Anwendungssicherheit

🔴 CVE-2026-90711: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-90711: Critical Schwachstelle

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip...

17. Sep. 2026 Keine Kommentare
🔴 CVE-2026-57139: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-57139: Critical Schwachstelle

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards...

17. Sep. 2026 Keine Kommentare
🔴 CVE-2026-57138: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-57138: Critical Schwachstelle

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside...

17. Sep. 2026 Keine Kommentare
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens ANWENDUNGSSICHERHEIT

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from...

16. Sep. 2026 Keine Kommentare
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells ANWENDUNGSSICHERHEIT

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more...

16. Sep. 2026 Keine Kommentare
🟡 CVE-2026-82773: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-82773: Medium Schwachstelle

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an...

16. Sep. 2026 Keine Kommentare
🟡 CVE-2023-51769: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2023-51769: Medium Schwachstelle

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

16. Sep. 2026 Keine Kommentare
🟡 CVE-2026-90700: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-90700: Medium Schwachstelle

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the...

16. Sep. 2026 Keine Kommentare
🟡 CVE-2026-90704: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-90704: Medium Schwachstelle

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing...

16. Sep. 2026 Keine Kommentare
🟠 CVE-2026-90701: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-90701: High Schwachstelle

A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file...

16. Sep. 2026 Keine Kommentare