Vulnérabilités Known-exploited
La partie Known-exploited du flux de menaces de Stateward : 4 incidents et techniques d’attaque curés, chacun expliquant comment cela s’est produit et comment l’éviter dans votre code.
4 Known-exploited entries · 0 curated · part of 476 total advisories
4 affichées
- HIGHKnown-exploitedexploitedCVE-2026-48907Widget Factory · Joomla Content Editor
Widget Factory Joomla Content Editor Improper Access Control Vulnerability. Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
- HIGHKnown-exploitedexploitedCVE-2026-54420LiteSpeed · cPanel Plugin
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability. LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
- HIGHKnown-exploitedexploitedCVE-2026-20262Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability. Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
- CRITICALKnown-exploitedexploitedransomwareCVE-2026-35273Oracle · PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability. Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Recevez le digest hebdo des menaces
Les nouvelles vulnérabilités activement exploitées et les attaques marquantes, chacune avec son correctif, dans votre boîte mail. Sans spam, désinscription à tout moment.
Stateward confronte vos dépendances à cette intelligence à chaque pull request, et ne vous signale que ce qui atteint réellement votre code.
Voyez-le sur votre dépôt