Anwendungssicherheit
🟠 CVE-2026-72810: High Schwachstelle
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered...
🟠 CVE-2026-15205: High Schwachstelle
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a...
🟠 CVE-2026-73673: High Schwachstelle
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images...
🟠 CVE-2026-72833: High Schwachstelle
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and
🟠 CVE-2026-72831: High Schwachstelle
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API....
🟠 CVE-2026-72827: High Schwachstelle
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute...
🟠 CVE-2026-72819: High Schwachstelle
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated...
🟠 CVE-2026-19821: High Schwachstelle
A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the...
🔴 CVE-2026-72830: Critical Schwachstelle
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys...
🔴 CVE-2026-72829: Critical Schwachstelle
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods...