Export limit exceeded: 366264 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 366264 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (366264 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-77140 | 1 Typo3 | 1 Extension "telephone Directory" | 2026-08-28 | N/A |
| The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check. | ||||
| CVE-2026-77138 | 1 Typo3 | 1 Extension "html5 Video Player Vs. Powermail" | 2026-08-28 | N/A |
| The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. | ||||
| CVE-2026-77137 | 1 Typo3 | 1 Extension "forms Export" | 2026-08-28 | N/A |
| The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and read access to the "Forms Export" Backend module. | ||||
| CVE-2026-77135 | 1 Typo3 | 1 Extension "femanager" | 2026-08-28 | N/A |
| The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID. | ||||
| CVE-2026-77134 | 1 Typo3 | 1 Extension "femanager" | 2026-08-28 | N/A |
| The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval. | ||||
| CVE-2026-77133 | 1 Typo3 | 1 Extension "femanager" | 2026-08-28 | N/A |
| The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups. | ||||
| CVE-2026-77131 | 1 Typo3 | 1 Extension "syssy - Typo3 Monitoring & Security Checks" | 2026-08-28 | N/A |
| When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key. | ||||
| CVE-2026-79074 | 1 Google | 1 Chrome | 2026-08-28 | 5.3 Medium |
| Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-77130 | 1 Typo3 | 1 Extension "syssy - Typo3 Monitoring & Security Checks" | 2026-08-28 | N/A |
| The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key. | ||||
| CVE-2026-56096 | 1 Typo3 | 1 Extension "apache Solr For Typo3 - Enterprise Search" | 2026-08-28 | N/A |
| The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration. | ||||
| CVE-2026-56095 | 1 Typo3 | 1 Extension "apache Solr For Typo3 - Enterprise Search" | 2026-08-28 | N/A |
| The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If user-generated content saved in the TYPO3 database can reach an indexed field, this exposes a PHP Object Injection surface. | ||||
| CVE-2026-56094 | 1 Typo3 | 1 Extension "apache Solr For Typo3 - Enterprise Search" | 2026-08-28 | N/A |
| The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read public documents belonging to another site. The same root cause also affects the suggest top-results path when suggest is enabled. | ||||
| CVE-2026-56093 | 1 Typo3 | 1 Extension "apache Solr For Typo3 - Enterprise Search" | 2026-08-28 | N/A |
| The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere. | ||||
| CVE-2026-56092 | 1 Typo3 | 1 Extension "apache Solr For Typo3 - Enterprise Search" | 2026-08-28 | N/A |
| The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages. | ||||
| CVE-2026-12878 | 1 Octopus Deploy | 1 Codefresh | 2026-08-28 | N/A |
| In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. | ||||
| CVE-2026-78576 | 2 Readabler, Wordpress | 2 Readabler, Wordpress | 2026-08-28 | 7.5 High |
| The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-75037 | 1 Ilya-zlobintsev | 1 Lact | 2026-08-28 | 7 High |
| Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566. | ||||
| CVE-2026-16231 | 1 Hbs | 1 Hbs | 2026-08-28 | 8.1 High |
| hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder with the raw callback return value without escaping it, across the cached, uncached, and layout render paths. An application that passes attacker-influenced data, for example user-supplied content from a database, into an async helper callback can therefore have arbitrary HTML and JavaScript injected into the server-rendered page, resulting in stored or reflected cross-site scripting. Versions 2.1.0 through 4.2.1 are affected, and the issue is fixed in 4.3.0, which HTML-escapes async helper output. Applications that intentionally emit raw HTML from an async helper can opt in explicitly with hbs.SafeString. Users should upgrade to 4.3.0. | ||||
| CVE-2026-75038 | 1 Ilya-zlobintsev | 1 Lact | 2026-08-28 | 6.1 Medium |
| UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0. | ||||
| CVE-2026-12600 | 1 Poppler | 1 Innodata Labs | 2026-08-28 | N/A |
| Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in the JPXStream::readCodestream() function, where values controlled from the SIZ segment (such as img.nComps) are used for the memory allocation of tiles and components without adequate validation. This allows an attacker to force excessive memory allocation and cause a resource exhaustion, ultimately causing the pdftoppm process to terminate due to out-of-memory (OOM) conditions. | ||||