link>https://tsecurity.de/de/4153526/sicherheitsluecken-cve/cve-2026-93456-batiste-django-page-cms-up-to-2013-admin-views-pagesadminviewspy-cross-site-scripting-euvd-2026-82616/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153526/sicherheitsluecken-cve/cve-2026-93456-batiste-django-page-cms-up-to-2013-admin-views-pagesadminviewspy-cross-site-scripting-euvd-2026-82616/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in batiste django-page-cms up to 2.0.13 and classified as problematic. This vulnerability affects unknown code of the file pages/admin/views.py of the component Admin Views. The manipulation leads to cross site scripting. This vulnerability is listed as CVE-2026-93456. The attack may be initiated remotely. There is... <a href="https://vuldb.com/vuln/407334" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93455 | batiste django-page-cms up to 2.0.13 permission (EUVD-2026-82615)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in batiste django-page-cms up to 2.0.13. Affected by this vulnerability is an unknown functionality. Such manipulation leads to permission issues. This vulnerability is referenced as CVE-2026-93455. It is possible to launch the attack remotely. ...]]></description>
<link>https://tsecurity.de/de/4153525/sicherheitsluecken-cve/cve-2026-93455-batiste-django-page-cms-up-to-2013-permission-euvd-2026-82615/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153525/sicherheitsluecken-cve/cve-2026-93455-batiste-django-page-cms-up-to-2013-permission-euvd-2026-82615/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in batiste django-page-cms up to 2.0.13. Affected by this vulnerability is an unknown functionality. Such manipulation leads to permission issues. This vulnerability is referenced as CVE-2026-93455. It is possible to launch the attack remotely. No exploit is available. <a href="https://vuldb.com/vuln/407331" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93313 | Freedesktop Poppler 26.07.0 poppler/JBIG2Stream.cc readCodeTableSeg integer overflow (ID 1760 / EUVD-2026-82614)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. This vulnerability is identified as CVE-2026-93313...]]></description>
<link>https://tsecurity.de/de/4153524/sicherheitsluecken-cve/cve-2026-93313-freedesktop-poppler-26070-popplerjbig2streamcc-readcodetableseg-integer-overflow-id-1760-euvd-2026-82614/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153524/sicherheitsluecken-cve/cve-2026-93313-freedesktop-poppler-26070-popplerjbig2streamcc-readcodetableseg-integer-overflow-id-1760-euvd-2026-82614/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. This vulnerability is identified as CVE-2026-93313. The attack can be initiated remotely.... <a href="https://vuldb.com/vuln/406612" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89825 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 panthor drm/panthor panthor_init_cs_iface/panthor_init_csg_iface memory corruption (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.109/6.18.50/7.2.4. This affects the function panthor_init_cs_iface/panthor_init_csg_iface of the file drm/panthor of the component panthor. Such manipulation leads to memory corruption. This vulnerability ...]]></description>
<link>https://tsecurity.de/de/4153523/sicherheitsluecken-cve/cve-2026-89825-linux-kernel-up-to-61210961850724-panthor-drmpanthor-panthorinitcsifacepanthorinitcsgiface-memory-corruption-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153523/sicherheitsluecken-cve/cve-2026-89825-linux-kernel-up-to-61210961850724-panthor-drmpanthor-panthorinitcsifacepanthorinitcsgiface-memory-corruption-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.109/6.18.50/7.2.4. This affects the function panthor_init_cs_iface/panthor_init_csg_iface of the file drm/panthor of the component panthor. Such manipulation leads to memory corruption. This vulnerability is traded as CVE-2026-89825. The attack may be... <a href="https://vuldb.com/vuln/405645" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89826 | Linux Kernel up to 6.18.50/7.2.4 panthor panthor_fw_read_build_info out-of-bounds (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.50/7.2.4. This impacts the function panthor_fw_read_build_info of the component panthor. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2026-89826. Remote exploita...]]></description>
<link>https://tsecurity.de/de/4153522/sicherheitsluecken-cve/cve-2026-89826-linux-kernel-up-to-61850724-panthor-panthorfwreadbuildinfo-out-of-bounds-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153522/sicherheitsluecken-cve/cve-2026-89826-linux-kernel-up-to-61850724-panthor-panthorfwreadbuildinfo-out-of-bounds-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.50/7.2.4. This impacts the function panthor_fw_read_build_info of the component panthor. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2026-89826. Remote exploitation of the attack is possible. No exploit is... <a href="https://vuldb.com/vuln/405646" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89827 | Linux Kernel up to 7.2.4 UVD Ring drm/amdgpu amdgpu_uvd_resume uninitialized pointer (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.2.4. It has been rated as very critical. The impacted element is the function amdgpu_uvd_resume of the file drm/amdgpu of the component UVD Ring. This manipulation causes uninitialized pointer. This vulnerability appears as CVE-2026-89827. The att...]]></description>
<link>https://tsecurity.de/de/4153521/sicherheitsluecken-cve/cve-2026-89827-linux-kernel-up-to-724-uvd-ring-drmamdgpu-amdgpuuvdresume-uninitialized-pointer-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153521/sicherheitsluecken-cve/cve-2026-89827-linux-kernel-up-to-724-uvd-ring-drmamdgpu-amdgpuuvdresume-uninitialized-pointer-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 7.2.4. It has been rated as very critical. The impacted element is the function amdgpu_uvd_resume of the file drm/amdgpu of the component UVD Ring. This manipulation causes uninitialized pointer. This vulnerability appears as CVE-2026-89827. The attack may be initiated remotely. There is no available... <a href="https://vuldb.com/vuln/405644" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89830 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 f2fs __allocate_data_block data_blkaddr allocation of resources (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected by this issue is the function __allocate_data_block of the component f2fs. The manipulation of the argument data_blkaddr results in allocation of resources. This vulnerability was name...]]></description>
<link>https://tsecurity.de/de/4153520/sicherheitsluecken-cve/cve-2026-89830-linux-kernel-up-to-61210961850724-f2fs-allocatedatablock-datablkaddr-allocation-of-resources-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153520/sicherheitsluecken-cve/cve-2026-89830-linux-kernel-up-to-61210961850724-f2fs-allocatedatablock-datablkaddr-allocation-of-resources-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected by this issue is the function __allocate_data_block of the component f2fs. The manipulation of the argument data_blkaddr results in allocation of resources. This vulnerability was named CVE-2026-89830. The attack may be performed from... <a href="https://vuldb.com/vuln/405649" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89829 | Linux Kernel up to 6.18.50/7.2.4 f2fs f2fs_sanity_check_node_footer index infinite loop (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function f2fs_sanity_check_node_footer of the component f2fs. The manipulation of the argument index leads to infinite loop. This vulnerability is uniquely identifi...]]></description>
<link>https://tsecurity.de/de/4153519/sicherheitsluecken-cve/cve-2026-89829-linux-kernel-up-to-61850724-f2fs-f2fssanitychecknodefooter-index-infinite-loop-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153519/sicherheitsluecken-cve/cve-2026-89829-linux-kernel-up-to-61850724-f2fs-f2fssanitychecknodefooter-index-infinite-loop-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function f2fs_sanity_check_node_footer of the component f2fs. The manipulation of the argument index leads to infinite loop. This vulnerability is uniquely identified as CVE-2026-89829. The attack is possible to be... <a href="https://vuldb.com/vuln/405648" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89828 | Linux Kernel up to 6.18.50/7.2.4 amdgpu_vram_mgr drm/amdgpu amdgpu_vram_mgr_init free_trees null pointer dereference (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.50/7.2.4. Affected is the function amdgpu_vram_mgr_init of the file drm/amdgpu of the component amdgpu_vram_mgr. Executing a manipulation of the argument free_trees can lead to null pointer dereference. This vulnerabili...]]></description>
<link>https://tsecurity.de/de/4153518/sicherheitsluecken-cve/cve-2026-89828-linux-kernel-up-to-61850724-amdgpuvrammgr-drmamdgpu-amdgpuvrammgrinit-freetrees-null-pointer-dereference-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153518/sicherheitsluecken-cve/cve-2026-89828-linux-kernel-up-to-61850724-amdgpuvrammgr-drmamdgpu-amdgpuvrammgrinit-freetrees-null-pointer-dereference-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.50/7.2.4. Affected is the function amdgpu_vram_mgr_init of the file drm/amdgpu of the component amdgpu_vram_mgr. Executing a manipulation of the argument free_trees can lead to null pointer dereference. This vulnerability is handled as CVE-2026-89828. The attack can be... <a href="https://vuldb.com/vuln/405647" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I Built CyberKit: A Fast, 100% In-Browser Security & Network Utility Suite]]></title>
<description><![CDATA[As developers, sysadmins, and security enthusiasts, we reach for online utility tools every single day: calculating CVSS scores, decoding Base64 or URL strings, validating JWT tokens, computing CIDR subnet masks, or generating cryptographic hashes. Yet, most online security tool platforms today s...]]></description>
<link>https://tsecurity.de/de/4153513/sicherheitsluecken-cve/why-i-built-cyberkit-a-fast-100-in-browser-security-network-utility-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153513/sicherheitsluecken-cve/why-i-built-cyberkit-a-fast-100-in-browser-security-network-utility-suite/</guid>
<pubDate>Fri, 18 Sep 2026 07:07:19 +0200</pubDate>
<content:encoded><![CDATA[<p>As developers, sysadmins, and security enthusiasts, we reach for online utility tools every single day: calculating CVSS scores, decoding Base64 or URL strings, validating JWT tokens, computing CIDR subnet masks, or generating cryptographic hashes. Yet, most online security tool platforms today share two major flaws: Ad-Cluttered &amp;amp; Slow: Heavy... <a href="https://dev.to/sudeepth_p_fd23a1eee35068/why-i-built-cyberkit-a-fast-100-in-browser-security-network-utility-suite-3knm" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Use Claude Opus 5 to Hack OpenAI Forum and Reach Internal Repositories]]></title>
<description><![CDATA[Researchers used Anthropic’s Claude Opus 5 to help weaponize an image-decoder vulnerability, compromise OpenAI’s community forum, take over employees’ ChatGPT and Codex accounts, and reach an internal source-code repository. The July 25, 2026 operation by Hacktron linked remote code execution in ...]]></description>
<link>https://tsecurity.de/de/4153500/sicherheitsluecken-cve/researchers-use-claude-opus-5-to-hack-openai-forum-and-reach-internal-repositories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153500/sicherheitsluecken-cve/researchers-use-claude-opus-5-to-hack-openai-forum-and-reach-internal-repositories/</guid>
<pubDate>Fri, 18 Sep 2026 07:05:04 +0200</pubDate>
<content:encoded><![CDATA[<p>Researchers used Anthropic’s Claude Opus 5 to help weaponize an image-decoder vulnerability, compromise OpenAI’s community forum, take over employees’ ChatGPT and Codex accounts, and reach an internal source-code repository. The July 25, 2026 operation by Hacktron linked remote code execution in Discourse’s image-processing stack to a flaw in... <a href="https://cybersecuritynews.com/opus-5-to-help-exploit-openai-flaws/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-18 07h : 11 posts]]></title>
<description><![CDATA[11 posts published in the last hour 04:31Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges 04:31CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers 04:31OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permi...]]></description>
<link>https://tsecurity.de/de/4153499/sicherheitsluecken-cve/it-security-news-hourly-summary-2026-09-18-07h-11-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153499/sicherheitsluecken-cve/it-security-news-hourly-summary-2026-09-18-07h-11-posts/</guid>
<pubDate>Fri, 18 Sep 2026 07:05:02 +0200</pubDate>
<content:encoded><![CDATA[<p>11 posts published in the last hour 04:31Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges 04:31CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers 04:31OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permission 04:31How Pentest Companies Adapt In The Era of... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-18-07h-11-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Steam Windows Vulnerability Lets Users Escalate Privileges to NT AUTHORITY\SYSTEM]]></title>
<description><![CDATA[A newly published proof of concept called “BrokenPipe” has revealed a local privilege escalation vulnerability in the Steam Client Service on Windows systems. According to the project’s GitHub repository, this flaw could allow a standard, non-administrative Windows user to make the Steam Client S...]]></description>
<link>https://tsecurity.de/de/4153498/sicherheitsluecken-cve/steam-windows-vulnerability-lets-users-escalate-privileges-to-nt-authoritysystem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153498/sicherheitsluecken-cve/steam-windows-vulnerability-lets-users-escalate-privileges-to-nt-authoritysystem/</guid>
<pubDate>Fri, 18 Sep 2026 07:05:02 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly published proof of concept called “BrokenPipe” has revealed a local privilege escalation vulnerability in the Steam Client Service on Windows systems. According to the project’s GitHub repository, this flaw could allow a standard, non-administrative Windows user to make the Steam Client Service launch an executable with NT AUTHORITY\SYSTEM... <a href="https://www.itsecuritynews.info/steam-windows-vulnerability-lets-users-escalate-privileges-to-nt-authoritysystem/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DFN-CERT-2026-4940 libvirt: Eine Schwachstelle ermöglicht die Eskalation von Privilegien]]></title>
<description><![CDATA[sowie Red Hat Enterprise Linux Server in Version AUS 9.2, 9.4 und 9.6 ... Gruppenleiter*in Managed Windows ServerBerlin, Home Office. PSI Software ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153465/sicherheitsluecken/dfn-cert-2026-4940-libvirt-eine-schwachstelle-ermoeglicht-die-eskalation-von-privilegien/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153465/sicherheitsluecken/dfn-cert-2026-4940-libvirt-eine-schwachstelle-ermoeglicht-die-eskalation-von-privilegien/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:48 +0200</pubDate>
<content:encoded><![CDATA[<p>sowie Red Hat Enterprise Linux Server in Version AUS 9.2, 9.4 und 9.6 ... Gruppenleiter*in Managed Windows ServerBerlin, Home Office. PSI Software ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.linux-magazin.de/dfn-cert-advisories/dfn-cert-2026-4940-libvirt-eine-schwachstelle-ermoeglicht-die-eskalation-von-privilegien/&amp;ct=ga&amp;cd=CAIyGWE4YWZlOWE1ODU5MTM3YjQ6ZGU6ZGU6REU&amp;usg=AOvVaw1nm19eWS59BprP5K-ux8k8" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89820 | Linux Kernel up to 6.18.50/7.2.4 AMD Display drm/amd/display amdgpu_dm_commit_zero_streams locking (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function amdgpu_dm_commit_zero_streams of the file drm/amd/display of the component AMD Display. The manipulation results in improper locking. This vulnerability is identifi...]]></description>
<link>https://tsecurity.de/de/4153462/sicherheitsluecken/cve-2026-89820-linux-kernel-up-to-61850724-amd-display-drmamddisplay-amdgpudmcommitzerostreams-locking-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153462/sicherheitsluecken/cve-2026-89820-linux-kernel-up-to-61850724-amd-display-drmamddisplay-amdgpudmcommitzerostreams-locking-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function amdgpu_dm_commit_zero_streams of the file drm/amd/display of the component AMD Display. The manipulation results in improper locking. This vulnerability is identified as CVE-2026-89820. The attack can be executed... <a href="https://vuldb.com/vuln/405637" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89821 | Linux Kernel up to 7.2.4 drm/amd/display __is_lut_linear divide by zero (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. This issue affects the function __is_lut_linear of the file drm/amd/display. Executing a manipulation can lead to divide by zero. This vulnerability is registered as CVE-2026-89821. It is possible to launch the atta...]]></description>
<link>https://tsecurity.de/de/4153461/sicherheitsluecken/cve-2026-89821-linux-kernel-up-to-724-drmamddisplay-islutlinear-divide-by-zero-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153461/sicherheitsluecken/cve-2026-89821-linux-kernel-up-to-724-drmamddisplay-islutlinear-divide-by-zero-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. This issue affects the function __is_lut_linear of the file drm/amd/display. Executing a manipulation can lead to divide by zero. This vulnerability is registered as CVE-2026-89821. It is possible to launch the attack remotely. No exploit is available. It is... <a href="https://vuldb.com/vuln/405641" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89823 | Linux Kernel up to 7.2.4 drm drm_dev_register race condition (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 7.2.4. Affected by this issue is the function drm_dev_register of the component drm. This manipulation causes race condition. This vulnerability is tracked as CVE-2026-89823. The attack is possible to be ...]]></description>
<link>https://tsecurity.de/de/4153460/sicherheitsluecken/cve-2026-89823-linux-kernel-up-to-724-drm-drmdevregister-race-condition-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153460/sicherheitsluecken/cve-2026-89823-linux-kernel-up-to-724-drm-drmdevregister-race-condition-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 7.2.4. Affected by this issue is the function drm_dev_register of the component drm. This manipulation causes race condition. This vulnerability is tracked as CVE-2026-89823. The attack is possible to be carried out remotely. No exploit exists. It is... <a href="https://vuldb.com/vuln/405638" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89822 | Linux Kernel up to 7.3-rc1 i915 i915_pci_probe null pointer dereference (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Linux Kernel up to 7.3-rc1. The affected element is the function i915_pci_probe of the component i915. This manipulation causes null pointer dereference. This vulnerability is handled as CVE-2026-89822. It is possible to launch the at...]]></description>
<link>https://tsecurity.de/de/4153459/sicherheitsluecken/cve-2026-89822-linux-kernel-up-to-73-rc1-i915-i915pciprobe-null-pointer-dereference-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153459/sicherheitsluecken/cve-2026-89822-linux-kernel-up-to-73-rc1-i915-i915pciprobe-null-pointer-dereference-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as problematic has been detected in Linux Kernel up to 7.3-rc1. The affected element is the function i915_pci_probe of the component i915. This manipulation causes null pointer dereference. This vulnerability is handled as CVE-2026-89822. It is possible to launch the attack on the local host. There is not any exploit... <a href="https://vuldb.com/vuln/405632" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89824 | Linux Kernel up to 7.2.4 i2c adapter panel-edp.c memory leak (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.50/7.2.4. It has been classified as critical. Impacted is an unknown function of the file panel-edp.c of the component i2c adapter. The manipulation leads to memory leak. This vulnerability is documented as CVE-2026-898...]]></description>
<link>https://tsecurity.de/de/4153458/sicherheitsluecken/cve-2026-89824-linux-kernel-up-to-724-i2c-adapter-panel-edpc-memory-leak-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153458/sicherheitsluecken/cve-2026-89824-linux-kernel-up-to-724-i2c-adapter-panel-edpc-memory-leak-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.50/7.2.4. It has been classified as critical. Impacted is an unknown function of the file panel-edp.c of the component i2c adapter. The manipulation leads to memory leak. This vulnerability is documented as CVE-2026-89824. The attack can be initiated remotely. There is... <a href="https://vuldb.com/vuln/405642" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44379 | Automotive Shop Management System 1.0 Master.php?f=delete_service sql injection (EUVD-2022-47324)]]></title>
<description><![CDATA[A vulnerability was found in Automotive Shop Management System 1.0. It has been declared as critical. This impacts an unknown function of the file /asms/classes/Master.php?f=delete_service. Such manipulation leads to sql injection. This vulnerability is documented as CVE-2022-44379. The attack ca...]]></description>
<link>https://tsecurity.de/de/4153457/sicherheitsluecken/cve-2022-44379-automotive-shop-management-system-10-masterphpfdeleteservice-sql-injection-euvd-2022-47324/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153457/sicherheitsluecken/cve-2022-44379-automotive-shop-management-system-10-masterphpfdeleteservice-sql-injection-euvd-2022-47324/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Automotive Shop Management System 1.0. It has been declared as critical. This impacts an unknown function of the file /asms/classes/Master.php?f=delete_service. Such manipulation leads to sql injection. This vulnerability is documented as CVE-2022-44379. The attack can be executed remotely. There is not any exploit... <a href="https://vuldb.com/vuln/213927" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44384 | rConfig 3.9.6 PHP File unrestricted upload (Exploit 49783 / EUVD-2022-47327)]]></title>
<description><![CDATA[A vulnerability was found in rConfig 3.9.6. It has been classified as critical. This issue affects some unknown processing of the component PHP File Handler. Performing a manipulation results in unrestricted upload. This vulnerability is known as CVE-2022-44384. Access to the local network is req...]]></description>
<link>https://tsecurity.de/de/4153456/sicherheitsluecken/cve-2022-44384-rconfig-396-php-file-unrestricted-upload-exploit-49783-euvd-2022-47327/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153456/sicherheitsluecken/cve-2022-44384-rconfig-396-php-file-unrestricted-upload-exploit-49783-euvd-2022-47327/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in rConfig 3.9.6. It has been classified as critical. This issue affects some unknown processing of the component PHP File Handler. Performing a manipulation results in unrestricted upload. This vulnerability is known as CVE-2022-44384. Access to the local network is required for this attack. Furthermore, an exploit is... <a href="https://vuldb.com/vuln/213856" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44387 | EyouCMS 1.5.9-UTF8-SP1 Basic Information cross-site request forgery (Issue 29 / EUVD-2022-47330)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in EyouCMS 1.5.9-UTF8-SP1. Impacted is an unknown function of the component Basic Information Component. Such manipulation leads to cross-site request forgery. This vulnerability is referenced as CVE-2022-44387. It is possible to launch...]]></description>
<link>https://tsecurity.de/de/4153455/sicherheitsluecken/cve-2022-44387-eyoucms-159-utf8-sp1-basic-information-cross-site-request-forgery-issue-29-euvd-2022-47330/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153455/sicherheitsluecken/cve-2022-44387-eyoucms-159-utf8-sp1-basic-information-cross-site-request-forgery-issue-29-euvd-2022-47330/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in EyouCMS 1.5.9-UTF8-SP1. Impacted is an unknown function of the component Basic Information Component. Such manipulation leads to cross-site request forgery. This vulnerability is referenced as CVE-2022-44387. It is possible to launch the attack remotely. No exploit is available. <a href="https://vuldb.com/vuln/213681" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44390 | EyouCMS 1.5.9-UTF8-SP1 Public Security Record Number cross site scripting (Issue 31 / EUVD-2022-47333)]]></title>
<description><![CDATA[A vulnerability has been found in EyouCMS 1.5.9-UTF8-SP1 and classified as problematic. The impacted element is an unknown function of the component Public Security Record Number Handler. The manipulation leads to cross site scripting. This vulnerability is documented as CVE-2022-44390. The attac...]]></description>
<link>https://tsecurity.de/de/4153454/sicherheitsluecken/cve-2022-44390-eyoucms-159-utf8-sp1-public-security-record-number-cross-site-scripting-issue-31-euvd-2022-47333/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153454/sicherheitsluecken/cve-2022-44390-eyoucms-159-utf8-sp1-public-security-record-number-cross-site-scripting-issue-31-euvd-2022-47333/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in EyouCMS 1.5.9-UTF8-SP1 and classified as problematic. The impacted element is an unknown function of the component Public Security Record Number Handler. The manipulation leads to cross site scripting. This vulnerability is documented as CVE-2022-44390. The attack can be initiated remotely. There is not any... <a href="https://vuldb.com/vuln/213672" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44389 | EyouCMS 1.5.9-UTF8-SP1 Edit Admin Profile cross-site request forgery (Issue 30 / EUVD-2022-47332)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in EyouCMS 1.5.9-UTF8-SP1. The affected element is an unknown function of the component Edit Admin Profile Module. Executing a manipulation can lead to cross-site request forgery. This vulnerability is registered as CVE-2022-44389. I...]]></description>
<link>https://tsecurity.de/de/4153453/sicherheitsluecken/cve-2022-44389-eyoucms-159-utf8-sp1-edit-admin-profile-cross-site-request-forgery-issue-30-euvd-2022-47332/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153453/sicherheitsluecken/cve-2022-44389-eyoucms-159-utf8-sp1-edit-admin-profile-cross-site-request-forgery-issue-30-euvd-2022-47332/</guid>
<pubDate>Fri, 18 Sep 2026 06:39:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in EyouCMS 1.5.9-UTF8-SP1. The affected element is an unknown function of the component Edit Admin Profile Module. Executing a manipulation can lead to cross-site request forgery. This vulnerability is registered as CVE-2022-44389. It is possible to launch the attack remotely. No... <a href="https://vuldb.com/vuln/213671" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92991 | bdthemes Element Pack Addons for Elementor Plugin on WordPress Sigmative API display_id cross site scripting (EUVD-2026-82645)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in bdthemes Element Pack Addons for Elementor Plugin, Elementor Pixel Gallery Addons Plugin, Live Copy Paste for Elementor Plugin, Prime Slider Plugin, Smart Admin Assistant Plugin, Ultimate Post Kit Plugin and Ultimate Store Kit Plug...]]></description>
<link>https://tsecurity.de/de/4153382/sicherheitsluecken/cve-2026-92991-bdthemes-element-pack-addons-for-elementor-plugin-on-wordpress-sigmative-api-displayid-cross-site-scripting-euvd-2026-82645/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153382/sicherheitsluecken/cve-2026-92991-bdthemes-element-pack-addons-for-elementor-plugin-on-wordpress-sigmative-api-displayid-cross-site-scripting-euvd-2026-82645/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in bdthemes Element Pack Addons for Elementor Plugin, Elementor Pixel Gallery Addons Plugin, Live Copy Paste for Elementor Plugin, Prime Slider Plugin, Smart Admin Assistant Plugin, Ultimate Post Kit Plugin and Ultimate Store Kit Plugin on WordPress. This affects an unknown function of... <a href="https://vuldb.com/vuln/407339" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15650 | themewant RT Mega Menu Plugin up to 1.5.2 on WordPress Block Attribute pointer_menu_item cross site scripting (EUVD-2026-82643)]]></title>
<description><![CDATA[A vulnerability was found in themewant RT Mega Menu Plugin up to 1.5.2 on WordPress. It has been declared as problematic. The affected element is an unknown function of the component Block Attribute. Such manipulation of the argument pointer_menu_item leads to cross site scripting. This vulnerabi...]]></description>
<link>https://tsecurity.de/de/4153381/sicherheitsluecken/cve-2026-15650-themewant-rt-mega-menu-plugin-up-to-152-on-wordpress-block-attribute-pointermenuitem-cross-site-scripting-euvd-2026-82643/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153381/sicherheitsluecken/cve-2026-15650-themewant-rt-mega-menu-plugin-up-to-152-on-wordpress-block-attribute-pointermenuitem-cross-site-scripting-euvd-2026-82643/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in themewant RT Mega Menu Plugin up to 1.5.2 on WordPress. It has been declared as problematic. The affected element is an unknown function of the component Block Attribute. Such manipulation of the argument pointer_menu_item leads to cross site scripting. This vulnerability is documented as CVE-2026-15650. The attack can... <a href="https://vuldb.com/vuln/407337" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14855 | themewant RT Mega Menu Plugin up to 1.5.1 on WordPress css[left] cross site scripting (EUVD-2026-82644)]]></title>
<description><![CDATA[A vulnerability was found in themewant RT Mega Menu Plugin up to 1.5.1 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument css[left] results in cross site scripting. This vulnerability is cataloged as CVE-2026-14855. The attack ...]]></description>
<link>https://tsecurity.de/de/4153380/sicherheitsluecken/cve-2026-14855-themewant-rt-mega-menu-plugin-up-to-151-on-wordpress-cssleft-cross-site-scripting-euvd-2026-82644/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153380/sicherheitsluecken/cve-2026-14855-themewant-rt-mega-menu-plugin-up-to-151-on-wordpress-cssleft-cross-site-scripting-euvd-2026-82644/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in themewant RT Mega Menu Plugin up to 1.5.1 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation of the argument css[left] results in cross site scripting. This vulnerability is cataloged as CVE-2026-14855. The attack may be launched remotely. There is no exploit... <a href="https://vuldb.com/vuln/407335" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93468 | HGiga OAKclouds up to 106 path traversal (EUVD-2026-82642)]]></title>
<description><![CDATA[A vulnerability was found in HGiga OAKclouds up to 106. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in path traversal. This vulnerability is reported as CVE-2026-93468. The attack is possible to be carried out remotely. No explo...]]></description>
<link>https://tsecurity.de/de/4153379/sicherheitsluecken/cve-2026-93468-hgiga-oakclouds-up-to-106-path-traversal-euvd-2026-82642/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153379/sicherheitsluecken/cve-2026-93468-hgiga-oakclouds-up-to-106-path-traversal-euvd-2026-82642/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in HGiga OAKclouds up to 106. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in path traversal. This vulnerability is reported as CVE-2026-93468. The attack is possible to be carried out remotely. No exploit exists. Upgrading the affected component is... <a href="https://vuldb.com/vuln/407338" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93467 | HGiga OAKclouds-custom_page-4.0 up to 25 deserialization (EUVD-2026-82641)]]></title>
<description><![CDATA[A vulnerability was found in HGiga OAKclouds-custom_page-2.0, OAKclouds-custom_page-3.0 and OAKclouds-custom_page-4.0 up to 25. It has been classified as critical. Impacted is an unknown function. This manipulation causes deserialization. This vulnerability is registered as CVE-2026-93467. Remote...]]></description>
<link>https://tsecurity.de/de/4153378/sicherheitsluecken/cve-2026-93467-hgiga-oakclouds-custompage-40-up-to-25-deserialization-euvd-2026-82641/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153378/sicherheitsluecken/cve-2026-93467-hgiga-oakclouds-custompage-40-up-to-25-deserialization-euvd-2026-82641/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in HGiga OAKclouds-custom_page-2.0, OAKclouds-custom_page-3.0 and OAKclouds-custom_page-4.0 up to 25. It has been classified as critical. Impacted is an unknown function. This manipulation causes deserialization. This vulnerability is registered as CVE-2026-93467. Remote exploitation of the attack is possible. No exploit... <a href="https://vuldb.com/vuln/407336" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93371 | marcopiovanello yt-dlp-web-ui up to v4 generic.go NewGenericDownload params command injection (EUVD-2026-82640)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. This vulnerability is reference...]]></description>
<link>https://tsecurity.de/de/4153377/sicherheitsluecken/cve-2026-93371-marcopiovanello-yt-dlp-web-ui-up-to-v4-genericgo-newgenericdownload-params-command-injection-euvd-2026-82640/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153377/sicherheitsluecken/cve-2026-93371-marcopiovanello-yt-dlp-web-ui-up-to-v4-genericgo-newgenericdownload-params-command-injection-euvd-2026-82640/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. This vulnerability is referenced as CVE-2026-93371. It is possible to launch the... <a href="https://vuldb.com/vuln/406851" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93331 | GPAC 26.08-DEV RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt size out-of-bounds (Issue 3868 / EUVD-2026-82639)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. This vulnerability is refe...]]></description>
<link>https://tsecurity.de/de/4153376/sicherheitsluecken/cve-2026-93331-gpac-2608-dev-rtp-depacketizer-rtpdepacketizerc-gfrtpparsettxt-size-out-of-bounds-issue-3868-euvd-2026-82639/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153376/sicherheitsluecken/cve-2026-93331-gpac-2608-dev-rtp-depacketizer-rtpdepacketizerc-gfrtpparsettxt-size-out-of-bounds-issue-3868-euvd-2026-82639/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-93331. It is possible to launch... <a href="https://vuldb.com/vuln/406641" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50696 | Microsoft Windows up to Server 2025 Internet Key Exchange buffer overflow]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Microsoft Windows up to Server 2025. Impacted is an unknown function of the component Internet Key Exchange. Executing a manipulation can lead to buffer overflow. This vulnerability is handled as CVE-2026-50696. The attack can be exec...]]></description>
<link>https://tsecurity.de/de/4153375/sicherheitsluecken/cve-2026-50696-microsoft-windows-up-to-server-2025-internet-key-exchange-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153375/sicherheitsluecken/cve-2026-50696-microsoft-windows-up-to-server-2025-internet-key-exchange-buffer-overflow/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as critical has been discovered in Microsoft Windows up to Server 2025. Impacted is an unknown function of the component Internet Key Exchange. Executing a manipulation can lead to buffer overflow. This vulnerability is handled as CVE-2026-50696. The attack can be executed remotely. There is not any exploit available.... <a href="https://vuldb.com/vuln/378527" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59258 | immich-app immich up to 3.0.2 id/user access control (EUVD-2026-44755)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in immich-app immich up to 3.0.2. This impacts an unknown function. The manipulation of the argument id/user results in improper access controls. This vulnerability is cataloged as CVE-2026-59258. The attack may be launched remotely. There is no ex...]]></description>
<link>https://tsecurity.de/de/4153374/sicherheitsluecken/cve-2026-59258-immich-app-immich-up-to-302-iduser-access-control-euvd-2026-44755/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153374/sicherheitsluecken/cve-2026-59258-immich-app-immich-up-to-302-iduser-access-control-euvd-2026-44755/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in immich-app immich up to 3.0.2. This impacts an unknown function. The manipulation of the argument id/user results in improper access controls. This vulnerability is cataloged as CVE-2026-59258. The attack may be launched remotely. There is no exploit available. Upgrading the affected component is... <a href="https://vuldb.com/vuln/379345" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-59255 | SpecterOps BloodHound up to 9.4.0 Custom-Nodes API authorization (EUVD-2026-44754)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in SpecterOps BloodHound up to 9.4.0. The impacted element is an unknown function of the component Custom-Nodes API. Executing a manipulation can lead to missing authorization. This vulnerability is tracked as CVE-2026-59255. The attack ca...]]></description>
<link>https://tsecurity.de/de/4153373/sicherheitsluecken/cve-2026-59255-specterops-bloodhound-up-to-940-custom-nodes-api-authorization-euvd-2026-44754/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153373/sicherheitsluecken/cve-2026-59255-specterops-bloodhound-up-to-940-custom-nodes-api-authorization-euvd-2026-44754/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in SpecterOps BloodHound up to 9.4.0. The impacted element is an unknown function of the component Custom-Nodes API. Executing a manipulation can lead to missing authorization. This vulnerability is tracked as CVE-2026-59255. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/379343" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56176 | Microsoft Windows up to Server 2025 Win32K out-of-bounds]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Win32K. Such manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-56176. The attack can only be performe...]]></description>
<link>https://tsecurity.de/de/4153372/sicherheitsluecken/cve-2026-56176-microsoft-windows-up-to-server-2025-win32k-out-of-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153372/sicherheitsluecken/cve-2026-56176-microsoft-windows-up-to-server-2025-win32k-out-of-bounds/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Win32K. Such manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-56176. The attack can only be performed from a local environment. No exploit is available.... <a href="https://vuldb.com/vuln/378951" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62240 | crewAIInc crewAI up to 1.15.0 URL Validation validate_url server-side request forgery]]></title>
<description><![CDATA[A vulnerability was found in crewAIInc crewAI up to 1.15.0 and classified as problematic. This vulnerability affects the function validate_url of the component URL Validation. Executing a manipulation can lead to server-side request forgery. This vulnerability is tracked as CVE-2026-62240. The at...]]></description>
<link>https://tsecurity.de/de/4153371/sicherheitsluecken/cve-2026-62240-crewaiinc-crewai-up-to-1150-url-validation-validateurl-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153371/sicherheitsluecken/cve-2026-62240-crewaiinc-crewai-up-to-1150-url-validation-validateurl-server-side-request-forgery/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in crewAIInc crewAI up to 1.15.0 and classified as problematic. This vulnerability affects the function validate_url of the component URL Validation. Executing a manipulation can lead to server-side request forgery. This vulnerability is tracked as CVE-2026-62240. The attack can be launched remotely. No exploit exists. It... <a href="https://vuldb.com/vuln/378173" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-62239 | Dao-AILab FlashAttention up to 2.8.3.post1 Archive Extraction hopper/setup.py download_and_copy symlink]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Dao-AILab FlashAttention up to 2.8.3.post1. Affected by this issue is the function download_and_copy of the file hopper/setup.py of the component Archive Extraction. Such manipulation leads to symlink following. This vulnerability...]]></description>
<link>https://tsecurity.de/de/4153370/sicherheitsluecken/cve-2026-62239-dao-ailab-flashattention-up-to-283post1-archive-extraction-hoppersetuppy-downloadandcopy-symlink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153370/sicherheitsluecken/cve-2026-62239-dao-ailab-flashattention-up-to-283post1-archive-extraction-hoppersetuppy-downloadandcopy-symlink/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Dao-AILab FlashAttention up to 2.8.3.post1. Affected by this issue is the function download_and_copy of the file hopper/setup.py of the component Archive Extraction. Such manipulation leads to symlink following. This vulnerability is referenced as CVE-2026-62239. The attack can... <a href="https://vuldb.com/vuln/378171" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66395 | siyuan-note SiYuan up to 3.7.1 Bazaar Plugin Readme plugin name cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.7.1. This affects an unknown function of the component Bazaar Plugin Readme Handler. The manipulation of the argument plugin name results in cross site scripting. This vulnerability is known as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/4153369/sicherheitsluecken/cve-2026-66395-siyuan-note-siyuan-up-to-371-bazaar-plugin-readme-plugin-name-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153369/sicherheitsluecken/cve-2026-66395-siyuan-note-siyuan-up-to-371-bazaar-plugin-readme-plugin-name-cross-site-scripting/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.7.1. This affects an unknown function of the component Bazaar Plugin Readme Handler. The manipulation of the argument plugin name results in cross site scripting. This vulnerability is known as CVE-2026-66395. It is possible to launch the attack remotely.... <a href="https://vuldb.com/vuln/383491" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65013 | Onlook up to 0.2.32 tRPC API projectId/conversationId authorization (423e2e9)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Onlook up to 0.2.32. Affected by this vulnerability is the function project.get/member.remove/chat.conversation.delete of the component tRPC API. Such manipulation of the argument projectId/conversationId leads to authorization bypass. This vuln...]]></description>
<link>https://tsecurity.de/de/4153368/sicherheitsluecken/cve-2026-65013-onlook-up-to-0232-trpc-api-projectidconversationid-authorization-423e2e9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153368/sicherheitsluecken/cve-2026-65013-onlook-up-to-0232-trpc-api-projectidconversationid-authorization-423e2e9/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in Onlook up to 0.2.32. Affected by this vulnerability is the function project.get/member.remove/chat.conversation.delete of the component tRPC API. Such manipulation of the argument projectId/conversationId leads to authorization bypass. This vulnerability is uniquely identified as CVE-2026-65013.... <a href="https://vuldb.com/vuln/382383" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66396 | siyuan-note SiYuan up to 3.7.1 Gallery/Kanban Cover Images cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is an unknown function of the component Gallery/Kanban Cover Images. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2026-66396. It is p...]]></description>
<link>https://tsecurity.de/de/4153367/sicherheitsluecken/cve-2026-66396-siyuan-note-siyuan-up-to-371-gallerykanban-cover-images-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153367/sicherheitsluecken/cve-2026-66396-siyuan-note-siyuan-up-to-371-gallerykanban-cover-images-cross-site-scripting/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is an unknown function of the component Gallery/Kanban Cover Images. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2026-66396. It is possible to initiate the attack remotely. There is no... <a href="https://vuldb.com/vuln/383490" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-66005 | janhq Jan up to 0.8.4 Local API Server cross-domain policy (EUVD-2026-48611)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in janhq Jan up to 0.8.4. This issue affects some unknown processing of the component Local API Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. This vulnerability is handled as CVE-2...]]></description>
<link>https://tsecurity.de/de/4153366/sicherheitsluecken/cve-2026-66005-janhq-jan-up-to-084-local-api-server-cross-domain-policy-euvd-2026-48611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153366/sicherheitsluecken/cve-2026-66005-janhq-jan-up-to-084-local-api-server-cross-domain-policy-euvd-2026-48611/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in janhq Jan up to 0.8.4. This issue affects some unknown processing of the component Local API Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. This vulnerability is handled as CVE-2026-66005. The attack can be executed remotely.... <a href="https://vuldb.com/vuln/382937" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65606 | siyuan-note SiYuan up to 3.7.1 Protocol app/src/layout/Tab.ts innerHTML icon cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is the function innerHTML of the file app/src/layout/Tab.ts of the component Protocol Handler. The manipulation of the argument icon leads to cross site scripting. This vul...]]></description>
<link>https://tsecurity.de/de/4153365/sicherheitsluecken/cve-2026-65606-siyuan-note-siyuan-up-to-371-protocol-appsrclayouttabts-innerhtml-icon-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153365/sicherheitsluecken/cve-2026-65606-siyuan-note-siyuan-up-to-371-protocol-appsrclayouttabts-innerhtml-icon-cross-site-scripting/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is the function innerHTML of the file app/src/layout/Tab.ts of the component Protocol Handler. The manipulation of the argument icon leads to cross site scripting. This vulnerability is referenced as CVE-2026-65606. Remote... <a href="https://vuldb.com/vuln/382566" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63765 | Chatwoot up to 4.15.x Direct Uploads Controller missing authentication]]></title>
<description><![CDATA[A vulnerability was found in Chatwoot up to 4.15.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component Direct Uploads Controller. Such manipulation leads to missing authentication. This vulnerability is listed as CVE-2026-63765. The attack may b...]]></description>
<link>https://tsecurity.de/de/4153364/sicherheitsluecken/cve-2026-63765-chatwoot-up-to-415x-direct-uploads-controller-missing-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153364/sicherheitsluecken/cve-2026-63765-chatwoot-up-to-415x-direct-uploads-controller-missing-authentication/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Chatwoot up to 4.15.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component Direct Uploads Controller. Such manipulation leads to missing authentication. This vulnerability is listed as CVE-2026-63765. The attack may be performed from remote. There is no available... <a href="https://vuldb.com/vuln/382779" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-65605 | siyuan-note SiYuan up to 3.7.1 Attribute View innerHTML Template column value cross site scripting]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in siyuan-note SiYuan up to 3.7.1. This affects the function innerHTML of the component Attribute View. The manipulation of the argument Template column value results in cross site scripting. This vulnerability is known as CVE-2026-65605. It i...]]></description>
<link>https://tsecurity.de/de/4153363/sicherheitsluecken/cve-2026-65605-siyuan-note-siyuan-up-to-371-attribute-view-innerhtml-template-column-value-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153363/sicherheitsluecken/cve-2026-65605-siyuan-note-siyuan-up-to-371-attribute-view-innerhtml-template-column-value-cross-site-scripting/</guid>
<pubDate>Fri, 18 Sep 2026 05:54:13 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in siyuan-note SiYuan up to 3.7.1. This affects the function innerHTML of the component Attribute View. The manipulation of the argument Template column value results in cross site scripting. This vulnerability is known as CVE-2026-65605. It is possible to launch the attack remotely. No exploit... <a href="https://vuldb.com/vuln/382561" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges]]></title>
<description><![CDATA[A newly disclosed Windows zero-day affecting the Steam Client Service can reportedly let a standard local user obtain NT AUTHORITY\SYSTEM privileges without administrator credentials, a User Account Control prompt, Steam authentication, or launching a game. Researcher KillaBoi published the Broke...]]></description>
<link>https://tsecurity.de/de/4153347/sicherheitsluecken/steam-windows-0-day-vulnerability-allows-users-to-silently-escalate-to-full-system-privileges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153347/sicherheitsluecken/steam-windows-0-day-vulnerability-allows-users-to-silently-escalate-to-full-system-privileges/</guid>
<pubDate>Fri, 18 Sep 2026 05:52:21 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly disclosed Windows zero-day affecting the Steam Client Service can reportedly let a standard local user obtain NT AUTHORITY\SYSTEM privileges without administrator credentials, a User Account Control prompt, Steam authentication, or launching a game. Researcher KillaBoi published the BrokenPipe proof of concept on September 14, describing... <a href="https://cybersecuritynews.com/steam-windows-0-day-vulnerability/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files]]></title>
<description><![CDATA[Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs th...]]></description>
<link>https://tsecurity.de/de/4153331/sicherheitsluecken/critical-docker-sandboxes-flaw-lets-malicious-guest-code-read-and-modify-macos-host-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153331/sicherheitsluecken/critical-docker-sandboxes-flaw-lets-malicious-guest-code-read-and-modify-macos-host-files/</guid>
<pubDate>Fri, 18 Sep 2026 05:49:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is... <a href="https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root]]></title>
<description><![CDATA[A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point h...]]></description>
<link>https://tsecurity.de/de/4153329/sicherheitsluecken/critical-check-point-management-flaw-lets-unauthenticated-attackers-run-code-as-root/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153329/sicherheitsluecken/critical-check-point-management-flaw-lets-unauthenticated-attackers-run-code-as-root/</guid>
<pubDate>Fri, 18 Sep 2026 05:49:11 +0200</pubDate>
<content:encoded><![CDATA[<p>A critical vulnerability in Check Point&#039;s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update... <a href="https://thehackernews.com/2026/09/critical-check-point-management-server.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-1380 | Linux Kernel cfg80211.c brcmf_get_assoc_ies out-of-bounds (EUVD-2023-23636)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Linux Kernel. The affected element is the function brcmf_get_assoc_ies of the file drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c. Such manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-...]]></description>
<link>https://tsecurity.de/de/4153319/sicherheitsluecken/cve-2023-1380-linux-kernel-cfg80211c-brcmfgetassocies-out-of-bounds-euvd-2023-23636/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153319/sicherheitsluecken/cve-2023-1380-linux-kernel-cfg80211c-brcmfgetassocies-out-of-bounds-euvd-2023-23636/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in Linux Kernel. The affected element is the function brcmf_get_assoc_ies of the file drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c. Such manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2023-1380. The attack needs to be initiated within... <a href="https://vuldb.com/vuln/224121" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-20327 | Cisco IOS up to 15.2(8)E5 Web UI improper validation of specified type of input (cisco-sa-ios-invalid-url-dos-Nvxszf6u)]]></title>
<description><![CDATA[A vulnerability was found in Cisco IOS. It has been declared as critical. This issue affects some unknown processing of the component Web UI. The manipulation results in improper validation of specified type of input. This vulnerability was named CVE-2025-20327. The attack may be performed from r...]]></description>
<link>https://tsecurity.de/de/4153318/sicherheitsluecken/cve-2025-20327-cisco-ios-up-to-1528e5-web-ui-improper-validation-of-specified-type-of-input-cisco-sa-ios-invalid-url-dos-nvxszf6u/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153318/sicherheitsluecken/cve-2025-20327-cisco-ios-up-to-1528e5-web-ui-improper-validation-of-specified-type-of-input-cisco-sa-ios-invalid-url-dos-nvxszf6u/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Cisco IOS. It has been declared as critical. This issue affects some unknown processing of the component Web UI. The manipulation results in improper validation of specified type of input. This vulnerability was named CVE-2025-20327. The attack may be performed from remote. There is no available exploit. It is... <a href="https://vuldb.com/vuln/325759" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93382 | Google Chrome up to 153.0.8010.47 PDFium use after free (Nessus ID 346979)]]></title>
<description><![CDATA[A vulnerability has been found in Google Chrome and classified as critical. Impacted is an unknown function of the component PDFium. This manipulation causes use after free. This vulnerability is tracked as CVE-2026-93382. The attack is possible to be carried out remotely. No exploit exists. The ...]]></description>
<link>https://tsecurity.de/de/4153317/sicherheitsluecken/cve-2026-93382-google-chrome-up-to-1530801047-pdfium-use-after-free-nessus-id-346979/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153317/sicherheitsluecken/cve-2026-93382-google-chrome-up-to-1530801047-pdfium-use-after-free-nessus-id-346979/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Google Chrome and classified as critical. Impacted is an unknown function of the component PDFium. This manipulation causes use after free. This vulnerability is tracked as CVE-2026-93382. The attack is possible to be carried out remotely. No exploit exists. The affected component should be upgraded. <a href="https://vuldb.com/vuln/407138" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93373 | Google Chrome up to 153.0.8010.47 Extensions use after free (Nessus ID 346979)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Google Chrome. Affected by this issue is some unknown functionality of the component Extensions. Performing a manipulation results in use after free. This vulnerability was named CVE-2026-93373. The attack may be initiated remotely. There i...]]></description>
<link>https://tsecurity.de/de/4153316/sicherheitsluecken/cve-2026-93373-google-chrome-up-to-1530801047-extensions-use-after-free-nessus-id-346979/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153316/sicherheitsluecken/cve-2026-93373-google-chrome-up-to-1530801047-extensions-use-after-free-nessus-id-346979/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in Google Chrome. Affected by this issue is some unknown functionality of the component Extensions. Performing a manipulation results in use after free. This vulnerability was named CVE-2026-93373. The attack may be initiated remotely. There is no available exploit. It is recommended to upgrade... <a href="https://vuldb.com/vuln/407134" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93372 | Google Chrome up to 153.0.8010.47 WebGL buffer overflow (Nessus ID 346979)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Google Chrome. This impacts an unknown function of the component WebGL. The manipulation results in buffer overflow. This vulnerability is known as CVE-2026-93372. It is possible to launch the attack remotely. No exploit is available. The affe...]]></description>
<link>https://tsecurity.de/de/4153315/sicherheitsluecken/cve-2026-93372-google-chrome-up-to-1530801047-webgl-buffer-overflow-nessus-id-346979/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153315/sicherheitsluecken/cve-2026-93372-google-chrome-up-to-1530801047-webgl-buffer-overflow-nessus-id-346979/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in Google Chrome. This impacts an unknown function of the component WebGL. The manipulation results in buffer overflow. This vulnerability is known as CVE-2026-93372. It is possible to launch the attack remotely. No exploit is available. The affected component should be upgraded. <a href="https://vuldb.com/vuln/407131" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93374 | Google Chrome up to 153.0.8010.47 Dawn use after free (Nessus ID 346979)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Dawn. Such manipulation leads to use after free. This vulnerability is uniquely identified as CVE-2026-93374. The attack can be launched remotely...]]></description>
<link>https://tsecurity.de/de/4153314/sicherheitsluecken/cve-2026-93374-google-chrome-up-to-1530801047-dawn-use-after-free-nessus-id-346979/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153314/sicherheitsluecken/cve-2026-93374-google-chrome-up-to-1530801047-dawn-use-after-free-nessus-id-346979/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Dawn. Such manipulation leads to use after free. This vulnerability is uniquely identified as CVE-2026-93374. The attack can be launched remotely. No exploit exists. Upgrading the affected... <a href="https://vuldb.com/vuln/407133" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93314 | Freedesktop Poppler 26.07.0 fofi/FoFiTrueType.cc mapCodeToGID segCnt integer overflow (ID 1761 / EUVD-2026-82624)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. This vulnerability is tracked as CVE-2026-93314. ...]]></description>
<link>https://tsecurity.de/de/4153313/sicherheitsluecken/cve-2026-93314-freedesktop-poppler-26070-fofifofitruetypecc-mapcodetogid-segcnt-integer-overflow-id-1761-euvd-2026-82624/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153313/sicherheitsluecken/cve-2026-93314-freedesktop-poppler-26070-fofifofitruetypecc-mapcodetogid-segcnt-integer-overflow-id-1761-euvd-2026-82624/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. This vulnerability is tracked as CVE-2026-93314. The attack can be launched remotely. Moreover, an... <a href="https://vuldb.com/vuln/406613" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-92925 | Redis up to 8.8.1/8.9.x Cluster Bus out-of-bounds (EUVD-2026-81460)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Redis up to 8.8.1/8.9.x. The affected element is an unknown function of the component Cluster Bus. The manipulation leads to out-of-bounds read. This vulnerability is traded as CVE-2026-92925. It is possible to initiate the atta...]]></description>
<link>https://tsecurity.de/de/4153312/sicherheitsluecken/cve-2026-92925-redis-up-to-88189x-cluster-bus-out-of-bounds-euvd-2026-81460/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153312/sicherheitsluecken/cve-2026-92925-redis-up-to-88189x-cluster-bus-out-of-bounds-euvd-2026-81460/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, has been found in Redis up to 8.8.1/8.9.x. The affected element is an unknown function of the component Cluster Bus. The manipulation leads to out-of-bounds read. This vulnerability is traded as CVE-2026-92925. It is possible to initiate the attack remotely. There is no exploit available. It is... <a href="https://vuldb.com/vuln/406380" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-68493 | Nextcloud Server up to 34.0.0 privileges management (EUVD-2026-82623)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Nextcloud Server up to 34.0.0. This affects an unknown part. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as CVE-2026-68493. The attack can be launched remotely. No exploit exis...]]></description>
<link>https://tsecurity.de/de/4153311/sicherheitsluecken/cve-2026-68493-nextcloud-server-up-to-3400-privileges-management-euvd-2026-82623/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153311/sicherheitsluecken/cve-2026-68493-nextcloud-server-up-to-3400-privileges-management-euvd-2026-82623/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Nextcloud Server up to 34.0.0. This affects an unknown part. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as CVE-2026-68493. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/407333" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-82985 | Nextcloud up to 31.x Photos privileges management (EUVD-2026-82622)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Nextcloud up to 31.x. The impacted element is an unknown function of the component Photos. Executing a manipulation can lead to improper privilege management. This vulnerability is handled as CVE-2026-82985. The attack can be executed remot...]]></description>
<link>https://tsecurity.de/de/4153310/sicherheitsluecken/cve-2026-82985-nextcloud-up-to-31x-photos-privileges-management-euvd-2026-82622/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153310/sicherheitsluecken/cve-2026-82985-nextcloud-up-to-31x-photos-privileges-management-euvd-2026-82622/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in Nextcloud up to 31.x. The impacted element is an unknown function of the component Photos. Executing a manipulation can lead to improper privilege management. This vulnerability is handled as CVE-2026-82985. The attack can be executed remotely. There is not any exploit available. The... <a href="https://vuldb.com/vuln/407327" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-77164 | Nextcloud Server up to 32.0.0 Circles server-side request forgery (EUVD-2026-82621)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Nextcloud Server up to 32.0.0. This impacts an unknown function of the component Circles. The manipulation results in server-side request forgery. This vulnerability was named CVE-2026-77164. The attack may be performed from remote. ...]]></description>
<link>https://tsecurity.de/de/4153309/sicherheitsluecken/cve-2026-77164-nextcloud-server-up-to-3200-circles-server-side-request-forgery-euvd-2026-82621/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153309/sicherheitsluecken/cve-2026-77164-nextcloud-server-up-to-3200-circles-server-side-request-forgery-euvd-2026-82621/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Nextcloud Server up to 32.0.0. This impacts an unknown function of the component Circles. The manipulation results in server-side request forgery. This vulnerability was named CVE-2026-77164. The attack may be performed from remote. There is no available exploit. <a href="https://vuldb.com/vuln/407329" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89814 | Linux Kernel up to 6.18.50/7.2.4 drm/amdgpu out-of-bounds (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. This affects an unknown function of the component drm/amdgpu. Performing a manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-89814. The attack needs to be approached loca...]]></description>
<link>https://tsecurity.de/de/4153308/sicherheitsluecken/cve-2026-89814-linux-kernel-up-to-61850724-drmamdgpu-out-of-bounds-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153308/sicherheitsluecken/cve-2026-89814-linux-kernel-up-to-61850724-drmamdgpu-out-of-bounds-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. This affects an unknown function of the component drm/amdgpu. Performing a manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-89814. The attack needs to be approached locally. There is no available exploit. It is suggested... <a href="https://vuldb.com/vuln/405634" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89815 | Linux Kernel up to 7.2.4 ttm ttm_pool_restore_and_alloc stack-based overflow (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Linux Kernel up to 7.2.4. The impacted element is the function ttm_pool_restore_and_alloc of the component ttm. Such manipulation leads to stack-based buffer overflow. This vulnerability is uniquely identified as CVE-2026-89815. Local access i...]]></description>
<link>https://tsecurity.de/de/4153307/sicherheitsluecken/cve-2026-89815-linux-kernel-up-to-724-ttm-ttmpoolrestoreandalloc-stack-based-overflow-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153307/sicherheitsluecken/cve-2026-89815-linux-kernel-up-to-724-ttm-ttmpoolrestoreandalloc-stack-based-overflow-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in Linux Kernel up to 7.2.4. The impacted element is the function ttm_pool_restore_and_alloc of the component ttm. Such manipulation leads to stack-based buffer overflow. This vulnerability is uniquely identified as CVE-2026-89815. Local access is required to approach this attack. No exploit... <a href="https://vuldb.com/vuln/405633" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89817 | Linux Kernel up to 7.3-rc1 gud gud_drv.c gud_connector_add_tv_mode out-of-bounds (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.3-rc1. This affects the function gud_connector_add_tv_mode of the file drivers/gpu/drm/gud/gud_drv.c of the component gud. Such manipulation leads to out-of-bounds read. This vulnerability is listed as CVE-2026-8...]]></description>
<link>https://tsecurity.de/de/4153306/sicherheitsluecken/cve-2026-89817-linux-kernel-up-to-73-rc1-gud-guddrvc-gudconnectoraddtvmode-out-of-bounds-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153306/sicherheitsluecken/cve-2026-89817-linux-kernel-up-to-73-rc1-gud-guddrvc-gudconnectoraddtvmode-out-of-bounds-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.3-rc1. This affects the function gud_connector_add_tv_mode of the file drivers/gpu/drm/gud/gud_drv.c of the component gud. Such manipulation leads to out-of-bounds read. This vulnerability is listed as CVE-2026-89817. The attack must be carried out locally. There... <a href="https://vuldb.com/vuln/405639" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89816 | Linux Kernel up to 7.3-rc1 drm drm/ complete_signaling memory leak (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Linux Kernel up to 7.3-rc1. This impacts the function complete_signaling of the file drm/ of the component drm. Executing a manipulation can lead to memory leak. The identification of this vulnerability is CVE-2026-89816. The attack ...]]></description>
<link>https://tsecurity.de/de/4153305/sicherheitsluecken/cve-2026-89816-linux-kernel-up-to-73-rc1-drm-drm-completesignaling-memory-leak-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153305/sicherheitsluecken/cve-2026-89816-linux-kernel-up-to-73-rc1-drm-drm-completesignaling-memory-leak-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Linux Kernel up to 7.3-rc1. This impacts the function complete_signaling of the file drm/ of the component drm. Executing a manipulation can lead to memory leak. The identification of this vulnerability is CVE-2026-89816. The attack can only be executed locally. There is no exploit... <a href="https://vuldb.com/vuln/405635" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89819 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 Plane Degamma LUT Validation drm/amd/display __set_dm_plane_degamma out-of-bounds (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected is the function __set_dm_plane_degamma of the file drm/amd/display of the component Plane Degamma LUT Validation. The manipulation leads to out-of-bounds read. This vulnerability is r...]]></description>
<link>https://tsecurity.de/de/4153304/sicherheitsluecken/cve-2026-89819-linux-kernel-up-to-61210961850724-plane-degamma-lut-validation-drmamddisplay-setdmplanedegamma-out-of-bounds-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153304/sicherheitsluecken/cve-2026-89819-linux-kernel-up-to-61210961850724-plane-degamma-lut-validation-drmamddisplay-setdmplanedegamma-out-of-bounds-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected is the function __set_dm_plane_degamma of the file drm/amd/display of the component Plane Degamma LUT Validation. The manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE-2026-89819. The attack can only be... <a href="https://vuldb.com/vuln/405636" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89818 | Linux Kernel up to 7.2.4 Vcn drm/amdgpu/vcn num_buffers integer overflow (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability has been found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.50/7.2.4 and classified as critical. This vulnerability affects unknown code of the file drm/amdgpu/vcn of the component Vcn. Performing a manipulation of the argument num_buffers results in integer overflow. This ...]]></description>
<link>https://tsecurity.de/de/4153303/sicherheitsluecken/cve-2026-89818-linux-kernel-up-to-724-vcn-drmamdgpuvcn-numbuffers-integer-overflow-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153303/sicherheitsluecken/cve-2026-89818-linux-kernel-up-to-724-vcn-drmamdgpuvcn-numbuffers-integer-overflow-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Linux Kernel up to 6.1.187/6.6.156/6.12.109/6.18.50/7.2.4 and classified as critical. This vulnerability affects unknown code of the file drm/amdgpu/vcn of the component Vcn. Performing a manipulation of the argument num_buffers results in integer overflow. This vulnerability is cataloged as CVE-2026-89818. The... <a href="https://vuldb.com/vuln/405640" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-87886 | Acronis Backup Plugin permission]]></title>
<description><![CDATA[A vulnerability was found in Acronis Backup Plugin, Acronis Backup Extension and Acronis Backup Plugin. It has been classified as very critical. Affected is an unknown function. Performing a manipulation results in permission issues. This vulnerability is reported as CVE-2026-87886. The attack re...]]></description>
<link>https://tsecurity.de/de/4153302/sicherheitsluecken/cve-2026-87886-acronis-backup-plugin-permission/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153302/sicherheitsluecken/cve-2026-87886-acronis-backup-plugin-permission/</guid>
<pubDate>Fri, 18 Sep 2026 05:10:04 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Acronis Backup Plugin, Acronis Backup Extension and Acronis Backup Plugin. It has been classified as very critical. Affected is an unknown function. Performing a manipulation results in permission issues. This vulnerability is reported as CVE-2026-87886. The attack requires a local approach. Moreover, an exploit is... <a href="https://vuldb.com/vuln/407308" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LiveOverflow: How OpenAI got hacked with an image]]></title>
<description><![CDATA[YouTube VideoTwo guys hacked OpenAI with a malicious HEIF image. They turned a one year old libheif heap overflow into a remote code execution on OpenAI's Discourse forum, took over an employee's ChatGPT account, and left a message in the internal monorepo. This story shows how AI changes the eco...]]></description>
<link>https://tsecurity.de/de/4153281/sicherheitsluecken/how-openai-got-hacked-with-an-image/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153281/sicherheitsluecken/how-openai-got-hacked-with-an-image/</guid>
<pubDate>Fri, 18 Sep 2026 05:00:37 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/gjHh9g7yo9Y"></iframe></p><div class="youtube-description">Two guys hacked OpenAI with a malicious HEIF image. They turned a one year old libheif heap overflow into a remote code execution on OpenAI&#039;s Discourse forum, took over an employee&#039;s ChatGPT account, and left a message in the internal monorepo. This story shows how AI changes the economics of exploit development and why security through complexity doesn&#039;t work anymore.<br />
<br />
LEARN ON HEXTREE (ad)<br />
Learn hacking on Hextree: https://www.hextree.io/<br />
Learn more about AI on Hextree: https://app.hextree.io/map/artificial-intelligence<br />
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy<br />
<br />
IMPORTANT FOR SELF-HOSTED DISCOURSE<br />
Rebuild your Discourse installation to pull the current image-processing dependencies. Updating only through the web interface may not replace an older Libheif package.<br />
<br />
RESOURCES<br />
Hacktron research: https://www.hacktron.ai/blog<br />
Harsh on X: https://x.com/rootxharsh<br />
Mohan on X: https://x.com/S1r1u5_<br />
<br />
CHAPTERS<br />
00:00 - Introduction<br />
01:37 - Chapter 1: Vulnerability Research<br />
05:39 - Chapter 2: The Vulnerability in Libheif<br />
08:49 - Chapter 3: Hacking into OpenAI<br />
11:32 - Chapter 4: Disclosure<br />
13:17 - Chapter 5: Hack the Planet<br />
17:19 - Outro<br />
<br />
SUPPORT<br />
Per video: https://www.patreon.com/join/liveoverflow<br />
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join<br />
Buy my handwriting font (ad): https://shop.liveoverflow.com/<br />
<br />
WATCH, FOLLOW &amp; READ<br />
Second channel: https://www.youtube.com/LiveUnderflow<br />
Twitch: https://twitch.tv/LiveOverflow/<br />
Twitter: https://twitter.com/LiveOverflow/<br />
Instagram: https://instagram.com/LiveOverflow/<br />
TikTok: https://www.tiktok.com/@liveoverflow_<br />
LiveOverflow blog: https://liveoverflow.com/<br />
Hextree blog (ad): https://www.hextree.io/blog<br />
<br />
#OpenAI #ChatGPT #LiveOverflow<br />
<br />
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.</div>]]></content:encoded>
<enclosure url="https://i4.ytimg.com/vi/gjHh9g7yo9Y/hqdefault.jpg" length="0" type="image/jpeg" />
</item>
<item>
<title><![CDATA[CVE-2022-44365 | Tenda i21 1.0.0.14 /goform/setSysPwd stack-based overflow (EUVD-2022-47310)]]></title>
<description><![CDATA[A vulnerability was found in Tenda i21 1.0.0.14. It has been rated as critical. This affects an unknown part of the file /goform/setSysPwd. This manipulation causes stack-based buffer overflow. This vulnerability is handled as CVE-2022-44365. The attack can only be done within the local network. ...]]></description>
<link>https://tsecurity.de/de/4153279/sicherheitsluecken/cve-2022-44365-tenda-i21-10014-goformsetsyspwd-stack-based-overflow-euvd-2022-47310/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153279/sicherheitsluecken/cve-2022-44365-tenda-i21-10014-goformsetsyspwd-stack-based-overflow-euvd-2022-47310/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Tenda i21 1.0.0.14. It has been rated as critical. This affects an unknown part of the file /goform/setSysPwd. This manipulation causes stack-based buffer overflow. This vulnerability is handled as CVE-2022-44365. The attack can only be done within the local network. There is not any exploit available. <a href="https://vuldb.com/vuln/214712" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44367 | Tenda i21 1.0.0.14 /goform/setUplinkInfo buffer overflow (EUVD-2022-47312)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Tenda i21 1.0.0.14. This issue affects some unknown processing of the file /goform/setUplinkInfo. Performing a manipulation results in buffer overflow. This vulnerability was named CVE-2022-44367. The attack needs to be approached within...]]></description>
<link>https://tsecurity.de/de/4153278/sicherheitsluecken/cve-2022-44367-tenda-i21-10014-goformsetuplinkinfo-buffer-overflow-euvd-2022-47312/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153278/sicherheitsluecken/cve-2022-44367-tenda-i21-10014-goformsetuplinkinfo-buffer-overflow-euvd-2022-47312/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in Tenda i21 1.0.0.14. This issue affects some unknown processing of the file /goform/setUplinkInfo. Performing a manipulation results in buffer overflow. This vulnerability was named CVE-2022-44367. The attack needs to be approached within the local network. There is no available exploit. <a href="https://vuldb.com/vuln/214714" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44368 | NASM 2.16 null pointer dereference (EUVD-2022-47313)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in NASM 2.16. This vulnerability affects unknown code. This manipulation causes null pointer dereference. This vulnerability is tracked as CVE-2022-44368. The attack is only possible within the local network. No exploit exists. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153277/sicherheitsluecken/cve-2022-44368-nasm-216-null-pointer-dereference-euvd-2022-47313/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153277/sicherheitsluecken/cve-2022-44368-nasm-216-null-pointer-dereference-euvd-2022-47313/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in NASM 2.16. This vulnerability affects unknown code. This manipulation causes null pointer dereference. This vulnerability is tracked as CVE-2022-44368. The attack is only possible within the local network. No exploit exists. <a href="https://vuldb.com/vuln/224558" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44369 | NASM 2.16 output/outaout.c null pointer dereference (EUVD-2022-47314)]]></title>
<description><![CDATA[A vulnerability was found in NASM 2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the file output/outaout.c. Executing a manipulation can lead to null pointer dereference. This vulnerability is handled as CVE-2022-44369. The attack can only be do...]]></description>
<link>https://tsecurity.de/de/4153276/sicherheitsluecken/cve-2022-44369-nasm-216-outputoutaoutc-null-pointer-dereference-euvd-2022-47314/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153276/sicherheitsluecken/cve-2022-44369-nasm-216-outputoutaoutc-null-pointer-dereference-euvd-2022-47314/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in NASM 2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the file output/outaout.c. Executing a manipulation can lead to null pointer dereference. This vulnerability is handled as CVE-2022-44369. The attack can only be done within the local network. There is not any... <a href="https://vuldb.com/vuln/224567" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44371 | hope-boot 1.0.0 deserialization (Issue 83 / EUVD-2022-47316)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in hope-boot 1.0.0. This affects an unknown function. Performing a manipulation results in deserialization. This vulnerability is identified as CVE-2022-44371. The attack can be initiated remotely. There is not any exploit available. Weiter...]]></description>
<link>https://tsecurity.de/de/4153275/sicherheitsluecken/cve-2022-44371-hope-boot-100-deserialization-issue-83-euvd-2022-47316/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153275/sicherheitsluecken/cve-2022-44371-hope-boot-100-deserialization-issue-83-euvd-2022-47316/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in hope-boot 1.0.0. This affects an unknown function. Performing a manipulation results in deserialization. This vulnerability is identified as CVE-2022-44371. The attack can be initiated remotely. There is not any exploit available. <a href="https://vuldb.com/vuln/215092" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44373 | TRENDnet Wireless AC Easy-Upgrader TEW-820AP 1.0R stack-based overflow (EUVD-2022-47318)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in TRENDnet Wireless AC Easy-Upgrader TEW-820AP 1.0R. Affected by this vulnerability is an unknown functionality. The manipulation leads to stack-based buffer overflow. This vulnerability is referenced as CVE-2022-44373. Remote exploitation...]]></description>
