Anwendungssicherheit
🟠 CVE-2026-16800: High Schwachstelle
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows...
🟠 CVE-2026-45813: High Schwachstelle
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add...
🔴 CVE-2026-12877: Critical Schwachstelle
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input...
ANWENDUNGSSICHERHEIT
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link...
ANWENDUNGSSICHERHEIT
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain...
🟡 CVE-2026-13119: Medium Schwachstelle
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard'...
🟡 CVE-2026-13009: Medium Schwachstelle
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all...
🟠 CVE-2026-57769: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in Grand Photography
🟠 CVE-2026-57767: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro
🟠 CVE-2026-57735: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in Breakdance