Anwendungssicherheit
🟠 CVE-2026-18358: High Schwachstelle
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system...
🟠 CVE-2026-14830: High Schwachstelle
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid...
🟠 CVE-2026-12720: High Schwachstelle
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated...
🟠 CVE-2026-63222: High Schwachstelle
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename...
🟠 CVE-2026-56671: High Schwachstelle
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py...
🟠 CVE-2026-10685: High Schwachstelle
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already...
🟠 CVE-2026-15258: High Schwachstelle
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules...
🟠 CVE-2026-56672: High Schwachstelle
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG...
🟠 CVE-2026-10079: High Schwachstelle
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment...
🟠 CVE-2026-12721: High Schwachstelle
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using...