Anwendungssicherheit
🟠 CVE-2026-78314: High Schwachstelle
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
🔴 CVE-2026-78211: Critical Schwachstelle
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious...
ANWENDUNGSSICHERHEIT
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX,...
ANWENDUNGSSICHERHEIT
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish...
🟡 CVE-2026-62385: Medium Schwachstelle
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files...
🟡 CVE-2026-4561: Medium Schwachstelle
The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post...
🟡 CVE-2026-4559: Medium Schwachstelle
The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode...
🟡 CVE-2026-62381: Medium Schwachstelle
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with...
🟡 CVE-2026-62204: Medium Schwachstelle
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with...
🟡 CVE-2026-77988: Medium Schwachstelle
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration...