Anwendungssicherheit
🟠 CVE-2026-28220: High Schwachstelle
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues...
🟠 CVE-2026-64623: High Schwachstelle
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty...
🟠 CVE-2026-11349: High Schwachstelle
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise...
🟠 CVE-2026-45270: High Schwachstelle
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify`...
🟠 CVE-2026-25039: High Schwachstelle
Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name,...
🟠 CVE-2026-21824: High Schwachstelle
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing...
🟠 CVE-2026-10081: High Schwachstelle
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the...
🔴 CVE-2026-57308: Critical Schwachstelle
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate...
🔴 CVE-2026-53421: Critical Schwachstelle
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the...
ANWENDUNGSSICHERHEIT
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution,...