Anwendungssicherheit
ANWENDUNGSSICHERHEIT
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds...
🟠 CVE-2026-78276: High Schwachstelle
Editor PHP Object Injection in Fluent Boards Pro
🟠 CVE-2026-13415: High Schwachstelle
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX...
🟠 CVE-2026-47893: High Schwachstelle
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an...
🟠 CVE-2026-47889: High Schwachstelle
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework...
🟠 CVE-2026-47888: High Schwachstelle
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8...
🟠 CVE-2026-47886: High Schwachstelle
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when...
🟠 CVE-2026-47885: High Schwachstelle
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0...
🟠 CVE-2026-47879: High Schwachstelle
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2...
🟠 CVE-2026-81277: High Schwachstelle
Contributor SQL Injection in Suggestion Engine for WooCommerce