Anwendungssicherheit
🟠 CVE-2026-85150: High Schwachstelle
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or...
🟠 CVE-2026-85124: High Schwachstelle
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the...
🟠 CVE-2026-80754: High Schwachstelle
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo During...
ANWENDUNGSSICHERHEIT
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to...
ANWENDUNGSSICHERHEIT
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow...
🟠 CVE-2026-84800: High Schwachstelle
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId...
🟠 CVE-2026-84794: High Schwachstelle
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer...
🟠 CVE-2026-81775: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in Estatik
🟠 CVE-2026-81771: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in TrustedSite
🟠 CVE-2026-81770: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps