Anwendungssicherheit

🔴 CVE-2026-63221: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-63221: Critical Schwachstelle

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions...

02. Aug. 2026 Keine Kommentare
🔴 CVE-2026-17561: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-17561: Critical Schwachstelle

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM...

02. Aug. 2026 Keine Kommentare
🔴 CVE-2026-14919: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-14919: Critical Schwachstelle

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check...

02. Aug. 2026 Keine Kommentare
🔴 CVE-2026-14483: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-14483: Critical Schwachstelle

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all...

02. Aug. 2026 Keine Kommentare
🔴 CVE-2026-63223: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-63223: Critical Schwachstelle

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently...

02. Aug. 2026 Keine Kommentare
🔴 CVE-2026-18452: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-18452: Critical Schwachstelle

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed...

02. Aug. 2026 Keine Kommentare
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks ANWENDUNGSSICHERHEIT

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch...

01. Aug. 2026 Keine Kommentare
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction ANWENDUNGSSICHERHEIT

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform,...

01. Aug. 2026 Keine Kommentare
🟠 CVE-2026-18381: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-18381: High Schwachstelle

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able...

01. Aug. 2026 Keine Kommentare
🟠 CVE-2026-18378: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-18378: High Schwachstelle

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify...

01. Aug. 2026 Keine Kommentare