Anwendungssicherheit
🟠 CVE-2026-3018: High Schwachstelle
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to,...
🟠 CVE-2026-8637: High Schwachstelle
A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated...
🟠 CVE-2026-52750: High Luecke in Nsa Ghidra
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly...
🟠 CVE-2026-45569: High Schwachstelle
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006...
🟠 CVE-2026-45565: High Schwachstelle
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30)...
🟠 CVE-2026-46558: High Luecke in Plane Plane
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any...
🟠 CVE-2026-45567: High Schwachstelle
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is...
🟠 CVE-2026-45549: High Schwachstelle
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179)...
🟠 CVE-2026-3326: High Schwachstelle
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL...
🟠 CVE-2026-20251: High Schwachstelle
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132,...