Anwendungssicherheit
🟠 CVE-2026-44094: High Schwachstelle
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including...
🟠 CVE-2026-13395: High Schwachstelle
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter...
🔴 CVE-2026-44092: Critical Schwachstelle
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it...
🔴 CVE-2026-58046: Critical Schwachstelle
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary...
ANWENDUNGSSICHERHEIT
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used...
ANWENDUNGSSICHERHEIT
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain...
🟠 CVE-2026-58151: High Schwachstelle
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects...
🟠 CVE-2026-63231: High Schwachstelle
A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the...
🟠 CVE-2026-14270: High Schwachstelle
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary...
🔴 CVE-2026-63230: Critical Schwachstelle
A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally...