Aggregator
CVE-2026-48760 | Symfony HtmlSanitizer URL Parser clickjacking
1 week 2 days ago
A vulnerability labeled as problematic has been found in Symfony. This impacts an unknown function of the component HtmlSanitizer URL Parser. Executing a manipulation can lead to clickjacking.
This vulnerability appears as CVE-2026-48760. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-48747 | Symfony Mailer Webhook Parser downgrade
1 week 2 days ago
A vulnerability identified as problematic has been detected in Symfony. This affects an unknown function of the component Mailer Webhook Parser. Performing a manipulation results in algorithm downgrade.
This vulnerability is reported as CVE-2026-48747. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-48736 | Symfony IpUtils::PRIVATE_SUBNETS server-side request forgery
1 week 2 days ago
A vulnerability categorized as critical has been discovered in Symfony. The impacted element is the function IpUtils::PRIVATE_SUBNETS. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-48736. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-48489 | Symfony Firewall authorization
1 week 2 days ago
A vulnerability was found in Symfony. It has been rated as critical. The affected element is an unknown function of the component Firewall. This manipulation causes incorrect authorization.
This vulnerability is registered as CVE-2026-48489. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-36521 | Sanluan PublicCMS 5.202506.d Site Configuration Management cross site scripting
1 week 2 days ago
A vulnerability was found in Sanluan PublicCMS 5.202506.d. It has been declared as problematic. Impacted is an unknown function of the component Site Configuration Management Module. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-36521. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-37216 | RuoYi 4.8.2 /system/notice/add cross site scripting (Issue 320)
1 week 2 days ago
A vulnerability was found in RuoYi 4.8.2. It has been classified as problematic. This issue affects some unknown processing of the file /system/notice/add. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-37216. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-50876 | Deck9 Input 2.0.1 cross site scripting
1 week 2 days ago
A vulnerability was found in Deck9 Input 2.0.1 and classified as problematic. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-50876. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-52702 | wp-buy SEO Redirection Plugin up to 9.17 on WordPress cross site scripting
1 week 2 days ago
A vulnerability has been found in wp-buy SEO Redirection Plugin up to 9.17 on WordPress and classified as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-52702. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-49773 | FolioVision FV Flowplayer Video Player Plugin 7.5.49.7212 on WordPress cross site scripting
1 week 2 days ago
A vulnerability, which was classified as problematic, was found in FolioVision FV Flowplayer Video Player Plugin 7.5.49.7212 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-49773. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-49055 | Glen Don Mongaya Drag and Drop Multiple File Upload Plugin up to 1.3.9.7 on WordPress cross site scripting
1 week 2 days ago
A vulnerability, which was classified as problematic, has been found in Glen Don Mongaya Drag and Drop Multiple File Upload Plugin up to 1.3.9.7 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-49055. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-49043 | WP Engine WP Migrate Lite Plugin up to 2.7.8 on WordPress cross-site request forgery
1 week 2 days ago
A vulnerability classified as problematic was found in WP Engine WP Migrate Lite Plugin up to 2.7.8 on WordPress. Affected is an unknown function. The manipulation results in cross-site request forgery.
This vulnerability was named CVE-2026-49043. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-48966 | FunnelKit Funnel Builder Plugin up to 3.15.0.2 on WordPress cross site scripting
1 week 2 days ago
A vulnerability classified as problematic has been found in FunnelKit Funnel Builder Plugin up to 3.15.0.2 on WordPress. This impacts an unknown function. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-48966. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-50891 | Filestash 0.4.0 /admin/api/config access control
1 week 2 days ago
A vulnerability described as critical has been identified in Filestash 0.4.0. This affects an unknown function of the file /admin/api/config. Executing a manipulation can lead to improper access controls.
This vulnerability is handled as CVE-2026-50891. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-50889 | LLDAP 0.6.2 Refresh Token denial of service
1 week 2 days ago
A vulnerability marked as problematic has been reported in LLDAP 0.6.2. The impacted element is an unknown function of the component Refresh Token Handler. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-50889. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-52721 | GStreamer PCAP File out-of-bounds (Nessus ID 321136)
1 week 2 days ago
A vulnerability labeled as critical has been found in GStreamer. The affected element is an unknown function of the component PCAP File Handler. Such manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-52721. The attack may be launched remotely. There is no exploit available.
vuldb.com
Худший кошмар параноика стал реальностью. Ошибка в LiteLLM подменяет ответы ИИ на чужой код
1 week 2 days ago
Доверенный посредник внезапно оказался самым опасным участником цепочки.
Meta在Facebook上推出全新的“AI模式”
1 week 2 days ago
Meta在Facebook上推出全新的“AI模式”为了在人工智能竞赛中迎头赶上,并提升其人工智能机器人的用户参与度,Meta公司周一宣布,将在 Facebook 平台上推出新的人工智能功能,旨在改变用
AMD悄悄从消费级处理器中禁用TSME透明安全内存加密技术引起忠实用户的不满
1 week 2 days ago
The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy
1 week 2 days ago
In the latest episode of Identity Insider, I sat down with Chris Hughes, a cybersecurity expert who’s involved in OWASP’s work on non-human and machine identity security. Unsurprisingly, our discussion centered on the rapidly changing cybersecurity landscape, driven by the rise of artificial intelligence (AI), particularly agentic AI, which is giving systems unprecedented autonomy within the enterprise. You can watch our full discussion here: The conversation reinforced something I’ve been thinking about for a while: … More →
The post The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy appeared first on Help Net Security.
Help Net Security