Anwendungssicherheit
🔴 CVE-2026-4703: Critical Schwachstelle
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection...
🔴 CVE-2026-78003: Critical Schwachstelle
The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up...
ANWENDUNGSSICHERHEIT
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and...
ANWENDUNGSSICHERHEIT
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name,...
🟡 CVE-2026-74866: Medium Schwachstelle
@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return...
🟡 CVE-2026-59296: Medium Schwachstelle
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous...
🟡 CVE-2026-59318: Medium Schwachstelle
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is...
🟡 CVE-2026-77769: Medium Schwachstelle
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc...
🟡 CVE-2026-77768: Medium Schwachstelle
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evalua...
🟡 CVE-2026-77763: Medium Schwachstelle
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target...