Anwendungssicherheit
🟠 CVE-2026-82655: High Schwachstelle
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to...
🟠 CVE-2026-82644: High Schwachstelle
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other...
🟠 CVE-2026-82636: High Schwachstelle
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because...
🟠 CVE-2026-82642: High Schwachstelle
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with...
🟠 CVE-2026-81660: High Schwachstelle
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to...
🟠 CVE-2026-76585: High Schwachstelle
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received...
ANWENDUNGSSICHERHEIT
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager...
ANWENDUNGSSICHERHEIT
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the...
🟡 CVE-2026-77010: Medium Schwachstelle
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API...
🟡 CVE-2026-76547: Medium Schwachstelle
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a...