Anwendungssicherheit
🔴 CVE-2026-90711: Critical Schwachstelle
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip...
🔴 CVE-2026-57139: Critical Schwachstelle
PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards...
🔴 CVE-2026-57138: Critical Schwachstelle
PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside...
ANWENDUNGSSICHERHEIT
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from...
ANWENDUNGSSICHERHEIT
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more...
🟡 CVE-2026-82773: Medium Schwachstelle
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an...
🟡 CVE-2023-51769: Medium Schwachstelle
Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.
🟡 CVE-2026-90700: Medium Schwachstelle
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the...
🟡 CVE-2026-90704: Medium Schwachstelle
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing...
🟠 CVE-2026-90701: High Schwachstelle
A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file...