Anwendungssicherheit
🟡 CVE-2026-16959: Medium Schwachstelle
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL...
🟡 CVE-2026-14601: Medium Schwachstelle
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in...
🟠 CVE-2026-16576: High Schwachstelle
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some...
🟠 CVE-2026-59279: High Schwachstelle
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions...
🟠 CVE-2026-47827: High Schwachstelle
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands...
🟠 CVE-2026-16323: High Schwachstelle
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue...
🟠 CVE-2026-63046: High Schwachstelle
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands...
🟠 CVE-2026-61400: High Schwachstelle
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality...
🟠 CVE-2026-50112: High Schwachstelle
SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing...
🔴 CVE-2026-77776: Critical Schwachstelle
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points...