Anwendungssicherheit
🟡 CVE-2026-10061: Medium Schwachstelle
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of...
🟡 CVE-2026-10060: Medium Schwachstelle
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation...
🟡 CVE-2026-9243: Medium Schwachstelle
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the...
🟡 CVE-2026-9714: Medium Schwachstelle
The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule]...
🟡 CVE-2026-6275: Medium Schwachstelle
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up...
🟡 CVE-2025-14042: Medium Schwachstelle
The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom...
🟡 CVE-2026-45619: Medium Schwachstelle
WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use...
🟠 CVE-2026-9808: High Schwachstelle
An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured...
🟠 CVE-2026-4776: High Schwachstelle
An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters,...
🟠 CVE-2026-10072: High Schwachstelle
DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell...