Anwendungssicherheit
🟠 CVE-2026-86242: High Schwachstelle
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins...
🟠 CVE-2026-19633: High Schwachstelle
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or...
ANWENDUNGSSICHERHEIT
New Ted Backdoor Hides Inside Victims‘ Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean...
ANWENDUNGSSICHERHEIT
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could...
🟡 CVE-2026-84021: Medium Schwachstelle
The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an...
🟡 CVE-2026-83544: Medium Schwachstelle
The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML...
🟠 CVE-2026-86188: High Schwachstelle
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users'...
🟠 CVE-2026-83625: High Schwachstelle
The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all...
🟠 CVE-2026-78438: High Schwachstelle
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator...
🟠 CVE-2026-77830: High Schwachstelle
The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label...