Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77141 | UNKNOWN | — | The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check … | Aug 25, 2026 |
| CVE-2026-77140 | UNKNOWN | — | The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that … | Aug 25, 2026 |
| CVE-2026-77139 | UNKNOWN | — | The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An … | Aug 25, 2026 |
| CVE-2026-77138 | UNKNOWN | — | The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted … | Aug 25, 2026 |
| CVE-2026-77137 | UNKNOWN | — | The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary … | Aug 25, 2026 |
| CVE-2026-77136 | UNKNOWN | — | The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View … | Aug 25, 2026 |
| CVE-2026-77135 | UNKNOWN | — | The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to … | Aug 25, 2026 |
| CVE-2026-77134 | UNKNOWN | — | The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor … | Aug 25, 2026 |
| CVE-2026-77133 | UNKNOWN | — | The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default … | Aug 25, 2026 |
| CVE-2026-77131 | UNKNOWN | — | When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already … | Aug 25, 2026 |
| CVE-2026-77130 | UNKNOWN | — | The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate … | Aug 25, 2026 |
| CVE-2026-77129 | UNKNOWN | — | The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event … | Aug 25, 2026 |
| CVE-2026-77128 | UNKNOWN | — | The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or … | Aug 25, 2026 |
| CVE-2026-77127 | UNKNOWN | — | The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, … | Aug 25, 2026 |
| CVE-2026-63587 | HIGH | 8.6 | The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry … | Aug 25, 2026 |
| CVE-2026-63586 | CRITICAL | 9.8 | The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without … | Aug 25, 2026 |
| CVE-2026-56096 | UNKNOWN | — | The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. … | Aug 25, 2026 |
| CVE-2026-56095 | UNKNOWN | — | The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and … | Aug 25, 2026 |
| CVE-2026-56094 | UNKNOWN | — | The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder … | Aug 25, 2026 |
| CVE-2026-56093 | UNKNOWN | — | The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A … | Aug 25, 2026 |
| CVE-2026-56092 | UNKNOWN | — | The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, … | Aug 25, 2026 |
| CVE-2026-17548 | UNKNOWN | — | Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view … | Aug 25, 2026 |
| CVE-2026-78701 | MEDIUM | 6.5 | A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By … | Aug 25, 2026 |
| CVE-2026-78322 | MEDIUM | 6.5 | A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, … | Aug 25, 2026 |
| CVE-2026-67578 | HIGH | 7.5 | FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter … | Aug 25, 2026 |