Anwendungssicherheit
🔴 CVE-2026-77006: Critical Schwachstelle
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of...
🔴 CVE-2026-81402: Critical Schwachstelle
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on...
ANWENDUNGSSICHERHEIT
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process...
ANWENDUNGSSICHERHEIT
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according...
🟠 CVE-2026-17037: High Schwachstelle
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
🟠 CVE-2026-82578: High Schwachstelle
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a...
🟠 CVE-2026-87776: High Schwachstelle
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a...
🟠 CVE-2026-89174: High Schwachstelle
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain...
🟠 CVE-2026-38058: High Schwachstelle
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which...
🟠 CVE-2026-78224: High Schwachstelle
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data...