Anwendungssicherheit

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories ANWENDUNGSSICHERHEIT

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100...

17. Sep. 2026 Keine Kommentare
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution ANWENDUNGSSICHERHEIT

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-62280: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-62280: Medium Schwachstelle

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-91005: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-91005: Medium Schwachstelle

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-81303: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-81303: Medium Schwachstelle

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-18063: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-18063: Medium Schwachstelle

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-15402: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-15402: Medium Schwachstelle

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-91994: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-91994: Medium Schwachstelle

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-16593: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-16593: Medium Schwachstelle

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in...

17. Sep. 2026 Keine Kommentare
🟠 CVE-2026-19515: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-19515: High Schwachstelle

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects...

17. Sep. 2026 Keine Kommentare