Anwendungssicherheit
🔴 CVE-2026-16947: Critical Schwachstelle
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it...
🔴 CVE-2026-77012: Critical Schwachstelle
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on...
🔴 CVE-2026-15369: Critical Schwachstelle
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and...
🔴 CVE-2026-82448: Critical Schwachstelle
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute...
🔴 CVE-2026-14494: Critical Schwachstelle
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,...
🔴 CVE-2026-16259: Critical Schwachstelle
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action...
🔴 CVE-2026-82542: Critical Schwachstelle
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file...
🔴 CVE-2026-82456: Critical Schwachstelle
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN...
ANWENDUNGSSICHERHEIT
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known...
ANWENDUNGSSICHERHEIT
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and...