<link>https://tsecurity.de/de/4153274/sicherheitsluecken/cve-2022-44373-trendnet-wireless-ac-easy-upgrader-tew-820ap-10r-stack-based-overflow-euvd-2022-47318/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153274/sicherheitsluecken/cve-2022-44373-trendnet-wireless-ac-easy-upgrader-tew-820ap-10r-stack-based-overflow-euvd-2022-47318/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in TRENDnet Wireless AC Easy-Upgrader TEW-820AP 1.0R. Affected by this vulnerability is an unknown functionality. The manipulation leads to stack-based buffer overflow. This vulnerability is referenced as CVE-2022-44373. Remote exploitation of the attack is possible. No exploit is available. <a href="https://vuldb.com/vuln/215106" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44378 | Automotive Shop Management System 1.0 Master.php?f=delete_mechanic sql injection (EUVD-2022-47323)]]></title>
<description><![CDATA[A vulnerability was found in Automotive Shop Management System 1.0. It has been classified as critical. This affects an unknown function of the file /asms/classes/Master.php?f=delete_mechanic. This manipulation causes sql injection. This vulnerability is registered as CVE-2022-44378. The attack r...]]></description>
<link>https://tsecurity.de/de/4153273/sicherheitsluecken/cve-2022-44378-automotive-shop-management-system-10-masterphpfdeletemechanic-sql-injection-euvd-2022-47323/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153273/sicherheitsluecken/cve-2022-44378-automotive-shop-management-system-10-masterphpfdeletemechanic-sql-injection-euvd-2022-47323/</guid>
<pubDate>Fri, 18 Sep 2026 04:10:01 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Automotive Shop Management System 1.0. It has been classified as critical. This affects an unknown function of the file /asms/classes/Master.php?f=delete_mechanic. This manipulation causes sql injection. This vulnerability is registered as CVE-2022-44378. The attack requires access to the local network. No exploit is... <a href="https://vuldb.com/vuln/213926" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20716 | Intel Processors access control (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Intel Processors. This affects an unknown function. Such manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-20716. The attack can only be performed from a local environment. No exploit is available. W...]]></description>
<link>https://tsecurity.de/de/4153252/sicherheitsluecken/cve-2026-20716-intel-processors-access-control-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153252/sicherheitsluecken/cve-2026-20716-intel-processors-access-control-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:07 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Intel Processors. This affects an unknown function. Such manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-20716. The attack can only be performed from a local environment. No exploit is available. <a href="https://vuldb.com/vuln/388221" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20760 | Intel Processors Microcode privileges management (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Intel Processors. The impacted element is an unknown function of the component Microcode. Executing a manipulation can lead to improper privilege management. This vulnerability appears as CVE-2026-20760. The attack requires local...]]></description>
<link>https://tsecurity.de/de/4153251/sicherheitsluecken/cve-2026-20760-intel-processors-microcode-privileges-management-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153251/sicherheitsluecken/cve-2026-20760-intel-processors-microcode-privileges-management-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:07 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as very critical has been discovered in Intel Processors. The impacted element is an unknown function of the component Microcode. Executing a manipulation can lead to improper privilege management. This vulnerability appears as CVE-2026-20760. The attack requires local access. There is no available exploit. <a href="https://vuldb.com/vuln/388649" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20713 | Intel Xeon processors control flow (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Intel Xeon processors. The impacted element is an unknown function. This manipulation causes incorrect control flow. The identification of this vulnerability is CVE-2026-20713. The attack can only be executed locally. There is no exploit...]]></description>
<link>https://tsecurity.de/de/4153250/sicherheitsluecken/cve-2026-20713-intel-xeon-processors-control-flow-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153250/sicherheitsluecken/cve-2026-20713-intel-xeon-processors-control-flow-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:07 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in Intel Xeon processors. The impacted element is an unknown function. This manipulation causes incorrect control flow. The identification of this vulnerability is CVE-2026-20713. The attack can only be executed locally. There is no exploit available. <a href="https://vuldb.com/vuln/388220" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20707 | Intel Xeon Scalable Processors race condition (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Intel Xeon Scalable Processors. The affected element is an unknown function. The manipulation results in race condition. This vulnerability was named CVE-2026-20707. The attack needs to be approached locally. There is no available explo...]]></description>
<link>https://tsecurity.de/de/4153249/sicherheitsluecken/cve-2026-20707-intel-xeon-scalable-processors-race-condition-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153249/sicherheitsluecken/cve-2026-20707-intel-xeon-scalable-processors-race-condition-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:07 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in Intel Xeon Scalable Processors. The affected element is an unknown function. The manipulation results in race condition. This vulnerability was named CVE-2026-20707. The attack needs to be approached locally. There is no available exploit. <a href="https://vuldb.com/vuln/388219" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20901 | Intel Xeon Processors Firmware input validation (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Intel Xeon Processors. Affected is an unknown function of the component Firmware. Executing a manipulation can lead to improper input validation. The identification of this vulnerability is CVE-2026-20901. The attack can only be ex...]]></description>
<link>https://tsecurity.de/de/4153248/sicherheitsluecken/cve-2026-20901-intel-xeon-processors-firmware-input-validation-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153248/sicherheitsluecken/cve-2026-20901-intel-xeon-processors-firmware-input-validation-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in Intel Xeon Processors. Affected is an unknown function of the component Firmware. Executing a manipulation can lead to improper input validation. The identification of this vulnerability is CVE-2026-20901. The attack can only be executed locally. There is no exploit available. <a href="https://vuldb.com/vuln/388355" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-91097 | HP Linux Imaging and Printing Software up to 3.26.5 privileges management (Nessus ID 346887)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in HP Linux Imaging and Printing Software up to 3.26.5. This affects an unknown part. The manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2026-91097. The attack is possible to be carried out...]]></description>
<link>https://tsecurity.de/de/4153247/sicherheitsluecken/cve-2026-91097-hp-linux-imaging-and-printing-software-up-to-3265-privileges-management-nessus-id-346887/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153247/sicherheitsluecken/cve-2026-91097-hp-linux-imaging-and-printing-software-up-to-3265-privileges-management-nessus-id-346887/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in HP Linux Imaging and Printing Software up to 3.26.5. This affects an unknown part. The manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2026-91097. The attack is possible to be carried out remotely. No exploit exists. It is suggested to... <a href="https://vuldb.com/vuln/406068" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44347 | Sanitization Management System 1.0 view_inquiry ID sql injection (EUVD-2022-47292)]]></title>
<description><![CDATA[A vulnerability was found in Sanitization Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php-sms/admin/?page=inquiries/view_inquiry. The manipulation of the argument ID results in sql injection. This vulnerability is known as CVE-2022-443...]]></description>
<link>https://tsecurity.de/de/4153246/sicherheitsluecken/cve-2022-44347-sanitization-management-system-10-viewinquiry-id-sql-injection-euvd-2022-47292/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153246/sicherheitsluecken/cve-2022-44347-sanitization-management-system-10-viewinquiry-id-sql-injection-euvd-2022-47292/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Sanitization Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php-sms/admin/?page=inquiries/view_inquiry. The manipulation of the argument ID results in sql injection. This vulnerability is known as CVE-2022-44347. Access to the local network is required for this... <a href="https://vuldb.com/vuln/214681" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44348 | Sanitization Management System 1.0 update_status.php ID sql injection (EUVD-2022-47293)]]></title>
<description><![CDATA[A vulnerability was found in Sanitization Management System 1.0. It has been classified as critical. Impacted is an unknown function of the file /php-sms/admin/orders/update_status.php. This manipulation of the argument ID causes sql injection. This vulnerability is handled as CVE-2022-44348. The...]]></description>
<link>https://tsecurity.de/de/4153245/sicherheitsluecken/cve-2022-44348-sanitization-management-system-10-updatestatusphp-id-sql-injection-euvd-2022-47293/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153245/sicherheitsluecken/cve-2022-44348-sanitization-management-system-10-updatestatusphp-id-sql-injection-euvd-2022-47293/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Sanitization Management System 1.0. It has been classified as critical. Impacted is an unknown function of the file /php-sms/admin/orders/update_status.php. This manipulation of the argument ID causes sql injection. This vulnerability is handled as CVE-2022-44348. The attack can only be done within the local network.... <a href="https://vuldb.com/vuln/214682" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44349 | NAVBLUE S.A.S N-Ops & Crew 22.5-rc.50 cross site scripting (EUVD-2022-47294)]]></title>
<description><![CDATA[A vulnerability has been found in NAVBLUE S.A.S N-Ops &amp; Crew 22.5-rc.50 and classified as problematic. The affected element is an unknown function. Performing a manipulation results in cross site scripting. This vulnerability was named CVE-2022-44349. The attack may be initiated remotely. The...]]></description>
<link>https://tsecurity.de/de/4153244/sicherheitsluecken/cve-2022-44349-navblue-sas-n-ops-crew-225-rc50-cross-site-scripting-euvd-2022-47294/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153244/sicherheitsluecken/cve-2022-44349-navblue-sas-n-ops-crew-225-rc50-cross-site-scripting-euvd-2022-47294/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in NAVBLUE S.A.S N-Ops &amp;amp; Crew 22.5-rc.50 and classified as problematic. The affected element is an unknown function. Performing a manipulation results in cross site scripting. This vulnerability was named CVE-2022-44349. The attack may be initiated remotely. There is no available exploit. <a href="https://vuldb.com/vuln/238564" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44351 | Zorlan Skycaiji 2.5.1 Mystore.php deserialization (Issue 46 / EUVD-2022-47296)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Zorlan Skycaiji 2.5.1. This issue affects some unknown processing of the file /SkycaijiApp/admin/controller/Mystore.php. Executing a manipulation can lead to deserialization. This vulnerability appears as CVE-2022-44351. The attac...]]></description>
<link>https://tsecurity.de/de/4153243/sicherheitsluecken/cve-2022-44351-zorlan-skycaiji-251-mystorephp-deserialization-issue-46-euvd-2022-47296/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153243/sicherheitsluecken/cve-2022-44351-zorlan-skycaiji-251-mystorephp-deserialization-issue-46-euvd-2022-47296/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Zorlan Skycaiji 2.5.1. This issue affects some unknown processing of the file /SkycaijiApp/admin/controller/Mystore.php. Executing a manipulation can lead to deserialization. This vulnerability appears as CVE-2022-44351. The attacker needs to be present on the local network. There... <a href="https://vuldb.com/vuln/215099" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44354 | SolarView Compact 4.0/5.0 unrestricted upload (EUVD-2022-47299)]]></title>
<description><![CDATA[A vulnerability was found in SolarView Compact 4.0/5.0. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in unrestricted upload. This vulnerability is reported as CVE-2022-44354. The attacker must have access to the local network to execute the att...]]></description>
<link>https://tsecurity.de/de/4153242/sicherheitsluecken/cve-2022-44354-solarview-compact-4050-unrestricted-upload-euvd-2022-47299/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153242/sicherheitsluecken/cve-2022-44354-solarview-compact-4050-unrestricted-upload-euvd-2022-47299/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in SolarView Compact 4.0/5.0. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in unrestricted upload. This vulnerability is reported as CVE-2022-44354. The attacker must have access to the local network to execute the attack. No exploit exists. <a href="https://vuldb.com/vuln/214558" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64684 | Model Context Protocol RMCP SDK up to 2.0.x StreamableHttpClientTransport streamable_http_client.rs apply_custom_headers information disclosure (Nessus ID 346886)]]></title>
<description><![CDATA[A vulnerability was found in Model Context Protocol RMCP SDK up to 2.0.x and classified as problematic. Affected by this issue is the function apply_custom_headers of the file crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs of the component StreamableHttpClientTransport. The ma...]]></description>
<link>https://tsecurity.de/de/4153241/sicherheitsluecken/cve-2026-64684-model-context-protocol-rmcp-sdk-up-to-20x-streamablehttpclienttransport-streamablehttpclientrs-applycustomheaders-information-disclosure-nessus-id-346886/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153241/sicherheitsluecken/cve-2026-64684-model-context-protocol-rmcp-sdk-up-to-20x-streamablehttpclienttransport-streamablehttpclientrs-applycustomheaders-information-disclosure-nessus-id-346886/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Model Context Protocol RMCP SDK up to 2.0.x and classified as problematic. Affected by this issue is the function apply_custom_headers of the file crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs of the component StreamableHttpClientTransport. The manipulation results in information disclosure. This... <a href="https://vuldb.com/vuln/406243" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-91105 | HP HPLIP up to 3.26.5 privileges management (Nessus ID 346885)]]></title>
<description><![CDATA[A vulnerability was found in HP HPLIP up to 3.26.5. It has been classified as critical. Affected is an unknown function. This manipulation causes improper privilege management. This vulnerability is registered as CVE-2026-91105. Remote exploitation of the attack is possible. No exploit is availab...]]></description>
<link>https://tsecurity.de/de/4153240/sicherheitsluecken/cve-2026-91105-hp-hplip-up-to-3265-privileges-management-nessus-id-346885/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153240/sicherheitsluecken/cve-2026-91105-hp-hplip-up-to-3265-privileges-management-nessus-id-346885/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in HP HPLIP up to 3.26.5. It has been classified as critical. Affected is an unknown function. This manipulation causes improper privilege management. This vulnerability is registered as CVE-2026-91105. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component is recommended. <a href="https://vuldb.com/vuln/406076" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-91102 | HP HPLIP up to 3.26.5 privileges management (Nessus ID 346884)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation leads to improper privilege management. This vulnerability is traded as CVE-2026-91102. It is possible to initiate the attack remotely. There is no exploit ...]]></description>
<link>https://tsecurity.de/de/4153239/sicherheitsluecken/cve-2026-91102-hp-hplip-up-to-3265-privileges-management-nessus-id-346884/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153239/sicherheitsluecken/cve-2026-91102-hp-hplip-up-to-3265-privileges-management-nessus-id-346884/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation leads to improper privilege management. This vulnerability is traded as CVE-2026-91102. It is possible to initiate the attack remotely. There is no exploit available. You should upgrade the affected component. <a href="https://vuldb.com/vuln/406080" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-91098 | HP HPLIP up to 3.26.5 privilege escalation (Nessus ID 346883)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation results in privilege escalation. This vulnerability was named CVE-2026-91098. The attack may be performed from remote. There is no available exploit. Upgra...]]></description>
<link>https://tsecurity.de/de/4153238/sicherheitsluecken/cve-2026-91098-hp-hplip-up-to-3265-privilege-escalation-nessus-id-346883/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153238/sicherheitsluecken/cve-2026-91098-hp-hplip-up-to-3265-privilege-escalation-nessus-id-346883/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in HP HPLIP up to 3.26.5. This vulnerability affects unknown code. The manipulation results in privilege escalation. This vulnerability was named CVE-2026-91098. The attack may be performed from remote. There is no available exploit. Upgrading the affected component is recommended. <a href="https://vuldb.com/vuln/406069" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44355 | SolarView Compact 7.0 /network_test.php cross site scripting (EUVD-2022-47300)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in SolarView Compact 7.0. Affected by this issue is some unknown functionality of the file /network_test.php. The manipulation results in cross site scripting. This vulnerability was named CVE-2022-44355. The attack may be performed from remote....]]></description>
<link>https://tsecurity.de/de/4153237/sicherheitsluecken/cve-2022-44355-solarview-compact-70-networktestphp-cross-site-scripting-euvd-2022-47300/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153237/sicherheitsluecken/cve-2022-44355-solarview-compact-70-networktestphp-cross-site-scripting-euvd-2022-47300/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in SolarView Compact 7.0. Affected by this issue is some unknown functionality of the file /network_test.php. The manipulation results in cross site scripting. This vulnerability was named CVE-2022-44355. The attack may be performed from remote. There is no available exploit. <a href="https://vuldb.com/vuln/214579" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44361 | ZZCMS 2022 admin/ad_list.php cross site scripting (EUVD-2022-47306)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in ZZCMS 2022. This impacts an unknown function of the file admin/ad_list.php. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44361. The attack can be launched remotely. No exploit exists. ...]]></description>
<link>https://tsecurity.de/de/4153236/sicherheitsluecken/cve-2022-44361-zzcms-2022-adminadlistphp-cross-site-scripting-euvd-2022-47306/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153236/sicherheitsluecken/cve-2022-44361-zzcms-2022-adminadlistphp-cross-site-scripting-euvd-2022-47306/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as problematic has been found in ZZCMS 2022. This impacts an unknown function of the file admin/ad_list.php. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44361. The attack can be launched remotely. No exploit exists. <a href="https://vuldb.com/vuln/215093" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44362 | Tenda i21 1.0.0.14 /goform/AddSysLogRule buffer overflow (EUVD-2022-47307)]]></title>
<description><![CDATA[A vulnerability was found in Tenda i21 1.0.0.14. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/AddSysLogRule. The manipulation leads to buffer overflow. This vulnerability is traded as CVE-2022-44362. Access to the local network...]]></description>
<link>https://tsecurity.de/de/4153235/sicherheitsluecken/cve-2022-44362-tenda-i21-10014-goformaddsyslogrule-buffer-overflow-euvd-2022-47307/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153235/sicherheitsluecken/cve-2022-44362-tenda-i21-10014-goformaddsyslogrule-buffer-overflow-euvd-2022-47307/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Tenda i21 1.0.0.14. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/AddSysLogRule. The manipulation leads to buffer overflow. This vulnerability is traded as CVE-2022-44362. Access to the local network is required for this attack to succeed. There is no... <a href="https://vuldb.com/vuln/214710" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44363 | Tenda i21 1.0.0.14 /goform/setSnmpInfo buffer overflow (EUVD-2022-47308)]]></title>
<description><![CDATA[A vulnerability was found in Tenda i21 1.0.0.14. It has been declared as critical. Affected by this issue is some unknown functionality of the file /goform/setSnmpInfo. The manipulation results in buffer overflow. This vulnerability is known as CVE-2022-44363. Access to the local network is requi...]]></description>
<link>https://tsecurity.de/de/4153234/sicherheitsluecken/cve-2022-44363-tenda-i21-10014-goformsetsnmpinfo-buffer-overflow-euvd-2022-47308/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153234/sicherheitsluecken/cve-2022-44363-tenda-i21-10014-goformsetsnmpinfo-buffer-overflow-euvd-2022-47308/</guid>
<pubDate>Fri, 18 Sep 2026 03:40:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Tenda i21 1.0.0.14. It has been declared as critical. Affected by this issue is some unknown functionality of the file /goform/setSnmpInfo. The manipulation results in buffer overflow. This vulnerability is known as CVE-2022-44363. Access to the local network is required for this attack. No exploit is available. <a href="https://vuldb.com/vuln/214711" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89806 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 Sysfb drm/sysfb integer overflow (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. It has been classified as very critical. This affects an unknown part of the file drm/sysfb of the component Sysfb. Performing a manipulation results in integer overflow. This vulnerability is reported as CVE-2026-89806. The a...]]></description>
<link>https://tsecurity.de/de/4153203/sicherheitsluecken/cve-2026-89806-linux-kernel-up-to-6185072473-rc1-sysfb-drmsysfb-integer-overflow-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153203/sicherheitsluecken/cve-2026-89806-linux-kernel-up-to-6185072473-rc1-sysfb-drmsysfb-integer-overflow-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. It has been classified as very critical. This affects an unknown part of the file drm/sysfb of the component Sysfb. Performing a manipulation results in integer overflow. This vulnerability is reported as CVE-2026-89806. The attack requires a local approach. No exploit exists.... <a href="https://vuldb.com/vuln/405628" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89807 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 amdkfd amdkfd.c create_queue_cpsch/create_queue_nocpsch null pointer dereference (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. It has been declared as problematic. This vulnerability affects the function create_queue_cpsch/create_queue_nocpsch of the file drivers/gpu/drm/amd/amdkfd/amdkfd.c of the component amdkfd. Executing a manipulation can lead t...]]></description>
<link>https://tsecurity.de/de/4153202/sicherheitsluecken/cve-2026-89807-linux-kernel-up-to-61210961850724-amdkfd-amdkfdc-createqueuecpschcreatequeuenocpsch-null-pointer-dereference-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153202/sicherheitsluecken/cve-2026-89807-linux-kernel-up-to-61210961850724-amdkfd-amdkfdc-createqueuecpschcreatequeuenocpsch-null-pointer-dereference-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. It has been declared as problematic. This vulnerability affects the function create_queue_cpsch/create_queue_nocpsch of the file drivers/gpu/drm/amd/amdkfd/amdkfd.c of the component amdkfd. Executing a manipulation can lead to null pointer dereference. This vulnerability... <a href="https://vuldb.com/vuln/405629" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89810 | Linux Kernel up to 6.18.50/7.2.4 amdkfd drm/amdkfd svm_migrate_copy_to_ram allocation of resources (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. Impacted is the function svm_migrate_copy_to_ram of the file drm/amdkfd of the component amdkfd. The manipulation results in allocation of resources. This vulnerability is known as CVE-2026-89810...]]></description>
<link>https://tsecurity.de/de/4153201/sicherheitsluecken/cve-2026-89810-linux-kernel-up-to-61850724-amdkfd-drmamdkfd-svmmigratecopytoram-allocation-of-resources-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153201/sicherheitsluecken/cve-2026-89810-linux-kernel-up-to-61850724-amdkfd-drmamdkfd-svmmigratecopytoram-allocation-of-resources-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. Impacted is the function svm_migrate_copy_to_ram of the file drm/amdkfd of the component amdkfd. The manipulation results in allocation of resources. This vulnerability is known as CVE-2026-89810. It is possible to launch the attack remotely. No... <a href="https://vuldb.com/vuln/405631" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89808 | Linux Kernel up to 6.18.50/7.2.4 amdkfd svm_migrate_copy_memory_gart uninitialized variable (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4. It has been rated as very critical. This issue affects the function svm_migrate_copy_memory_gart of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd. The manipulation leads to use of uninitialized variable. This vulnerabili...]]></description>
<link>https://tsecurity.de/de/4153200/sicherheitsluecken/cve-2026-89808-linux-kernel-up-to-61850724-amdkfd-svmmigratecopymemorygart-uninitialized-variable-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153200/sicherheitsluecken/cve-2026-89808-linux-kernel-up-to-61850724-amdkfd-svmmigratecopymemorygart-uninitialized-variable-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4. It has been rated as very critical. This issue affects the function svm_migrate_copy_memory_gart of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd. The manipulation leads to use of uninitialized variable. This vulnerability is traded as CVE-2026-89808. It is possible to... <a href="https://vuldb.com/vuln/405630" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89809 | Linux Kernel up to 7.2.4/7.3-rc1 amdkfd mqds pqm_debugfs_mqds pqn null pointer dereference (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Linux Kernel up to 7.2.4/7.3-rc1. Affected is the function pqm_debugfs_mqds of the file /sys/kernel/debug/kfd/mqds of the component amdkfd. The manipulation of the argument pqn results in null pointer dereference. This vulnerabili...]]></description>
<link>https://tsecurity.de/de/4153199/sicherheitsluecken/cve-2026-89809-linux-kernel-up-to-72473-rc1-amdkfd-mqds-pqmdebugfsmqds-pqn-null-pointer-dereference-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153199/sicherheitsluecken/cve-2026-89809-linux-kernel-up-to-72473-rc1-amdkfd-mqds-pqmdebugfsmqds-pqn-null-pointer-dereference-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Linux Kernel up to 7.2.4/7.3-rc1. Affected is the function pqm_debugfs_mqds of the file /sys/kernel/debug/kfd/mqds of the component amdkfd. The manipulation of the argument pqn results in null pointer dereference. This vulnerability is cataloged as CVE-2026-89809. The attack must... <a href="https://vuldb.com/vuln/405625" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89812 | Linux Kernel MES ring amdgpu_device_pre_asic_reset infinite loop (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function amdgpu_device_pre_asic_reset of the component MES ring. This manipulation causes infinite loop. This vulnerability is registered as CVE-2026-89812. Remote exploitation of the ...]]></description>
<link>https://tsecurity.de/de/4153198/sicherheitsluecken/cve-2026-89812-linux-kernel-mes-ring-amdgpudevicepreasicreset-infinite-loop-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153198/sicherheitsluecken/cve-2026-89812-linux-kernel-mes-ring-amdgpudevicepreasicreset-infinite-loop-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function amdgpu_device_pre_asic_reset of the component MES ring. This manipulation causes infinite loop. This vulnerability is registered as CVE-2026-89812. Remote exploitation of the attack is possible. No exploit is available. It is... <a href="https://vuldb.com/vuln/405626" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89811 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 amdkfd/MES Queue Management amdkfd evict_process_queues_cpsch/suspend_queues race condition (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This impacts the function evict_process_queues_cpsch/suspend_queues of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd/MES Queue Management. The manipulation leads to ra...]]></description>
<link>https://tsecurity.de/de/4153197/sicherheitsluecken/cve-2026-89811-linux-kernel-up-to-6185072473-rc1-amdkfdmes-queue-management-amdkfd-evictprocessqueuescpschsuspendqueues-race-condition-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153197/sicherheitsluecken/cve-2026-89811-linux-kernel-up-to-6185072473-rc1-amdkfdmes-queue-management-amdkfd-evictprocessqueuescpschsuspendqueues-race-condition-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This impacts the function evict_process_queues_cpsch/suspend_queues of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd/MES Queue Management. The manipulation leads to race condition. This vulnerability is listed as... <a href="https://vuldb.com/vuln/405624" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-89813 | Linux Kernel up to 7.2.4 KIQ ring drm/amdgpu amdgpu_device_pre_asic_reset race condition (WID-SEC-2026-3438)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. Affected by this issue is the function amdgpu_device_pre_asic_reset of the file drm/amdgpu of the component KIQ ring. Such manipulation leads to race condition. This vulnerability is documented as CVE-2026-89813. Th...]]></description>
<link>https://tsecurity.de/de/4153196/sicherheitsluecken/cve-2026-89813-linux-kernel-up-to-724-kiq-ring-drmamdgpu-amdgpudevicepreasicreset-race-condition-wid-sec-2026-3438/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153196/sicherheitsluecken/cve-2026-89813-linux-kernel-up-to-724-kiq-ring-drmamdgpu-amdgpudevicepreasicreset-race-condition-wid-sec-2026-3438/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. Affected by this issue is the function amdgpu_device_pre_asic_reset of the file drm/amdgpu of the component KIQ ring. Such manipulation leads to race condition. This vulnerability is documented as CVE-2026-89813. The attack can be executed remotely. There is not any... <a href="https://vuldb.com/vuln/405627" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44316 | PicoC 3.2.2 lex.c LexGetStringConstant heap-based overflow (Issue 37 / EUVD-2022-47261)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in PicoC 3.2.2. The affected element is the function LexGetStringConstant of the file lex.c. This manipulation causes heap-based buffer overflow. The identification of this vulnerability is CVE-2022-44316. The attack needs to be do...]]></description>
<link>https://tsecurity.de/de/4153195/sicherheitsluecken/cve-2022-44316-picoc-322-lexc-lexgetstringconstant-heap-based-overflow-issue-37-euvd-2022-47261/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153195/sicherheitsluecken/cve-2022-44316-picoc-322-lexc-lexgetstringconstant-heap-based-overflow-issue-37-euvd-2022-47261/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, has been found in PicoC 3.2.2. The affected element is the function LexGetStringConstant of the file lex.c. This manipulation causes heap-based buffer overflow. The identification of this vulnerability is CVE-2022-44316. The attack needs to be done within the local network. There is no exploit... <a href="https://vuldb.com/vuln/213110" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44317 | PicoC 3.2.2 cstdlib/stdio.c StdioOutPutc heap-based overflow (Issue 37 / EUVD-2022-47262)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in PicoC 3.2.2. The impacted element is the function StdioOutPutc in the library cstdlib/stdio.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is referenced as CVE-2022-44317. The attack needs to be initiate...]]></description>
<link>https://tsecurity.de/de/4153194/sicherheitsluecken/cve-2022-44317-picoc-322-cstdlibstdioc-stdiooutputc-heap-based-overflow-issue-37-euvd-2022-47262/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153194/sicherheitsluecken/cve-2022-44317-picoc-322-cstdlibstdioc-stdiooutputc-heap-based-overflow-issue-37-euvd-2022-47262/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as critical, was found in PicoC 3.2.2. The impacted element is the function StdioOutPutc in the library cstdlib/stdio.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is referenced as CVE-2022-44317. The attack needs to be initiated within the local network. No exploit is available. <a href="https://vuldb.com/vuln/213111" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44319 | PicoC 3.2.2 cstdlib/string.c StdioBasePrintf heap-based overflow (Issue 37 / EUVD-2022-47264)]]></title>
<description><![CDATA[A vulnerability was found in PicoC 3.2.2 and classified as critical. This impacts the function StdioBasePrintf in the library cstdlib/string.c. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is tracked as CVE-2022-44319. The attack is only possible within the ...]]></description>
<link>https://tsecurity.de/de/4153193/sicherheitsluecken/cve-2022-44319-picoc-322-cstdlibstringc-stdiobaseprintf-heap-based-overflow-issue-37-euvd-2022-47264/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153193/sicherheitsluecken/cve-2022-44319-picoc-322-cstdlibstringc-stdiobaseprintf-heap-based-overflow-issue-37-euvd-2022-47264/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in PicoC 3.2.2 and classified as critical. This impacts the function StdioBasePrintf in the library cstdlib/string.c. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is tracked as CVE-2022-44319. The attack is only possible within the local network. No exploit exists. <a href="https://vuldb.com/vuln/213113" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44318 | PicoC 3.2.2 cstdlib/string.c StringStrcat heap-based overflow (Issue 37 / EUVD-2022-47263)]]></title>
<description><![CDATA[A vulnerability has been found in PicoC 3.2.2 and classified as critical. This affects the function StringStrcat in the library cstdlib/string.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is identified as CVE-2022-44318. The attack can only be performed f...]]></description>
<link>https://tsecurity.de/de/4153192/sicherheitsluecken/cve-2022-44318-picoc-322-cstdlibstringc-stringstrcat-heap-based-overflow-issue-37-euvd-2022-47263/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153192/sicherheitsluecken/cve-2022-44318-picoc-322-cstdlibstringc-stringstrcat-heap-based-overflow-issue-37-euvd-2022-47263/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in PicoC 3.2.2 and classified as critical. This affects the function StringStrcat in the library cstdlib/string.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is identified as CVE-2022-44318. The attack can only be performed from the local network. There is not any exploit... <a href="https://vuldb.com/vuln/213112" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-84386 | Fortinet FortiClientWindows up to 7.2.15/7.4.7 access control (Nessus ID 346901)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Fortinet FortiClientWindows up to 7.2.15/7.4.7. This affects an unknown function. The manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-84386. The attack can only be performed from a local enviro...]]></description>
<link>https://tsecurity.de/de/4153191/sicherheitsluecken/cve-2026-84386-fortinet-forticlientwindows-up-to-7215747-access-control-nessus-id-346901/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153191/sicherheitsluecken/cve-2026-84386-fortinet-forticlientwindows-up-to-7215747-access-control-nessus-id-346901/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Fortinet FortiClientWindows up to 7.2.15/7.4.7. This affects an unknown function. The manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-84386. The attack can only be performed from a local environment. No exploit is available. <a href="https://vuldb.com/vuln/399936" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15913 | Fortra GoAnywhere MFT up to 7.10.1 path traversal (EUVD-2026-75175 / Nessus ID 346899)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Fortra GoAnywhere MFT up to 7.10.1. This affects an unknown part. The manipulation results in path traversal. This vulnerability was named CVE-2026-15913. The attack may be performed from remote. There is no available exploit. Upgrading the a...]]></description>
<link>https://tsecurity.de/de/4153190/sicherheitsluecken/cve-2026-15913-fortra-goanywhere-mft-up-to-7101-path-traversal-euvd-2026-75175-nessus-id-346899/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153190/sicherheitsluecken/cve-2026-15913-fortra-goanywhere-mft-up-to-7101-path-traversal-euvd-2026-75175-nessus-id-346899/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Fortra GoAnywhere MFT up to 7.10.1. This affects an unknown part. The manipulation results in path traversal. This vulnerability was named CVE-2026-15913. The attack may be performed from remote. There is no available exploit. Upgrading the affected component is advised. <a href="https://vuldb.com/vuln/401899" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-70351 | Microsoft WebP Image Extension prior 1.2.31.0 integer overflow (Nessus ID 346896)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Microsoft WebP Image Extension. Affected by this vulnerability is an unknown functionality. This manipulation causes integer overflow. This vulnerability appears as CVE-2026-70351. The attack may be initiated remotely. There is no available ...]]></description>
<link>https://tsecurity.de/de/4153189/sicherheitsluecken/cve-2026-70351-microsoft-webp-image-extension-prior-12310-integer-overflow-nessus-id-346896/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153189/sicherheitsluecken/cve-2026-70351-microsoft-webp-image-extension-prior-12310-integer-overflow-nessus-id-346896/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in Microsoft WebP Image Extension. Affected by this vulnerability is an unknown functionality. This manipulation causes integer overflow. This vulnerability appears as CVE-2026-70351. The attack may be initiated remotely. There is no available exploit. It is suggested to upgrade the affected... <a href="https://vuldb.com/vuln/400874" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-31936 | Intel Xeon 6 processors SMM/TDX privileges management (Nessus ID 346889 / WID-SEC-2026-2772)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Intel Xeon 6 processors. Impacted is an unknown function of the component SMM/TDX. The manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2025-31936. Local access is required to approach ...]]></description>
<link>https://tsecurity.de/de/4153188/sicherheitsluecken/cve-2025-31936-intel-xeon-6-processors-smmtdx-privileges-management-nessus-id-346889-wid-sec-2026-2772/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153188/sicherheitsluecken/cve-2025-31936-intel-xeon-6-processors-smmtdx-privileges-management-nessus-id-346889-wid-sec-2026-2772/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Intel Xeon 6 processors. Impacted is an unknown function of the component SMM/TDX. The manipulation leads to improper privilege management. This vulnerability is uniquely identified as CVE-2025-31936. Local access is required to approach this attack. No exploit exists. <a href="https://vuldb.com/vuln/388218" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-31938 | Intel Xeon 6 Scalable processors TDX access control (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability was found in Intel Xeon 6 Scalable processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component TDX. The manipulation results in improper access controls. This vulnerability is reported as CVE-2025-31938. The attack r...]]></description>
<link>https://tsecurity.de/de/4153187/sicherheitsluecken/cve-2025-31938-intel-xeon-6-scalable-processors-tdx-access-control-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153187/sicherheitsluecken/cve-2025-31938-intel-xeon-6-scalable-processors-tdx-access-control-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Intel Xeon 6 Scalable processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component TDX. The manipulation results in improper access controls. This vulnerability is reported as CVE-2025-31938. The attack requires a local approach. No exploit exists. <a href="https://vuldb.com/vuln/388213" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20917 | Intel Processors Hypervisor/Kernel information disclosure (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability was found in Intel Processors. It has been classified as problematic. This affects an unknown part of the component Hypervisor/Kernel. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2026-20917. An attack has to be approached locally. There is...]]></description>
<link>https://tsecurity.de/de/4153186/sicherheitsluecken/cve-2026-20917-intel-processors-hypervisorkernel-information-disclosure-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153186/sicherheitsluecken/cve-2026-20917-intel-processors-hypervisorkernel-information-disclosure-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Intel Processors. It has been classified as problematic. This affects an unknown part of the component Hypervisor/Kernel. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2026-20917. An attack has to be approached locally. There is no exploit available. <a href="https://vuldb.com/vuln/388380" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-35973 | Intel Processors Kernel/Hypervisor privileges management (Nessus ID 346889)]]></title>
<description><![CDATA[A vulnerability was found in Intel Processors. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Kernel/Hypervisor. This manipulation causes improper privilege management. This vulnerability appears as CVE-2025-35973. The attack requires local...]]></description>
<link>https://tsecurity.de/de/4153185/sicherheitsluecken/cve-2025-35973-intel-processors-kernelhypervisor-privileges-management-nessus-id-346889/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153185/sicherheitsluecken/cve-2025-35973-intel-processors-kernelhypervisor-privileges-management-nessus-id-346889/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Intel Processors. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Kernel/Hypervisor. This manipulation causes improper privilege management. This vulnerability appears as CVE-2025-35973. The attack requires local access. There is no available exploit. <a href="https://vuldb.com/vuln/388214" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44320 | PicoC 3.2.2 expression.c ExpressionCoerceFP heap-based overflow (Issue 37 / EUVD-2022-47265)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in PicoC 3.2.2. This affects the function ExpressionCoerceFP of the file expression.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is known as CVE-2022-44320. Remote exploitation of the attack is possible...]]></description>
<link>https://tsecurity.de/de/4153184/sicherheitsluecken/cve-2022-44320-picoc-322-expressionc-expressioncoercefp-heap-based-overflow-issue-37-euvd-2022-47265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153184/sicherheitsluecken/cve-2022-44320-picoc-322-expressionc-expressioncoercefp-heap-based-overflow-issue-37-euvd-2022-47265/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in PicoC 3.2.2. This affects the function ExpressionCoerceFP of the file expression.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is known as CVE-2022-44320. Remote exploitation of the attack is possible. No exploit is available. <a href="https://vuldb.com/vuln/213106" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44343 | ZhongBangKeJi CRMEB 4.4.4 information disclosure (EUVD-2022-47288)]]></title>
<description><![CDATA[A vulnerability was found in ZhongBangKeJi CRMEB 4.4.4. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2022-44343. The attack requires being on the local network. There is...]]></description>
<link>https://tsecurity.de/de/4153183/sicherheitsluecken/cve-2022-44343-zhongbangkeji-crmeb-444-information-disclosure-euvd-2022-47288/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153183/sicherheitsluecken/cve-2022-44343-zhongbangkeji-crmeb-444-information-disclosure-euvd-2022-47288/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in ZhongBangKeJi CRMEB 4.4.4. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2022-44343. The attack requires being on the local network. There is not any exploit available. <a href="https://vuldb.com/vuln/220227" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44321 | PicoC 3.2.2 lex.c LexSkipComment heap-based overflow (Issue 37 / EUVD-2022-47266)]]></title>
<description><![CDATA[A vulnerability was found in PicoC 3.2.2. It has been classified as critical. Affected is the function LexSkipComment of the file lex.c. The manipulation leads to heap-based buffer overflow. This vulnerability is listed as CVE-2022-44321. The attack must be carried out from within the local netwo...]]></description>
<link>https://tsecurity.de/de/4153182/sicherheitsluecken/cve-2022-44321-picoc-322-lexc-lexskipcomment-heap-based-overflow-issue-37-euvd-2022-47266/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153182/sicherheitsluecken/cve-2022-44321-picoc-322-lexc-lexskipcomment-heap-based-overflow-issue-37-euvd-2022-47266/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in PicoC 3.2.2. It has been classified as critical. Affected is the function LexSkipComment of the file lex.c. The manipulation leads to heap-based buffer overflow. This vulnerability is listed as CVE-2022-44321. The attack must be carried out from within the local network. There is no available exploit. <a href="https://vuldb.com/vuln/213114" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44345 | Sanitization Management System 1.0 view_quote ID sql injection (EUVD-2022-47290)]]></title>
<description><![CDATA[A vulnerability has been found in Sanitization Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sms/admin/?page=quotes/view_quote. The manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2022-44345. ...]]></description>
<link>https://tsecurity.de/de/4153181/sicherheitsluecken/cve-2022-44345-sanitization-management-system-10-viewquote-id-sql-injection-euvd-2022-47290/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153181/sicherheitsluecken/cve-2022-44345-sanitization-management-system-10-viewquote-id-sql-injection-euvd-2022-47290/</guid>
<pubDate>Fri, 18 Sep 2026 02:42:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability has been found in Sanitization Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sms/admin/?page=quotes/view_quote. The manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2022-44345. Access to the local network is required for this... <a href="https://vuldb.com/vuln/214680" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Revolut breach exposes widespread security weakness — trust]]></title>
<description><![CDATA[&lt;p&gt;The Revolut breach highlights a vulnerability that experts say goes unnoticed in many enterprises: data release processes that conflate authentication and authorization, with users assuming requests from legitimate email domains are trustworthy.&lt;/p&gt; &lt;p&gt;In the attack on Revolu...]]></description>
<link>https://tsecurity.de/de/4153166/sicherheitsluecken/revolut-breach-exposes-widespread-security-weakness-trust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153166/sicherheitsluecken/revolut-breach-exposes-widespread-security-weakness-trust/</guid>
<pubDate>Fri, 18 Sep 2026 02:39:52 +0200</pubDate>
<content:encoded><![CDATA[<p>&amp;lt;p&amp;gt;The Revolut breach highlights a vulnerability that experts say goes unnoticed in many enterprises: data release processes that conflate authentication and authorization, with users assuming requests from legitimate email domains are trustworthy.&amp;lt;/p&amp;gt; &amp;lt;p&amp;gt;In the attack on Revolut, a London-based financial technology company,... <a href="https://www.itsecuritynews.info/revolut-breach-exposes-widespread-security-weakness-trust/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BrokenPipe]]></title>
<description><![CDATA[Steam Client Service Local Privilege Escalation Vulnerability Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153156/sicherheitsluecken/brokenpipe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153156/sicherheitsluecken/brokenpipe/</guid>
<pubDate>Fri, 18 Sep 2026 02:35:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Steam Client Service Local Privilege Escalation Vulnerability <a href="https://kitploit.com/en/tools/github/killaboi/brokenpipe" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[oxo v2.10.3]]></title>
<description><![CDATA[Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across networks, web apps, mobile apps, and APIs. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153151/sicherheitsluecken/oxo-v2103/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153151/sicherheitsluecken/oxo-v2103/</guid>
<pubDate>Fri, 18 Sep 2026 02:35:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across networks, web apps, mobile apps, and APIs. <a href="https://kitploit.com/en/posts/github-ostorlab-oxo-v2103" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Protect Your Linux System from Flatpak Security Issues (2026)]]></title>
<description><![CDATA[Flatpak 1.18.1 patched 10 security vulnerabilities including a critical sandbox escape (CVE-2026-34078). This guide walks you through checking your Flatpak version, updating on Ubuntu, Fedora, and Arch Linux, auditing app permissions with Flatseal, and implementing security best practices to prot...]]></description>
<link>https://tsecurity.de/de/4153135/sicherheitsluecken/how-to-protect-your-linux-system-from-flatpak-security-issues-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153135/sicherheitsluecken/how-to-protect-your-linux-system-from-flatpak-security-issues-2026/</guid>
<pubDate>Fri, 18 Sep 2026 02:33:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Flatpak 1.18.1 patched 10 security vulnerabilities including a critical sandbox escape (CVE-2026-34078). This guide walks you through checking your Flatpak version, updating on Ubuntu, Fedora, and Arch Linux, auditing app permissions with Flatseal, and implementing security best practices to protect your system. <a href="https://www.fosslinux.com/161874/how-to-protect-your-linux-system-from-flatpak-security-issues.htm" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44311 | html2xhtml 1.3 HTML File procesador.c elm_close out-of-bounds (Issue 19 / EUVD-2022-47256)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in html2xhtml 1.3. Affected is the function elm_close of the file procesador.c of the component HTML File Handler. The manipulation results in out-of-bounds read. This vulnerability is reported as CVE-2022-44311. The attacker must hav...]]></description>
<link>https://tsecurity.de/de/4153128/sicherheitsluecken/cve-2022-44311-html2xhtml-13-html-file-procesadorc-elmclose-out-of-bounds-issue-19-euvd-2022-47256/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153128/sicherheitsluecken/cve-2022-44311-html2xhtml-13-html-file-procesadorc-elmclose-out-of-bounds-issue-19-euvd-2022-47256/</guid>
<pubDate>Fri, 18 Sep 2026 01:57:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability categorized as problematic has been discovered in html2xhtml 1.3. Affected is the function elm_close of the file procesador.c of the component HTML File Handler. The manipulation results in out-of-bounds read. This vulnerability is reported as CVE-2022-44311. The attacker must have access to the local network to execute the attack.... <a href="https://vuldb.com/vuln/213103" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44313 | PicoC 3.2.2 expression.c ExpressionCoerceUnsignedInteger heap-based overflow (Issue 37 / EUVD-2022-47258)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in PicoC 3.2.2. Affected by this issue is the function ExpressionCoerceUnsignedInteger of the file expression.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is traded as CVE-2022-44313. The attack may be launched rem...]]></description>
<link>https://tsecurity.de/de/4153127/sicherheitsluecken/cve-2022-44313-picoc-322-expressionc-expressioncoerceunsignedinteger-heap-based-overflow-issue-37-euvd-2022-47258/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153127/sicherheitsluecken/cve-2022-44313-picoc-322-expressionc-expressioncoerceunsignedinteger-heap-based-overflow-issue-37-euvd-2022-47258/</guid>
<pubDate>Fri, 18 Sep 2026 01:57:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in PicoC 3.2.2. Affected by this issue is the function ExpressionCoerceUnsignedInteger of the file expression.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is traded as CVE-2022-44313. The attack may be launched remotely. There is no exploit available. <a href="https://vuldb.com/vuln/213105" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44312 | PicoC 3.2.2 expression.c ExpressionCoerceInteger heap-based overflow (Issue 37 / EUVD-2022-47257)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in PicoC 3.2.2. Affected by this vulnerability is the function ExpressionCoerceInteger of the file expression.c. This manipulation causes heap-based buffer overflow. This vulnerability appears as CVE-2022-44312. The attack may be initiated ...]]></description>
<link>https://tsecurity.de/de/4153126/sicherheitsluecken/cve-2022-44312-picoc-322-expressionc-expressioncoerceinteger-heap-based-overflow-issue-37-euvd-2022-47257/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153126/sicherheitsluecken/cve-2022-44312-picoc-322-expressionc-expressioncoerceinteger-heap-based-overflow-issue-37-euvd-2022-47257/</guid>
<pubDate>Fri, 18 Sep 2026 01:57:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability identified as critical has been detected in PicoC 3.2.2. Affected by this vulnerability is the function ExpressionCoerceInteger of the file expression.c. This manipulation causes heap-based buffer overflow. This vulnerability appears as CVE-2022-44312. The attack may be initiated remotely. There is no available exploit. <a href="https://vuldb.com/vuln/213104" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44315 | PicoC 3.2.2 expression.c ExpressionAssign heap-based overflow (Issue 37 / EUVD-2022-47260)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in PicoC 3.2.2. Impacted is the function ExpressionAssign of the file expression.c. The manipulation results in heap-based buffer overflow. This vulnerability was named CVE-2022-44315. The attack needs to be approached within the local network. The...]]></description>
<link>https://tsecurity.de/de/4153125/sicherheitsluecken/cve-2022-44315-picoc-322-expressionc-expressionassign-heap-based-overflow-issue-37-euvd-2022-47260/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153125/sicherheitsluecken/cve-2022-44315-picoc-322-expressionc-expressionassign-heap-based-overflow-issue-37-euvd-2022-47260/</guid>
<pubDate>Fri, 18 Sep 2026 01:57:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in PicoC 3.2.2. Impacted is the function ExpressionAssign of the file expression.c. The manipulation results in heap-based buffer overflow. This vulnerability was named CVE-2022-44315. The attack needs to be approached within the local network. There is no available exploit. <a href="https://vuldb.com/vuln/213109" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44314 | PicoC 3.2.2 cstdlib/string.c StringStrncpy heap-based overflow (Issue 37 / EUVD-2022-47259)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in PicoC 3.2.2. This issue affects the function StringStrncpy in the library cstdlib/string.c. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified as CVE-2022-44314. The attack can only be initiated ...]]></description>
<link>https://tsecurity.de/de/4153124/sicherheitsluecken/cve-2022-44314-picoc-322-cstdlibstringc-stringstrncpy-heap-based-overflow-issue-37-euvd-2022-47259/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153124/sicherheitsluecken/cve-2022-44314-picoc-322-cstdlibstringc-stringstrncpy-heap-based-overflow-issue-37-euvd-2022-47259/</guid>
<pubDate>Fri, 18 Sep 2026 01:57:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in PicoC 3.2.2. This issue affects the function StringStrncpy in the library cstdlib/string.c. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified as CVE-2022-44314. The attack can only be initiated within the local network. No exploit exists. <a href="https://vuldb.com/vuln/213108" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-4751 | vim up to 9.0.1247 heap-based overflow]]></title>
<description><![CDATA[A vulnerability was found in vim and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is registered as CVE-2023-4751. The attack needs to be launched locally. No exploit is available. ...]]></description>
<link>https://tsecurity.de/de/4153104/sicherheitsluecken/cve-2023-4751-vim-up-to-901247-heap-based-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153104/sicherheitsluecken/cve-2023-4751-vim-up-to-901247-heap-based-overflow/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in vim and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is registered as CVE-2023-4751. The attack needs to be launched locally. No exploit is available. It is suggested to upgrade the affected component. <a href="https://vuldb.com/vuln/238691" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-20327 | mongodb-client-encryption 1.2.0 on Node.js certificate validation]]></title>
<description><![CDATA[A vulnerability was found in mongodb-client-encryption 1.2.0 on Node.js and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to improper certificate validation. This vulnerability is registered as CVE-2021-20327. The attack requires access to ...]]></description>
<link>https://tsecurity.de/de/4153103/sicherheitsluecken/cve-2021-20327-mongodb-client-encryption-120-on-nodejs-certificate-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153103/sicherheitsluecken/cve-2021-20327-mongodb-client-encryption-120-on-nodejs-certificate-validation/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in mongodb-client-encryption 1.2.0 on Node.js and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to improper certificate validation. This vulnerability is registered as CVE-2021-20327. The attack requires access to the local network. No exploit is available. <a href="https://vuldb.com/vuln/170441" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2017-7200 | OpenStack Glance Image Service API v1 Portscan server-side request forgery (BID-96988)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in OpenStack Glance. The affected element is an unknown function of the component Image Service API v1. This manipulation causes server-side request forgery (Portscan). This vulnerability is registered as CVE-2017-7200. Remote exploitation ...]]></description>
<link>https://tsecurity.de/de/4153102/sicherheitsluecken/cve-2017-7200-openstack-glance-image-service-api-v1-portscan-server-side-request-forgery-bid-96988/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153102/sicherheitsluecken/cve-2017-7200-openstack-glance-image-service-api-v1-portscan-server-side-request-forgery-bid-96988/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic has been found in OpenStack Glance. The affected element is an unknown function of the component Image Service API v1. This manipulation causes server-side request forgery (Portscan). This vulnerability is registered as CVE-2017-7200. Remote exploitation of the attack is possible. No exploit is available.... <a href="https://vuldb.com/vuln/98336" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2012-5825 | Horde Kronolith 3.0.17 Portal Blocks input validation (ID 349780 / XFDB-80084)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Horde Kronolith 3.0.17. This issue affects some unknown processing of the component Portal Blocks. Such manipulation leads to improper input validation. This vulnerability is documented as CVE-2012-5825. The attack can be executed re...]]></description>
<link>https://tsecurity.de/de/4153101/sicherheitsluecken/cve-2012-5825-horde-kronolith-3017-portal-blocks-input-validation-id-349780-xfdb-80084/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153101/sicherheitsluecken/cve-2012-5825-horde-kronolith-3017-portal-blocks-input-validation-id-349780-xfdb-80084/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Horde Kronolith 3.0.17. This issue affects some unknown processing of the component Portal Blocks. Such manipulation leads to improper input validation. This vulnerability is documented as CVE-2012-5825. The attack can be executed remotely. Additionally, an exploit exists. Upgrading... <a href="https://vuldb.com/vuln/6957" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2012-5825 | Horde Groupware/Groupware Webmail Edition 4.0.8 Portal Blocks input validation (ID 349780 / XFDB-80084)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Horde Groupware and Groupware Webmail Edition 4.0.8. This vulnerability affects unknown code of the component Portal Blocks. This manipulation causes improper input validation. This vulnerability is registered as CVE-2012-5825. Remote exp...]]></description>
<link>https://tsecurity.de/de/4153100/sicherheitsluecken/cve-2012-5825-horde-groupwaregroupware-webmail-edition-408-portal-blocks-input-validation-id-349780-xfdb-80084/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153100/sicherheitsluecken/cve-2012-5825-horde-groupwaregroupware-webmail-edition-408-portal-blocks-input-validation-id-349780-xfdb-80084/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as problematic has been reported in Horde Groupware and Groupware Webmail Edition 4.0.8. This vulnerability affects unknown code of the component Portal Blocks. This manipulation causes improper input validation. This vulnerability is registered as CVE-2012-5825. Remote exploitation of the attack is possible. Furthermore, an... <a href="https://vuldb.com/vuln/6956" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-5535 | vim up to 9.0.1969 use after free]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in vim. This affects an unknown part. Executing a manipulation can lead to use after free. This vulnerability is tracked as CVE-2023-5535. The attack can be launched remotely. No exploit exists. Upgrading the affected component is recommen...]]></description>
<link>https://tsecurity.de/de/4153099/sicherheitsluecken/cve-2023-5535-vim-up-to-901969-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153099/sicherheitsluecken/cve-2023-5535-vim-up-to-901969-use-after-free/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in vim. This affects an unknown part. Executing a manipulation can lead to use after free. This vulnerability is tracked as CVE-2023-5535. The attack can be launched remotely. No exploit exists. Upgrading the affected component is recommended. <a href="https://vuldb.com/vuln/242003" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14311 | melograno Booking for Appointments and Events Calendar Plugin /users/customers/ improper authorization (EUVD-2026-82496)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.4 on WordPress. This affects an unknown function of the file /users/customers/. Performing a manipulation results in improper authorization. This vulnerability is repor...]]></description>
<link>https://tsecurity.de/de/4153098/sicherheitsluecken/cve-2026-14311-melograno-booking-for-appointments-and-events-calendar-plugin-userscustomers-improper-authorization-euvd-2026-82496/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153098/sicherheitsluecken/cve-2026-14311-melograno-booking-for-appointments-and-events-calendar-plugin-userscustomers-improper-authorization-euvd-2026-82496/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.4 on WordPress. This affects an unknown function of the file /users/customers/. Performing a manipulation results in improper authorization. This vulnerability is reported as CVE-2026-14311. The attack is possible to be... <a href="https://vuldb.com/vuln/407218" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16750 | Stylemix Motors Plugin up to 1.4.120 on WordPress mvl_ajax_dealer_load_cars improper authorization (EUVD-2026-82494)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Stylemix Motors Plugin up to 1.4.120 on WordPress. This impacts the function mvl_ajax_dealer_load_cars. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2026-16750. The attack may be performed fro...]]></description>
<link>https://tsecurity.de/de/4153097/sicherheitsluecken/cve-2026-16750-stylemix-motors-plugin-up-to-14120-on-wordpress-mvlajaxdealerloadcars-improper-authorization-euvd-2026-82494/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153097/sicherheitsluecken/cve-2026-16750-stylemix-motors-plugin-up-to-14120-on-wordpress-mvlajaxdealerloadcars-improper-authorization-euvd-2026-82494/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in Stylemix Motors Plugin up to 1.4.120 on WordPress. This impacts the function mvl_ajax_dealer_load_cars. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2026-16750. The attack may be performed from remote. There is no available exploit. <a href="https://vuldb.com/vuln/407219" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-16582 | melograno Booking for Appointments and Events Calendar Plugin improper authorization (EUVD-2026-82495)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.5 on WordPress. The impacted element is an unknown function. Such manipulation of the argument package-redemption identifier leads to improper authorization. Thi...]]></description>
<link>https://tsecurity.de/de/4153096/sicherheitsluecken/cve-2026-16582-melograno-booking-for-appointments-and-events-calendar-plugin-improper-authorization-euvd-2026-82495/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153096/sicherheitsluecken/cve-2026-16582-melograno-booking-for-appointments-and-events-calendar-plugin-improper-authorization-euvd-2026-82495/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.5 on WordPress. The impacted element is an unknown function. Such manipulation of the argument package-redemption identifier leads to improper authorization. This vulnerability is documented as CVE-2026-16582. The... <a href="https://vuldb.com/vuln/407217" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93426 | SigNoz up to 0.141.x Query Range API sql injection (EUVD-2026-82493)]]></title>
<description><![CDATA[A vulnerability was found in SigNoz up to 0.141.x and classified as critical. This issue affects some unknown processing of the component Query Range API. Such manipulation leads to sql injection. This vulnerability is referenced as CVE-2026-93426. It is possible to launch the attack remotely. No...]]></description>
<link>https://tsecurity.de/de/4153095/sicherheitsluecken/cve-2026-93426-signoz-up-to-0141x-query-range-api-sql-injection-euvd-2026-82493/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153095/sicherheitsluecken/cve-2026-93426-signoz-up-to-0141x-query-range-api-sql-injection-euvd-2026-82493/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in SigNoz up to 0.141.x and classified as critical. This issue affects some unknown processing of the component Query Range API. Such manipulation leads to sql injection. This vulnerability is referenced as CVE-2026-93426. It is possible to launch the attack remotely. No exploit is available. It is suggested to upgrade... <a href="https://vuldb.com/vuln/407181" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73638 | Imager up to 1.034 tiff_load_ifd out-of-bounds (EUVD-2026-82491)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Imager up to 1.034. This affects the function tiff_load_ifd. The manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-73638. The attack may be performed from remote. There is no available exploit. You ...]]></description>
<link>https://tsecurity.de/de/4153094/sicherheitsluecken/cve-2026-73638-imager-up-to-1034-tiffloadifd-out-of-bounds-euvd-2026-82491/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153094/sicherheitsluecken/cve-2026-73638-imager-up-to-1034-tiffloadifd-out-of-bounds-euvd-2026-82491/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Imager up to 1.034. This affects the function tiff_load_ifd. The manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-73638. The attack may be performed from remote. There is no available exploit. You should upgrade the affected component. <a href="https://vuldb.com/vuln/407179" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-73639 | Imager 1.003 PNG read_direct8 buffer overflow (EUVD-2026-82492)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Imager 1.003. Affected by this issue is the function read_direct8 of the component PNG. The manipulation leads to buffer overflow. This vulnerability is uniquely identified as CVE-2026-73639. The attack is possible to be carr...]]></description>
<link>https://tsecurity.de/de/4153093/sicherheitsluecken/cve-2026-73639-imager-1003-png-readdirect8-buffer-overflow-euvd-2026-82492/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153093/sicherheitsluecken/cve-2026-73639-imager-1003-png-readdirect8-buffer-overflow-euvd-2026-82492/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, has been found in Imager 1.003. Affected by this issue is the function read_direct8 of the component PNG. The manipulation leads to buffer overflow. This vulnerability is uniquely identified as CVE-2026-73639. The attack is possible to be carried out remotely. No exploit exists. <a href="https://vuldb.com/vuln/407178" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-93386 | Google Chrome up to 153.0.8010.47 WebAppInstalls information disclosure (EUVD-2026-82490)]]></title>
<description><![CDATA[A vulnerability was found in Google Chrome. It has been rated as problematic. This impacts an unknown function of the component WebAppInstalls. The manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-93386. The attack can be initiated remotely. There is not ...]]></description>
<link>https://tsecurity.de/de/4153092/sicherheitsluecken/cve-2026-93386-google-chrome-up-to-1530801047-webappinstalls-information-disclosure-euvd-2026-82490/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153092/sicherheitsluecken/cve-2026-93386-google-chrome-up-to-1530801047-webappinstalls-information-disclosure-euvd-2026-82490/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Google Chrome. It has been rated as problematic. This impacts an unknown function of the component WebAppInstalls. The manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-93386. The attack can be initiated remotely. There is not any exploit available. Upgrading the affected... <a href="https://vuldb.com/vuln/407142" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44295 | oretnom23 Sanitization Management System 1.0 assign_team.php ID sql injection (EUVD-2022-47242)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in oretnom23 Sanitization Management System 1.0. Impacted is an unknown function of the file /php-sms/admin/orders/assign_team.php. Such manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2022-44295...]]></description>
<link>https://tsecurity.de/de/4153091/sicherheitsluecken/cve-2022-44295-oretnom23-sanitization-management-system-10-assignteamphp-id-sql-injection-euvd-2022-47242/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153091/sicherheitsluecken/cve-2022-44295-oretnom23-sanitization-management-system-10-assignteamphp-id-sql-injection-euvd-2022-47242/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as critical has been identified in oretnom23 Sanitization Management System 1.0. Impacted is an unknown function of the file /php-sms/admin/orders/assign_team.php. Such manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2022-44295. Access to the local network is required for this... <a href="https://vuldb.com/vuln/214605" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44297 | SiteServer CMS 7.1.3 sql injection (Issue 3490 / EUVD-2022-47244)]]></title>
<description><![CDATA[A vulnerability was found in SiteServer CMS 7.1.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is reported as CVE-2022-44297. The attacker must have access to the local network to execute t...]]></description>
<link>https://tsecurity.de/de/4153090/sicherheitsluecken/cve-2022-44297-siteserver-cms-713-sql-injection-issue-3490-euvd-2022-47244/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153090/sicherheitsluecken/cve-2022-44297-siteserver-cms-713-sql-injection-issue-3490-euvd-2022-47244/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in SiteServer CMS 7.1.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is reported as CVE-2022-44297. The attacker must have access to the local network to execute the attack. No exploit exists. <a href="https://vuldb.com/vuln/219568" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44296 | oretnom23 Sanitization Management System 1.0 manage_remark.php ID sql injection (EUVD-2022-47243)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in oretnom23 Sanitization Management System 1.0. The affected element is an unknown function of the file /php-sms/admin/quotes/manage_remark.php. Performing a manipulation of the argument ID results in sql injection. This vulnerability is know...]]></description>
<link>https://tsecurity.de/de/4153089/sicherheitsluecken/cve-2022-44296-oretnom23-sanitization-management-system-10-manageremarkphp-id-sql-injection-euvd-2022-47243/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153089/sicherheitsluecken/cve-2022-44296-oretnom23-sanitization-management-system-10-manageremarkphp-id-sql-injection-euvd-2022-47243/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical has been found in oretnom23 Sanitization Management System 1.0. The affected element is an unknown function of the file /php-sms/admin/quotes/manage_remark.php. Performing a manipulation of the argument ID results in sql injection. This vulnerability is known as CVE-2022-44296. Access to the local network is... <a href="https://vuldb.com/vuln/214606" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44298 | SiteServer CMS 7.1.3 sql injection (Issue 3492 / EUVD-2022-47245)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in SiteServer CMS 7.1.3. Impacted is an unknown function. The manipulation results in sql injection. This vulnerability is reported as CVE-2022-44298. The attacker must have access to the local network to execute the attack. No exploit exists. We...]]></description>
<link>https://tsecurity.de/de/4153088/sicherheitsluecken/cve-2022-44298-siteserver-cms-713-sql-injection-issue-3492-euvd-2022-47245/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153088/sicherheitsluecken/cve-2022-44298-siteserver-cms-713-sql-injection-issue-3492-euvd-2022-47245/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability labeled as critical has been found in SiteServer CMS 7.1.3. Impacted is an unknown function. The manipulation results in sql injection. This vulnerability is reported as CVE-2022-44298. The attacker must have access to the local network to execute the attack. No exploit exists. <a href="https://vuldb.com/vuln/219643" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-44299 | SiteServerCMS 7.1.3 information disclosure (Issue 3491 / EUVD-2022-47246)]]></title>
<description><![CDATA[A vulnerability was found in SiteServerCMS 7.1.3 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CVE-2022-44299. The attack needs to be done within the local network. There is no ...]]></description>
<link>https://tsecurity.de/de/4153087/sicherheitsluecken/cve-2022-44299-siteservercms-713-information-disclosure-issue-3491-euvd-2022-47246/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153087/sicherheitsluecken/cve-2022-44299-siteservercms-713-information-disclosure-issue-3491-euvd-2022-47246/</guid>
<pubDate>Fri, 18 Sep 2026 01:28:23 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in SiteServerCMS 7.1.3 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CVE-2022-44299. The attack needs to be done within the local network. There is no exploit available. <a href="https://vuldb.com/vuln/221345" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom]]></title>
<description><![CDATA[Plugin4Shell attack affects all the major coding agents, researchers say This article has been indexed from www.theregister.com – Articles Read the original article: AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom The post AI coding agents’ 0-click RCE flaw could hand ...]]></description>
<link>https://tsecurity.de/de/4153068/sicherheitsluecken/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153068/sicherheitsluecken/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/</guid>
<pubDate>Fri, 18 Sep 2026 01:25:47 +0200</pubDate>
<content:encoded><![CDATA[<p>Plugin4Shell attack affects all the major coding agents, researchers say This article has been indexed from www.theregister.com – Articles Read the original article: AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom The post AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom appeared first on IT... <a href="https://www.itsecuritynews.info/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom]]></title>
<description><![CDATA[A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents - Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub Copilot - and could give attackers full access to every asset and piece of data th...]]></description>
<link>https://tsecurity.de/de/4153065/sicherheitsluecken/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153065/sicherheitsluecken/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/</guid>
<pubDate>Fri, 18 Sep 2026 01:23:06 +0200</pubDate>
<content:encoded><![CDATA[<p>A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents - Anthropic’s Claude Code, OpenAI’s Codex, Google&#039;s Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub Copilot - and could give attackers full access to every asset and piece of data that the agent can reach, researchers say. The... <a href="https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8779-2: Bubblewrap regression]]></title>
<description><![CDATA[USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete fix is available. We apologize for the inconvenience. Orig...]]></description>
<link>https://tsecurity.de/de/4153045/sicherheitsluecken/usn-8779-2-bubblewrap-regression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153045/sicherheitsluecken/usn-8779-2-bubblewrap-regression/</guid>
<pubDate>Fri, 18 Sep 2026 01:20:28 +0200</pubDate>
<content:encoded><![CDATA[<p>USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete fix is available. We apologize for the inconvenience. Original advisory details: It was discovered that... <a href="https://ubuntu.com/security/notices/USN-8779-2" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure]]></title>
<description><![CDATA[Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure In September 2026, researchers disclosed a class of configuration injection flaws affecting several AI coding agents, including Claude Code, Codex, Goose, Qwen Code and Grok Build, tracked...]]></description>
<link>https://tsecurity.de/de/4153036/sicherheitsluecken/finding-the-agent-infrastructure-what-internet-measurement-can-and-cannot-say-about-ai-coding-tool-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153036/sicherheitsluecken/finding-the-agent-infrastructure-what-internet-measurement-can-and-cannot-say-about-ai-coding-tool-exposure/</guid>
<pubDate>Fri, 18 Sep 2026 00:30:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure In September 2026, researchers disclosed a class of configuration injection flaws affecting several AI coding agents, including Claude Code, Codex, Goose, Qwen Code and Grok Build, tracked under identifiers including CVE-2026-19592. The... <a href="https://dev.to/bianliang/finding-the-agent-infrastructure-what-internet-measurement-can-and-cannot-say-about-ai-coding-tool-5ld" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus]]></title>
<description><![CDATA[The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4153012/sicherheitsluecken/cisa-ditches-weekly-vulnerability-roundups-for-risk-based-focus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4153012/sicherheitsluecken/cisa-ditches-weekly-vulnerability-roundups-for-risk-based-focus/</guid>
<pubDate>Fri, 18 Sep 2026 00:25:26 +0200</pubDate>
<content:encoded><![CDATA[<p>The move is consistent with the agency&#039;s advice on the need for organizations to prioritize the vulnerabilities that actually matter. <a href="https://www.darkreading.com/cyber-risk/cisa-ditches-weekly-vuln-roundups-risk-based-focus" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Missing Access Control in Rank Math SEO Schema Shortcode and Object Permission Checks]]></title>
<description><![CDATA[The schema snippet shortcode returned schema data for any post ID without checking whether the requester was allowed to view that post, disclosing schema (and content derived from it) for draft, pending, private, scheduled and password-protected posts to unauthenticated visitors. The plugin also ...]]></description>
<link>https://tsecurity.de/de/4152962/sicherheitsluecken/missing-access-control-in-rank-math-seo-schema-shortcode-and-object-permission-checks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152962/sicherheitsluecken/missing-access-control-in-rank-math-seo-schema-shortcode-and-object-permission-checks/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:23 +0200</pubDate>
<content:encoded><![CDATA[<p>The schema snippet shortcode returned schema data for any post ID without checking whether the requester was allowed to view that post, disclosing schema (and content derived from it) for draft, pending, private, scheduled and password-protected posts to unauthenticated visitors. The plugin also enforced its object permission checks only... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6267" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Application Firewall Rule Bypass in Jetpack WAF Runtime]]></title>
<description><![CDATA[Jetpack's bundled Web Application Firewall did not clear its cached MATCHED_VAR/MATCHED_VARS metadata between rule evaluations, so a rule referencing those targets kept receiving a previous rule's stale match data. A remote attacker could craft a request that makes later firewall rules evaluate t...]]></description>
<link>https://tsecurity.de/de/4152961/sicherheitsluecken/web-application-firewall-rule-bypass-in-jetpack-waf-runtime/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152961/sicherheitsluecken/web-application-firewall-rule-bypass-in-jetpack-waf-runtime/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Jetpack&#039;s bundled Web Application Firewall did not clear its cached MATCHED_VAR/MATCHED_VARS metadata between rule evaluations, so a rule referencing those targets kept receiving a previous rule&#039;s stale match data. A remote attacker could craft a request that makes later firewall rules evaluate the wrong content, masking malicious input and... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6261" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Request Forgery in WooCommerce Product and Term Ordering]]></title>
<description><![CDATA[The WooCommerce admin AJAX handlers WC_AJAX::product_ordering() and WC_AJAX::term_ordering() changed the menu_order of products and taxonomy terms without verifying a nonce; they were the only state-changing handlers in the file with the nonce check suppressed. An attacker could therefore forge a...]]></description>
<link>https://tsecurity.de/de/4152960/sicherheitsluecken/cross-site-request-forgery-in-woocommerce-product-and-term-ordering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152960/sicherheitsluecken/cross-site-request-forgery-in-woocommerce-product-and-term-ordering/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The WooCommerce admin AJAX handlers WC_AJAX::product_ordering() and WC_AJAX::term_ordering() changed the menu_order of products and taxonomy terms without verifying a nonce; they were the only state-changing handlers in the file with the nonce check suppressed. An attacker could therefore forge a cross-site request that, when opened by a logged-in... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6262" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unescaped Output in Enable Media Replace Error View]]></title>
<description><![CDATA[Enable Media Replace up to and including 4.1.8 printed the error message and error description into the error view without HTML escaping. Upstream added esc_html() to both outputs in 4.1.9. The values originate from a fixed set of plugin-supplied translated strings, so this is defence-in-depth ha...]]></description>
<link>https://tsecurity.de/de/4152959/sicherheitsluecken/unescaped-output-in-enable-media-replace-error-view/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152959/sicherheitsluecken/unescaped-output-in-enable-media-replace-error-view/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Enable Media Replace up to and including 4.1.8 printed the error message and error description into the error view without HTML escaping. Upstream added esc_html() to both outputs in 4.1.9. The values originate from a fixed set of plugin-supplied translated strings, so this is defence-in-depth hardening rather than a reachable injection point.... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6256" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stored Cross-Site Scripting in WooCommerce Order Notes REST API v4]]></title>
<description><![CDATA[WooCommerce before 10.7.0 passed the REST API v4 order-note request field directly to add_order_note() without sanitization, storing the value verbatim. Any user able to create an order note through the v4 REST API can inject script that is later executed when the note is rendered, including in t...]]></description>
<link>https://tsecurity.de/de/4152958/sicherheitsluecken/stored-cross-site-scripting-in-woocommerce-order-notes-rest-api-v4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152958/sicherheitsluecken/stored-cross-site-scripting-in-woocommerce-order-notes-rest-api-v4/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>WooCommerce before 10.7.0 passed the REST API v4 order-note request field directly to add_order_note() without sanitization, storing the value verbatim. Any user able to create an order note through the v4 REST API can inject script that is later executed when the note is rendered, including in the wp-admin order screens. The fix wraps the value... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6259" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unescaped Attribute Output in Enable Media Replace Upsell View]]></title>
<description><![CDATA[Enable Media Replace up to and including 4.1.8 printed CSS class values into HTML attributes in the upsell view without escaping. Upstream added esc_attr() to two of these outputs in 4.1.9. The values are assigned from fixed literals, so this is defence-in-depth hardening rather than a reachable ...]]></description>
<link>https://tsecurity.de/de/4152957/sicherheitsluecken/unescaped-attribute-output-in-enable-media-replace-upsell-view/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152957/sicherheitsluecken/unescaped-attribute-output-in-enable-media-replace-upsell-view/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Enable Media Replace up to and including 4.1.8 printed CSS class values into HTML attributes in the upsell view without escaping. Upstream added esc_attr() to two of these outputs in 4.1.9. The values are assigned from fixed literals, so this is defence-in-depth hardening rather than a reachable injection point. This vulnerability affects the... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6257" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stored Cross-Site Scripting in Essential Addons for Elementor Pricing Table Title Tag]]></title>
<description><![CDATA[Essential Addons for Elementor before 6.6.10 does not validate the HTML tag name configured for the Pricing Table widget title before rendering it. Because the value is used as a raw tag name, esc_html() does not constrain it, so an authenticated attacker with Contributor-level access or above ca...]]></description>
<link>https://tsecurity.de/de/4152956/sicherheitsluecken/stored-cross-site-scripting-in-essential-addons-for-elementor-pricing-table-title-tag/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152956/sicherheitsluecken/stored-cross-site-scripting-in-essential-addons-for-elementor-pricing-table-title-tag/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Essential Addons for Elementor before 6.6.10 does not validate the HTML tag name configured for the Pricing Table widget title before rendering it. Because the value is used as a raw tag name, esc_html() does not constrain it, so an authenticated attacker with Contributor-level access or above can inject JavaScript that executes when the post is... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6258" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stored Cross-Site Scripting in TablePress Shortcode Debug Output]]></title>
<description><![CDATA[TablePress up to and including 3.2 renders shortcode render options through var_export() without escaping when the shortcode_debug attribute is set. An authenticated attacker with Contributor-level access or above can inject arbitrary JavaScript through a table shortcode attribute, which then exe...]]></description>
<link>https://tsecurity.de/de/4152955/sicherheitsluecken/stored-cross-site-scripting-in-tablepress-shortcode-debug-output/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152955/sicherheitsluecken/stored-cross-site-scripting-in-tablepress-shortcode-debug-output/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>TablePress up to and including 3.2 renders shortcode render options through var_export() without escaping when the shortcode_debug attribute is set. An authenticated attacker with Contributor-level access or above can inject arbitrary JavaScript through a table shortcode attribute, which then executes for any logged-in user who views the page.... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6254" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Missing Authorization and Stored XSS in MonsterInsights Admin Endpoints and Popular Posts Widget]]></title>
<description><![CDATA[This definition covers two distinct issue classes in MonsterInsights.1) Stored Cross-Site Scripting in the Popular Posts widget. In 8.1.0-8.13.1 the widget concatenated the post title, the post link and the label text straight into markup with no escaping, so a post title containing markup was re...]]></description>
<link>https://tsecurity.de/de/4152954/sicherheitsluecken/missing-authorization-and-stored-xss-in-monsterinsights-admin-endpoints-and-popular-posts-widget/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152954/sicherheitsluecken/missing-authorization-and-stored-xss-in-monsterinsights-admin-endpoints-and-popular-posts-widget/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>This definition covers two distinct issue classes in MonsterInsights.1) Stored Cross-Site Scripting in the Popular Posts widget. In 8.1.0-8.13.1 the widget concatenated the post title, the post link and the label text straight into markup with no escaping, so a post title containing markup was rendered verbatim. Upstream added escaping in 8.14.0.... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6260" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stored Cross-Site Scripting in Enable Media Replace Location Directory Field]]></title>
<description><![CDATA[Enable Media Replace up to and including 4.1.8 renders the 'location_dir' value into an HTML attribute on the media replace screen without escaping it. An authenticated attacker with Author-level access or above can break out of the attribute and inject arbitrary JavaScript, which then executes f...]]></description>
<link>https://tsecurity.de/de/4152953/sicherheitsluecken/stored-cross-site-scripting-in-enable-media-replace-location-directory-field/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152953/sicherheitsluecken/stored-cross-site-scripting-in-enable-media-replace-location-directory-field/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Enable Media Replace up to and including 4.1.8 renders the &#039;location_dir&#039; value into an HTML attribute on the media replace screen without escaping it. An authenticated attacker with Author-level access or above can break out of the attribute and inject arbitrary JavaScript, which then executes for any user who views the affected page. This... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6255" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cache Poisoning and Stored Cross-Site Scripting in WP Supercache]]></title>
<description><![CDATA[WP Super Cache stores the CDN URL and CNAME settings unescaped and substitutes them into the src/href attribute of every rewritten asset URL, so a value containing a quote or an angle bracket breaks out of the attribute and executes script for every visitor. String settings and direct-page paths ...]]></description>
<link>https://tsecurity.de/de/4152952/sicherheitsluecken/cache-poisoning-and-stored-cross-site-scripting-in-wp-supercache/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152952/sicherheitsluecken/cache-poisoning-and-stored-cross-site-scripting-in-wp-supercache/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>WP Super Cache stores the CDN URL and CNAME settings unescaped and substitutes them into the src/href attribute of every rewritten asset URL, so a value containing a quote or an angle bracket breaks out of the attribute and executes script for every visitor. String settings and direct-page paths are written to the cache config file as raw PHP... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6280" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Incorrect Permissions in Ultimate Addons for Elementor Notice Dismissal]]></title>
<description><![CDATA[The bundled Astra Notices library passed the client-supplied notice identifier straight to update_user_meta() and set_transient() when an admin notice was dismissed, without checking it against the notices the plugin had actually registered. An authenticated user could therefore overwrite arbitra...]]></description>
<link>https://tsecurity.de/de/4152951/sicherheitsluecken/incorrect-permissions-in-ultimate-addons-for-elementor-notice-dismissal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152951/sicherheitsluecken/incorrect-permissions-in-ultimate-addons-for-elementor-notice-dismissal/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The bundled Astra Notices library passed the client-supplied notice identifier straight to update_user_meta() and set_transient() when an admin notice was dismissed, without checking it against the notices the plugin had actually registered. An authenticated user could therefore overwrite arbitrary keys of their own user metadata - including... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6270" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stored Cross-Site Scripting in Essential Addons for Elementor Advanced Tabs]]></title>
<description><![CDATA[The Advanced Tabs widget rendered repeater tab titles through a custom HTML allowlist that permitted , and inline style attributes, and additionally parsed shortcodes in them. An authenticated user with page-editing rights could store an iframe or auto-submitting form in a tab title and have it e...]]></description>
<link>https://tsecurity.de/de/4152950/sicherheitsluecken/stored-cross-site-scripting-in-essential-addons-for-elementor-advanced-tabs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152950/sicherheitsluecken/stored-cross-site-scripting-in-essential-addons-for-elementor-advanced-tabs/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The Advanced Tabs widget rendered repeater tab titles through a custom HTML allowlist that permitted , and inline style attributes, and additionally parsed shortcodes in them. An authenticated user with page-editing rights could store an iframe or auto-submitting form in a tab title and have it execute for every visitor of the page. Fixed by... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6269" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Authenticated (Contributor+) Stored Cross-Site Scripting via CF7 and Gravity Forms Styler Form ID]]></title>
<description><![CDATA[The Contact Form 7 and Gravity Forms styler blocks used the formId block attribute directly, concatenating it into a shortcode string that is then echoed. A user able to insert or edit a block (Contributor and above) could set formId to a value that breaks out of the shortcode, causing arbitrary ...]]></description>
<link>https://tsecurity.de/de/4152949/sicherheitsluecken/authenticated-contributor-stored-cross-site-scripting-via-cf7-and-gravity-forms-styler-form-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152949/sicherheitsluecken/authenticated-contributor-stored-cross-site-scripting-via-cf7-and-gravity-forms-styler-form-id/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The Contact Form 7 and Gravity Forms styler blocks used the formId block attribute directly, concatenating it into a shortcode string that is then echoed. A user able to insert or edit a block (Contributor and above) could set formId to a value that breaks out of the shortcode, causing arbitrary HTML or script to be rendered for anyone viewing the... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6279" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Improper Authorization in Magento Admin Shipment Controllers]]></title>
<description><![CDATA[The admin controllers that start, create and save an order shipment checked the broad 'Magento_Sales::shipment' ACL resource instead of the narrower 'Magento_Sales::ship' one, so an admin user granted only read access to shipments could still create and save them. A low-privileged authenticated a...]]></description>
<link>https://tsecurity.de/de/4152948/sicherheitsluecken/improper-authorization-in-magento-admin-shipment-controllers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152948/sicherheitsluecken/improper-authorization-in-magento-admin-shipment-controllers/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The admin controllers that start, create and save an order shipment checked the broad &#039;Magento_Sales::shipment&#039; ACL resource instead of the narrower &#039;Magento_Sales::ship&#039; one, so an admin user granted only read access to shipments could still create and save them. A low-privileged authenticated admin can therefore bypass the intended permission... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6278" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SQL Injection in All-in-One WP Migration and Backup Archive Restore]]></title>
<description><![CDATA[A flaw in the find-and-replace routine used when restoring a backup archive lets a crafted database value ending in an escaped backslash break out of its SQL string literal and append arbitrary SQL to the restore query. An authenticated user with permission to import an archive (or anyone able to...]]></description>
<link>https://tsecurity.de/de/4152947/sicherheitsluecken/sql-injection-in-all-in-one-wp-migration-and-backup-archive-restore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152947/sicherheitsluecken/sql-injection-in-all-in-one-wp-migration-and-backup-archive-restore/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>A flaw in the find-and-replace routine used when restoring a backup archive lets a crafted database value ending in an escaped backslash break out of its SQL string literal and append arbitrary SQL to the restore query. An authenticated user with permission to import an archive (or anyone able to supply an archive that an administrator restores)... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6275" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Login and Register Security Guard Bypass in Essential Addons for Elementor]]></title>
<description><![CDATA[Every security guard in the Login/Register widget — nonce verification, reCAPTCHA, Cloudflare Turnstile and the OTP gate — only terminated the request inside a branch that required the client-supplied Referer header. Omitting that header made a failed check fall through into the login, registrati...]]></description>
<link>https://tsecurity.de/de/4152946/sicherheitsluecken/login-and-register-security-guard-bypass-in-essential-addons-for-elementor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152946/sicherheitsluecken/login-and-register-security-guard-bypass-in-essential-addons-for-elementor/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Every security guard in the Login/Register widget — nonce verification, reCAPTCHA, Cloudflare Turnstile and the OTP gate — only terminated the request inside a branch that required the client-supplied Referer header. Omitting that header made a failed check fall through into the login, registration and password-reset logic instead of aborting,... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6277" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHP Object Injection in Rank Math SEO Schema REST Endpoint]]></title>
<description><![CDATA[The schema REST handler unserialized metadata that WordPress core had already unserialized, so a stored value whose first-pass result is itself a serialized object payload gets instantiated. An author-level user can therefore trigger PHP object injection and, with a suitable gadget chain, execute...]]></description>
<link>https://tsecurity.de/de/4152945/sicherheitsluecken/php-object-injection-in-rank-math-seo-schema-rest-endpoint/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152945/sicherheitsluecken/php-object-injection-in-rank-math-seo-schema-rest-endpoint/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The schema REST handler unserialized metadata that WordPress core had already unserialized, so a stored value whose first-pass result is itself a serialized object payload gets instantiated. An author-level user can therefore trigger PHP object injection and, with a suitable gadget chain, execute arbitrary code. The same release also requires the... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6276" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SQL Injection in Drupal PostgreSQL Entity Query Condition]]></title>
<description><![CDATA[On PostgreSQL-backed Drupal sites, the case-insensitive entity query array condition concatenated the caller-supplied operator straight into a raw SQL fragment without validating it. Code that passes untrusted input as the operator argument (reachable via contrib modules) could inject arbitrary S...]]></description>
<link>https://tsecurity.de/de/4152944/sicherheitsluecken/sql-injection-in-drupal-postgresql-entity-query-condition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152944/sicherheitsluecken/sql-injection-in-drupal-postgresql-entity-query-condition/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>On PostgreSQL-backed Drupal sites, the case-insensitive entity query array condition concatenated the caller-supplied operator straight into a raw SQL fragment without validating it. Code that passes untrusted input as the operator argument (reachable via contrib modules) could inject arbitrary SQL. The fix restricts the operator to IN and NOT IN... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6272" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stored Cross-Site Scripting in Starter Templates SVG Upload]]></title>
<description><![CDATA[Starter Templates through 4.2.1 registers an upload_mimes filter that permits SVG uploads, but never sanitizes the uploaded SVG contents. An authenticated attacker with contributor-level access or above could upload an SVG carrying arbitrary script, which then executes for any user who opens the ...]]></description>
