Anwendungssicherheit
🟠 CVE-2026-27060: High Schwachstelle
Contributor PHP Object Injection in ARMember Premium
🔴 CVE-2026-57679: Critical Schwachstelle
Unauthenticated SQL Injection in GeekyBot
🔴 CVE-2026-57625: Critical Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro
🔴 CVE-2026-57677: Critical Schwachstelle
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce
🔴 CVE-2026-57621: Critical Schwachstelle
Unauthenticated PHP Object Injection in Booktics
🔴 CVE-2026-57624: Critical Schwachstelle
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro
ANWENDUNGSSICHERHEIT
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an...
ANWENDUNGSSICHERHEIT
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain...
🟡 CVE-2026-6283: Medium Schwachstelle
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS....
🟡 CVE-2026-56016: Medium Schwachstelle
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id...