Anwendungssicherheit
🔴 CVE-2026-60090: Critical Schwachstelle
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema,...
🔴 CVE-2026-61447: Critical Schwachstelle
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import...
ANWENDUNGSSICHERHEIT
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited,...
ANWENDUNGSSICHERHEIT
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China-...
🟡 CVE-2026-15104: Medium Schwachstelle
The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL...
🟠 CVE-2026-60091: High Schwachstelle
PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is...
🟠 CVE-2026-59794: High Luecke in Jetbrains Teamcity
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
🟠 CVE-2026-33382: High Schwachstelle
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it....
🟠 CVE-2026-40007: High Schwachstelle
Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap receiver's readLength method calls itself recursively...
🟠 CVE-2026-40006: High Schwachstelle
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulnerability in...