CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-16231 HIGH

CVE-2026-16231 published: hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeh...

View full advisory →
CVE-2026-12878 UNKNOWN

CVE-2026-12878 published: In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

View full advisory →
CVE-2026-77128 UNKNOWN

CVE-2026-77128 published: The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active...

View full advisory →
CVE-2026-77129 UNKNOWN

CVE-2026-77129 published: The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose se...

View full advisory →
CVE-2026-77130 UNKNOWN

CVE-2026-77130 published: The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY projec...

View full advisory →
CVE-2026-77131 UNKNOWN

CVE-2026-77131 published: When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

View full advisory →
CVE-2026-77133 UNKNOWN

CVE-2026-77133 published: The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.

View full advisory →
CVE-2026-77134 UNKNOWN

CVE-2026-77134 published: The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pe...

View full advisory →
CVE-2026-63587 HIGH

CVE-2026-63587 published: The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS ...

View full advisory →
CVE-2026-77127 UNKNOWN

CVE-2026-77127 published: The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error re...

View full advisory →
CVE-2026-56094 UNKNOWN

CVE-2026-56094 published: The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core se...

View full advisory →
CVE-2026-56095 UNKNOWN

CVE-2026-56095 published: The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a ...

View full advisory →
CVE-2026-56096 UNKNOWN

CVE-2026-56096 published: The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed fie...

View full advisory →
CVE-2026-63586 CRITICAL

CVE-2026-63586 published: The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the syst...

View full advisory →
CVE-2026-56093 UNKNOWN

CVE-2026-56093 published: The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through ...

View full advisory →
CVE-2026-17548 UNKNOWN

CVE-2026-17548 published: Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

View full advisory →
CVE-2026-56092 UNKNOWN

CVE-2026-56092 published: The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherite...

View full advisory →
CVE-2026-66882 UNKNOWN

CVE-2026-66882 published: Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured with require_intera...

View full advisory →
CVE-2026-67578 HIGH

CVE-2026-67578 published: FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.

View full advisory →
CVE-2026-78322 MEDIUM

CVE-2026-78322 published: A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string cop...

View full advisory →