Anwendungssicherheit
🔴 CVE-2026-47210: Critical Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary...
🔴 CVE-2026-10557: Critical Schwachstelle
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices....
🔴 CVE-2026-47208: Critical Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This...
🔴 CVE-2026-47140: Critical Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as...
🔴 CVE-2026-47137: Critical Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check...
🔴 CVE-2026-47131: Critical Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__...
ANWENDUNGSSICHERHEIT
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result...
ANWENDUNGSSICHERHEIT
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding...
🟠 CVE-2023-33999: High Schwachstelle
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This...
🟠 CVE-2026-46697: High Schwachstelle
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy...