CVE-2026-78313
Description détaillée
Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Vecteur d'attaque (CVSS)
Dernières Vulnérabilités
CVE-2026-97185
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
CVE-2026-85682
The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.
CVE-2026-78312
Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