<link>https://tsecurity.de/de/4152943/sicherheitsluecken/stored-cross-site-scripting-in-starter-templates-svg-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152943/sicherheitsluecken/stored-cross-site-scripting-in-starter-templates-svg-upload/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Starter Templates through 4.2.1 registers an upload_mimes filter that permits SVG uploads, but never sanitizes the uploaded SVG contents. An authenticated attacker with contributor-level access or above could upload an SVG carrying arbitrary script, which then executes for any user who opens the file. The fix sanitizes SVG uploads on the... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6274" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Information Disclosure in Elementor Website Builder REST Post Query]]></title>
<description><![CDATA[The Elementor REST post-query endpoint built its WP_Query arguments with post_status 'any' for authenticated requests without restricting results to the requesting user, so any logged-in user (Contributor and above) could enumerate and read the titles and IDs of other authors' private and draft p...]]></description>
<link>https://tsecurity.de/de/4152942/sicherheitsluecken/information-disclosure-in-elementor-website-builder-rest-post-query/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152942/sicherheitsluecken/information-disclosure-in-elementor-website-builder-rest-post-query/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>The Elementor REST post-query endpoint built its WP_Query arguments with post_status &#039;any&#039; for authenticated requests without restricting results to the requesting user, so any logged-in user (Contributor and above) could enumerate and read the titles and IDs of other authors&#039; private and draft posts. The fix restricts the query to the current... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6271" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Privilege Escalation in Rank Math SEO Automated SEO Fix]]></title>
<description><![CDATA[Rank Math SEO before 1.0.277 gated the automated 'fix site SEO' action only on the plugin's own rank_math_site_analysis capability, which Editor-level users hold. An Editor could therefore trigger automated fixes that change site-wide WordPress and plugin settings reserved for administrators. The...]]></description>
<link>https://tsecurity.de/de/4152941/sicherheitsluecken/privilege-escalation-in-rank-math-seo-automated-seo-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152941/sicherheitsluecken/privilege-escalation-in-rank-math-seo-automated-seo-fix/</guid>
<pubDate>Thu, 17 Sep 2026 23:16:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Rank Math SEO before 1.0.277 gated the automated &#039;fix site SEO&#039; action only on the plugin&#039;s own rank_math_site_analysis capability, which Editor-level users hold. An Editor could therefore trigger automated fixes that change site-wide WordPress and plugin settings reserved for administrators. The fix additionally requires the manage_options... <a href="https://portal.patchman.co/detections/rss/vulnerabilities/6273" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco alerts customers to second actively exploited zero-day in as many days]]></title>
<description><![CDATA[Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was exploited before Cisco disclosed and patched the ...]]></description>
<link>https://tsecurity.de/de/4152929/sicherheitsluecken/cisco-alerts-customers-to-second-actively-exploited-zero-day-in-as-many-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152929/sicherheitsluecken/cisco-alerts-customers-to-second-actively-exploited-zero-day-in-as-many-days/</guid>
<pubDate>Thu, 17 Sep 2026 23:12:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was exploited before Cisco disclosed and patched the vulnerability Wednesday. The defect in an API of... <a href="https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco patches max-severity ISE flaw, the second critical zero-day this week]]></title>
<description><![CDATA[Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for t...]]></description>
<link>https://tsecurity.de/de/4152928/sicherheitsluecken/cisco-patches-max-severity-ise-flaw-the-second-critical-zero-day-this-week/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152928/sicherheitsluecken/cisco-patches-max-severity-ise-flaw-the-second-critical-zero-day-this-week/</guid>
<pubDate>Thu, 17 Sep 2026 23:12:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in... <a href="https://www.csoonline.com/article/4223535/cisco-patches-max-severity-ise-flaw-the-second-critical-zero-day-this-week.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-17 23h : 6 posts]]></title>
<description><![CDATA[6 posts published in the last hour 20:31Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point 20:31100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS 20:02New Italian unicorn E...]]></description>
<link>https://tsecurity.de/de/4152927/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-23h-6-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152927/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-23h-6-posts/</guid>
<pubDate>Thu, 17 Sep 2026 23:12:21 +0200</pubDate>
<content:encoded><![CDATA[<p>6 posts published in the last hour 20:31Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point 20:31100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS 20:02New Italian unicorn Exein rides the physical AI wave 20:02Mass-Scanning... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-17-23h-6-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI hates CAPTCHAs - PSW #944]]></title>
<description><![CDATA[In the security news this week:  UK government rolls out passkeys to 20 million users Phishing-resistant authentication and replay resistance Passkey adoption, device security, and user acceptance EU Cyber Resilience Act guidance, scope, and compliance CRA vulnerability disclosure and reporting r...]]></description>
<link>https://tsecurity.de/de/4152926/sicherheitsluecken/ai-hates-captchas-psw-944/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152926/sicherheitsluecken/ai-hates-captchas-psw-944/</guid>
<pubDate>Thu, 17 Sep 2026 23:10:40 +0200</pubDate>
<content:encoded><![CDATA[<p>In the security news this week:</p> <ul> <li>UK government rolls out passkeys to 20 million users</li> <li>Phishing-resistant authentication and replay resistance</li> <li>Passkey adoption, device security, and user acceptance</li> <li>EU Cyber Resilience Act guidance, scope, and compliance</li> <li>CRA vulnerability disclosure and reporting requirements</li> <li>The real cost of cyberattacks and cybersecurity spending</li> <li>Cyber insurance and improving organizational security</li> <li>Nightmare Eclipse and the release of Windows zero-days</li> <li>Check Point VPN vulnerabilities and perimeter security</li> <li>GitLab security updates and shadow IT</li> <li>Discovering unmanaged GitLab instances</li> <li>Cyberattacks against oil tankers and insider threats</li> <li>VPN patching and implied rules</li> <li>Zero-downtime GitLab updates and version management</li> <li>Running Windows ARM on Apple Silicon with VMware and Parallels</li> </ul> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/psw">https://www.securityweekly.com/psw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/psw-944">https://securityweekly.com/psw-944</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8780-1: libsoup vulnerabilities]]></title>
<description><![CDATA[It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects....]]></description>
<link>https://tsecurity.de/de/4152921/sicherheitsluecken/usn-8780-1-libsoup-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152921/sicherheitsluecken/usn-8780-1-libsoup-vulnerabilities/</guid>
<pubDate>Thu, 17 Sep 2026 23:05:19 +0200</pubDate>
<content:encoded><![CDATA[<p>It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects. A remote attacker could possibly use this issue to... <a href="https://ubuntu.com/security/notices/USN-8780-1" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Check Point: Authentifizierungs-Bypass ermöglicht Root-Codeausführung per CVE-2026-91843]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine kritische Schwachstelle in den Security Management und Log Servern von Check Point (CVE-2026-91843) kann es Angreifern ohne Login ermöglichen, Root-Code über das Netzwerk auszuführen. Check Point hat dafür einen LivePatch bereitgestellt und meldet zugleich keine Hinwei...]]></description>
<link>https://tsecurity.de/de/4152892/sicherheitsluecken/check-point-authentifizierungs-bypass-ermoeglicht-root-codeausfuehrung-per-cve-2026-91843/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152892/sicherheitsluecken/check-point-authentifizierungs-bypass-ermoeglicht-root-codeausfuehrung-per-cve-2026-91843/</guid>
<pubDate>Thu, 17 Sep 2026 22:42:27 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Eine kritische Schwachstelle in den Security Management und Log Servern von Check Point (CVE-2026-91843) kann es Angreifern ohne Login ermöglichen, Root-Code über das Netzwerk auszuführen. Check Point hat dafür einen LivePatch bereitgestellt und meldet zugleich keine Hinweise auf bereits beobachtete Ausnutzung. Betroffen... <a href="https://www.it-boltwise.de/check-point-authentifizierungs-bypass-ermoeglicht-root-codeausfuehrung-per-cve-2026-91843.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-17 22h : 5 posts]]></title>
<description><![CDATA[5 posts published in the last hour 19:31Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds 19:02HBO Max’s verified Reddit account hijacked to spread malware 19:02Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk 19:02Flock cameras are tracking people a...]]></description>
<link>https://tsecurity.de/de/4152890/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-22h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152890/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-22h-5-posts/</guid>
<pubDate>Thu, 17 Sep 2026 22:42:18 +0200</pubDate>
<content:encoded><![CDATA[<p>5 posts published in the last hour 19:31Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds 19:02HBO Max’s verified Reddit account hijacked to spread malware 19:02Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk 19:02Flock cameras are tracking people as well as cars 19:00IT Security News Hourly Summary... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-17-22h-5-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS]]></title>
<description><![CDATA[Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible. This article has been indexed from Blog – Wordfence Read the orig...]]></description>
<link>https://tsecurity.de/de/4152889/sicherheitsluecken/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152889/sicherheitsluecken/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/</guid>
<pubDate>Thu, 17 Sep 2026 22:42:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to version 4.0.8 as soon as possible. This article has been indexed from Blog – Wordfence Read the original article: 100,000 WordPress Sites Exposed to... <a href="https://www.itsecuritynews.info/100000-wordpress-sites-exposed-to-remote-code-execution-via-php-object-injection-vulnerability-found-by-wordfence-argus-in-tutor-lms/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8779-1: Bubblewrap vulnerabilities]]></title>
<description><![CDATA[It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-12439) It was discovered that Bubblewrap incorrectly han...]]></description>
<link>https://tsecurity.de/de/4152866/sicherheitsluecken/usn-8779-1-bubblewrap-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152866/sicherheitsluecken/usn-8779-1-bubblewrap-vulnerabilities/</guid>
<pubDate>Thu, 17 Sep 2026 22:35:38 +0200</pubDate>
<content:encoded><![CDATA[<p>It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-12439) It was discovered that Bubblewrap incorrectly handled certain symlinks during sandbox setup. A local... <a href="https://ubuntu.com/security/notices/USN-8779-1" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423]]></title>
<description><![CDATA[Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423 Vulnerability overview CVE-2026-76423 is an authentication bypass in the Cisco Identity Services Engine REST API, disclosed on 16 September 2026 with a CVSS v3 score of 10.0. Cisco's advisory attributes it to t...]]></description>
<link>https://tsecurity.de/de/4152813/sicherheitsluecken/hunting-the-cisco-ise-authentication-bypass-detection-and-response-for-cve-2026-76423/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152813/sicherheitsluecken/hunting-the-cisco-ise-authentication-bypass-detection-and-response-for-cve-2026-76423/</guid>
<pubDate>Thu, 17 Sep 2026 21:18:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423 Vulnerability overview CVE-2026-76423 is an authentication bypass in the Cisco Identity Services Engine REST API, disclosed on 16 September 2026 with a CVSS v3 score of 10.0. Cisco&#039;s advisory attributes it to the REST API web service being exposed with... <a href="https://dev.to/onaeiuspkz/hunting-the-cisco-ise-authentication-bypass-detection-and-response-for-cve-2026-76423-5363" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritische Flaw in Docker Sandboxes: Escape auf macOS über virtio-fs]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Docker warnt vor zwei Lücken in Docker Sandboxes, darunter eine als „Critical“ bewertete Schwachstelle (CVE-2026-77179) auf macOS. Ein bösartiger Code im Sandbox-Gast kann dabei über den virtio-fs Host-Server nach dem Dateifreigabe-Setup Symlinks missbrauchen und Host-Datei...]]></description>
<link>https://tsecurity.de/de/4152797/sicherheitsluecken/kritische-flaw-in-docker-sandboxes-escape-auf-macos-ueber-virtio-fs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152797/sicherheitsluecken/kritische-flaw-in-docker-sandboxes-escape-auf-macos-ueber-virtio-fs/</guid>
<pubDate>Thu, 17 Sep 2026 21:16:28 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Docker warnt vor zwei Lücken in Docker Sandboxes, darunter eine als „Critical“ bewertete Schwachstelle (CVE-2026-77179) auf macOS. Ein bösartiger Code im Sandbox-Gast kann dabei über den virtio-fs Host-Server nach dem Dateifreigabe-Setup Symlinks missbrauchen und Host-Dateien lesen oder ändern. Zusätzlich schließt Docker... <a href="https://www.it-boltwise.de/kritische-flaw-in-docker-sandboxes-escape-auf-macos-ueber-virtio-fs.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-17 21h : 7 posts]]></title>
<description><![CDATA[7 posts published in the last hour 18:3125 Years of Mass Surveillance Is Enough 18:02Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026) 18:02Should you care about an “AI slowdown?” 18:02From guidance to action: Security fundamentals that materia...]]></description>
<link>https://tsecurity.de/de/4152795/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-21h-7-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152795/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-21h-7-posts/</guid>
<pubDate>Thu, 17 Sep 2026 21:16:11 +0200</pubDate>
<content:encoded><![CDATA[<p>7 posts published in the last hour 18:3125 Years of Mass Surveillance Is Enough 18:02Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026) 18:02Should you care about an “AI slowdown?” 18:02From guidance to action: Security fundamentals that materially reduce risk 18:02China’s Salt Typhoon backdoors... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-17-21h-7-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Patching the Check Point VPN flaws: a prioritized response plan for CVE-2026-85102 and CVE-2026-85103]]></title>
<description><![CDATA[Patching the Check Point VPN flaws: a prioritized response plan for CVE-2026-85102 and CVE-2026-85103 When CERT-In issued note CIVN-2026-0459 on September 16, 2026, it described two critical Check Point VPN flaws that an unauthenticated remote attacker can exploit with crafted certificate data du...]]></description>
<link>https://tsecurity.de/de/4152724/sicherheitsluecken/patching-the-check-point-vpn-flaws-a-prioritized-response-plan-for-cve-2026-85102-and-cve-2026-85103/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152724/sicherheitsluecken/patching-the-check-point-vpn-flaws-a-prioritized-response-plan-for-cve-2026-85102-and-cve-2026-85103/</guid>
<pubDate>Thu, 17 Sep 2026 20:16:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Patching the Check Point VPN flaws: a prioritized response plan for CVE-2026-85102 and CVE-2026-85103 When CERT-In issued note CIVN-2026-0459 on September 16, 2026, it described two critical Check Point VPN flaws that an unauthenticated remote attacker can exploit with crafted certificate data during VPN negotiation. This article lays out a... <a href="https://dev.to/stark_zhuang_df5076f35c68/patching-the-check-point-vpn-flaws-a-prioritized-response-plan-for-cve-2026-85102-and-2bhp" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bedrohungen durch KI-Agenten, vergessene APIs und 800 Oracle-Patches]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsvorfälle zeigen diese Woche, wie schnell neue KI- und Angriffsflächen entstehen: von unauthentifizierten LocalAI-Instanzen bis zu Malware, die eigene Befehlsstrings zur Umgehung von EDR-Signaturen umschreibt. Dazu kommen konkrete Software-Schulden wie ein VMware ...]]></description>
<link>https://tsecurity.de/de/4152713/sicherheitsluecken/bedrohungen-durch-ki-agenten-vergessene-apis-und-800-oracle-patches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152713/sicherheitsluecken/bedrohungen-durch-ki-agenten-vergessene-apis-und-800-oracle-patches/</guid>
<pubDate>Thu, 17 Sep 2026 20:13:56 +0200</pubDate>
<content:encoded><![CDATA[<p>LONDON (IT BOLTWISE) – Sicherheitsvorfälle zeigen diese Woche, wie schnell neue KI- und Angriffsflächen entstehen: von unauthentifizierten LocalAI-Instanzen bis zu Malware, die eigene Befehlsstrings zur Umgehung von EDR-Signaturen umschreibt. Dazu kommen konkrete Software-Schulden wie ein VMware vCenter-RCE über Syslog-Directory-Traversal und ein... <a href="https://www.it-boltwise.de/bedrohungen-durch-ki-agenten-vergessene-apis-und-800-oracle-patches.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)]]></title>
<description><![CDATA[Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligen...]]></description>
<link>https://tsecurity.de/de/4152706/sicherheitsluecken/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-7-2026-to-september-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152706/sicherheitsluecken/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-7-2026-to-september-13-2026/</guid>
<pubDate>Thu, 17 Sep 2026 20:13:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with Wordfence Intelligence is to make valuable vulnerability information... <a href="https://www.itsecuritynews.info/wordfence-intelligence-weekly-wordpress-vulnerability-report-september-7-2026-to-september-13-2026/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DFN-CERT-2026-4936 Drupal: Eine Schwachstelle ermöglicht einen Cross-Site-Scripting-Angriff]]></title>
<description><![CDATA[Gruppenleiter*in Managed Windows ServerBerlin, Home Office. TEC2DATE GmbH. IT-Systemadministrator 2nd Level Support (m/w/d)Offenbach am Main. CYCAP ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4152663/sicherheitsluecken/dfn-cert-2026-4936-drupal-eine-schwachstelle-ermoeglicht-einen-cross-site-scripting-angriff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152663/sicherheitsluecken/dfn-cert-2026-4936-drupal-eine-schwachstelle-ermoeglicht-einen-cross-site-scripting-angriff/</guid>
<pubDate>Thu, 17 Sep 2026 19:47:47 +0200</pubDate>
<content:encoded><![CDATA[<p>Gruppenleiter*in Managed Windows ServerBerlin, Home Office. TEC2DATE GmbH. IT-Systemadministrator 2nd Level Support (m/w/d)Offenbach am Main. CYCAP ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.linux-magazin.de/dfn-cert-advisories/dfn-cert-2026-4936-drupal-eine-schwachstelle-ermoeglicht-einen-cross-site-scripting-angriff/&amp;ct=ga&amp;cd=CAIyGWE4YWZlOWE1ODU5MTM3YjQ6ZGU6ZGU6REU&amp;usg=AOvVaw033Tak-4BhGy824jVhQZ_C" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Beauty AR Demo Is Smooth—Now Test the Session It Will Actually Run]]></title>
<description><![CDATA[A Beauty AR proof of concept can look perfect during a 30-second desk test and still struggle in the product you intend to ship. The tension is not simply “performance versus visual quality.” It is deciding which effects must remain available on which devices, under what sustained workload, and w...]]></description>
<link>https://tsecurity.de/de/4152652/poc/your-beauty-ar-demo-is-smooth-now-test-the-session-it-will-actually-run/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152652/poc/your-beauty-ar-demo-is-smooth-now-test-the-session-it-will-actually-run/</guid>
<pubDate>Thu, 17 Sep 2026 19:46:14 +0200</pubDate>
<content:encoded><![CDATA[<p>A Beauty AR proof of concept can look perfect during a 30-second desk test and still struggle in the product you intend to ship. The tension is not simply “performance versus visual quality.” It is deciding which effects must remain available on which devices, under what sustained workload, and what the application should do when that contract... <a href="https://dev.to/susiewang/your-beauty-ar-demo-is-smooth-now-test-the-session-it-will-actually-run-m4e" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-84389 | Fortinet FortiSIEM up to 7.4.2/7.5.1 redirect (Nessus ID 346824)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Fortinet FortiSIEM up to 7.4.2/7.5.1. This impacts an unknown function. The manipulation results in open redirect. This vulnerability is identified as CVE-2026-84389. The attack can be executed remotely. There is not any exploit avai...]]></description>
<link>https://tsecurity.de/de/4152612/sicherheitsluecken/cve-2026-84389-fortinet-fortisiem-up-to-742751-redirect-nessus-id-346824/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152612/sicherheitsluecken/cve-2026-84389-fortinet-fortisiem-up-to-742751-redirect-nessus-id-346824/</guid>
<pubDate>Thu, 17 Sep 2026 19:13:44 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability described as problematic has been identified in Fortinet FortiSIEM up to 7.4.2/7.5.1. This impacts an unknown function. The manipulation results in open redirect. This vulnerability is identified as CVE-2026-84389. The attack can be executed remotely. There is not any exploit available. <a href="https://vuldb.com/vuln/399937" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46671 | msiemens onenote.rs up to 1.1.0 Parser Parser::parse_notebook path traversal (Nessus ID 346804)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in msiemens onenote.rs up to 1.1.0. Affected is the function Parser::parse_notebook of the component Parser. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CVE-2026-46671. The attack can be launched remotely. ...]]></description>
<link>https://tsecurity.de/de/4152611/sicherheitsluecken/cve-2026-46671-msiemens-onenoters-up-to-110-parser-parserparsenotebook-path-traversal-nessus-id-346804/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152611/sicherheitsluecken/cve-2026-46671-msiemens-onenoters-up-to-110-parser-parserparsenotebook-path-traversal-nessus-id-346804/</guid>
<pubDate>Thu, 17 Sep 2026 19:13:44 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in msiemens onenote.rs up to 1.1.0. Affected is the function Parser::parse_notebook of the component Parser. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CVE-2026-46671. The attack can be launched remotely. No exploit exists. Upgrading the affected component... <a href="https://vuldb.com/vuln/380633" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix]]></title>
<description><![CDATA[  Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname "ParaShells." JFrog rates the flaw 7.8 out of 10 on the CVSS severity scale. The bug does not allow remote attacks over a network. An attacker needs code already run...]]></description>
<link>https://tsecurity.de/de/4152580/sicherheitsluecken/parallels-desktop-vulnerability-gives-any-local-mac-user-full-root-access-intel-mac-users-left-without-a-clear-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152580/sicherheitsluecken/parallels-desktop-vulnerability-gives-any-local-mac-user-full-root-access-intel-mac-users-left-without-a-clear-fix/</guid>
<pubDate>Thu, 17 Sep 2026 19:09:52 +0200</pubDate>
<content:encoded><![CDATA[<p>  Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname &quot;ParaShells.&quot; JFrog rates the flaw 7.8 out of 10 on the CVSS severity scale. The bug does not allow remote attacks over a network. An attacker needs code already running on the machine as an ordinary local user, but... <a href="https://www.itsecuritynews.info/parallels-desktop-vulnerability-gives-any-local-mac-user-full-root-access-intel-mac-users-left-without-a-clear-fix/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-09-17 19h : 11 posts]]></title>
<description><![CDATA[11 posts published in the last hour 16:31Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix 16:31FBI, Coast Guard probe suspected cyberattacks on ships entering US waters 16:31New Settra Ransomware Strain Deploys MeshAgent RMM for P...]]></description>
<link>https://tsecurity.de/de/4152579/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-19h-11-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152579/sicherheitsluecken/it-security-news-hourly-summary-2026-09-17-19h-11-posts/</guid>
<pubDate>Thu, 17 Sep 2026 19:09:52 +0200</pubDate>
<content:encoded><![CDATA[<p>11 posts published in the last hour 16:31Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix 16:31FBI, Coast Guard probe suspected cyberattacks on ships entering US waters 16:31New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence 16:31Cyberattack on Tanker Prompts Coast... <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-09-17-19h-11-posts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bransys ELD]]></title>
<description><![CDATA[View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android &lt;11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS &lt;1.1.54 (CVE-2026-86520, CVE-2026-866...]]></description>
<link>https://tsecurity.de/de/4152576/sicherheitsluecken/bransys-eld/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4152576/sicherheitsluecken/bransys-eld/</guid>
<pubDate>Thu, 17 Sep 2026 19:09:24 +0200</pubDate>
<content:encoded><![CDATA[<p>View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android &amp;lt;11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS &amp;lt;1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment... <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,04ms -->