🛡 Cybersecurity & Privacy 🛡 - CVEs
описание
🔐 Explore the latest CVEs in cybersecurity and privacy. 🔔 Daily updates. 💻 Ensuring your online security. 📩 lalilolalo.dev@gmail.com
456
подписчиков
Охват к подписчикам
1,1%
ERR
Реакции к просмотрам
0,00%
0 на 50 постов
Пересылки к просмотрам
0,00%
0
Постов в день
36,6
всего 256
Где отзываются чаще
доля реакций к просмотрам- 23:35‼️ CVE-2026-54730 ‼️ authentik is an opensource identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome devicetrust stages advance the flow without confirming that the outofband device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED or the deprecated Google Chrome Device Trust Connector stage in an authentication flow. The device attestation occurs in a verification iframe that calls the Google Verified Access API and records the verified device on success, but the vulnerable stages treat the flow as passed as soon as the stage is submitted. An attacker who can reach such a stage, including after primary username and password authentication, can skip the verification iframe and authenticate from a device ... 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:35‼️ CVE-2026-49223 ‼️ Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a lowprivileged Vendor to manage reviews under another Vendor's products. The adminsqlsqliteproductreview.sql queries accept a callercontrolled productreviewid and do not verify productreview.productid against product.adminid for the current adminid. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:35‼️ CVE-2026-49223 ‼️ Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a lowprivileged Vendor to manage reviews under another Vendor's products. The adminsqlsqliteproductreview.sql queries accept a callercontrolled productreviewid and do not verify productreview.productid against product.adminid for the current adminid. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:35‼️ CVE-2026-49223 ‼️ Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a lowprivileged Vendor to manage reviews under another Vendor's products. The adminsqlsqliteproductreview.sql queries accept a callercontrolled productreviewid and do not verify productreview.productid against product.adminid for the current adminid. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:35‼️ CVE-2026-49223 ‼️ Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a lowprivileged Vendor to manage reviews under another Vendor's products. The adminsqlsqliteproductreview.sql queries accept a callercontrolled productreviewid and do not verify productreview.productid against product.adminid for the current adminid. An attacker can read pending review content, ratings, author information, and moderation state, change review status, edit review content, or delete reviews, manipulating product review visibility and integrity. This issue is fixed in version 1.0.8.4. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:35‼️ CVE-2026-49222 ‼️ Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product question operations allow a lowprivileged Vendor to manage questions under another Vendor's products. The adminsqlsqliteproductquestion.sql queries accept a callercontrolled productquestionid and do not verify productquestion.productid against product.adminid for the current adminid. An attacker can read pending question content and moderation data, change question status, edit question content, or delete questions, manipulating product QA visibility and integrity. This issue is fixed in version 1.0.8.4. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:33‼️ CVE-2026-48744 ‼️ Saleor is an ecommerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleorpermissionutils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType and translation queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:33‼️ CVE-2026-48744 ‼️ Saleor is an ecommerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleorpermissionutils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType and translation queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:33‼️ CVE-2026-48744 ‼️ Saleor is an ecommerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleorpermissionutils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType and translation queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:33‼️ CVE-2026-48744 ‼️ Saleor is an ecommerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleorpermissionutils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType and translation queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:33‼️ CVE-2026-48744 ‼️ Saleor is an ecommerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleorpermissionutils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType and translation queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%
- 23:33‼️ CVE-2026-52606 ‼️ A reflected crosssite scripting XSS vulnerability in reporticoweb 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the executemodePREPARE parameter of run.php. 📖 Read more. 🔗 Via "National Vulnerability Database" ---------- 👁️ Seen on @cibsecurity_CVEs0,00%