Accueil
Publications CVE
Les vulnérabilités découvertes par notre équipe R&D et publiées en divulgation coordonnée.
2026
Critical
Microsoft HEVC Video Extension: Heap Out-of-Bounds Write via an Unclamped NumDeltaPocs in st_ref_pic_set
Jean-Jamil KHALIFÉ
CVE-2026-58599
Critical
Microsoft Raw Image Extension: Out-of-Bounds Write in parse_kodak_ifd Reached by RAW Thumbnail Rendering
Jean-Jamil KHALIFÉ
CVE-2026-69649
Medium
TYPO3 CMS: Missing Authorization in the Backend Localization Wizard Leading to Information Disclosure
Jean-Jamil KHALIFÉ
CVE-2026-77132TYPO3-CORE-SA-2026-022
Critical
Contao Comments Bundle: Zero-Click Stored Cross-Site Scripting in the Back Office Comment List
Jean-Jamil KHALIFÉ
GHSA-628f-v4f6-p37r
Medium
Contao CMS: Unrestricted Activation Email Resending and Registration Oracle
Jean-Jamil KHALIFÉ
GHSA-mfxh-vp55-7gc6
Medium
Contao CMS: Improper Access Control in the CSV Import Wizard
Jean-Jamil KHALIFÉ
GHSA-23w9-4pg3-xwm3
Medium
Contao CMS: Unauthenticated Path Traversal in the Images Controller
Jean-Jamil KHALIFÉ
GHSA-mrvp-7wmx-5m4h
Low
Contao CMS: Cross-Site Request Forgery in Custom Back End Actions
Jean-Jamil KHALIFÉ
GHSA-9ff2-p842-45wq
Medium
Contao Newsletter Bundle: Improper Access Control in the Newsletter Module
Jean-Jamil KHALIFÉ
GHSA-3r9g-pfhv-3228
Medium
Contao CMS: Improper Access Control in the Preview Links Module
Jean-Jamil KHALIFÉ
GHSA-q6wp-fr43-gm9v
Medium
Contao CMS: Stored Cross-Site Scripting in the Front End Search Results
Jean-Jamil KHALIFÉ
GHSA-h57j-5f5m-789v
High
Contao CMS: Privilege Escalation to Code Execution through the Theme Import
Jean-Jamil KHALIFÉ
GHSA-r9qp-pqx5-8369
Critical
Shopware 6: App Script Sandbox Escape leading to Arbitrary PHP and OS Command Execution
Jean-Jamil KHALIFÉ
GHSA-6qhw-38wm-7g7h
High
Shopware 6: Path Traversal via media.fileExtension leading to Remote Code Execution
Jean-Jamil KHALIFÉ
GHSA-p67w-3mq7-rw2g
High
Shopware 6: Pre-Authentication SQL Injection in the Store API
Jean-Jamil KHALIFÉ
GHSA-p37c-pm9p-7vm5
2023
High
Netskope Client Service Local Privilege Escalation (USER to SYSTEM)
Jean-Jamil KHALIFÉ
CVE-2023-2270
Critical
NETGEAR Nighthawk R7000P upnpd Pre-Authentication Stack Buffer Overflow (Remote Code Execution)
Jean-Jamil KHALIFÉ
CVE-2022-48322
2022
High
NETGEAR R6900P and R7000P: post-authentication buffer overflow (PSV-2022-0156)
Jean-Jamil KHALIFÉ
High
NETGEAR Nighthawk R7000P: multiple post-authentication vulnerabilities
Jean-Jamil KHALIFÉ
High
NETGEAR Nighthawk R7000P aws_json Unauthenticated Double Stack Buffer Overflow (Pre-Auth RCE)
Jean-Jamil KHALIFÉ
CVE-2022-48176
High
NETGEAR Multiple Products upnpd Pre-Authentication Buffer Overflow (Pre-Auth RCE)
Jean-Jamil KHALIFÉ
CVE-2022-27643
Aucune advisory ne correspond à votre recherche.
Notre R&D traque les vulnérabilités.
Recherche de 0-day, reverse engineering, divulgation coordonnée : découvrez notre pôle R&D.
Découvrir notre R&D