Anwendungssicherheit
ANWENDUNGSSICHERHEIT
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100...
ANWENDUNGSSICHERHEIT
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under...
🟡 CVE-2026-62280: Medium Schwachstelle
Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page...
🟡 CVE-2026-91005: Medium Schwachstelle
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php...
🟡 CVE-2026-81303: Medium Schwachstelle
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the...
🟡 CVE-2026-18063: Medium Schwachstelle
The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up...
🟡 CVE-2026-15402: Medium Schwachstelle
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site...
🟡 CVE-2026-91994: Medium Schwachstelle
Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or...
🟡 CVE-2026-16593: Medium Schwachstelle
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in...
🟠 CVE-2026-19515: High Schwachstelle
The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects...