Anwendungssicherheit
🔴 CVE-2026-14950: Critical Schwachstelle
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it...
🔴 CVE-2026-73992: Critical Schwachstelle
Subscriber Remote Code Execution (RCE) in Query Wrangler
ANWENDUNGSSICHERHEIT
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence...
ANWENDUNGSSICHERHEIT
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers...
🟠 CVE-2026-66668: High Schwachstelle
Subscriber SQL Injection in Community by PeepSo
🟠 CVE-2026-32552: High Schwachstelle
Subscriber SQL Injection in YITH WooCommerce Membership Premium
🟠 CVE-2026-16950: High Schwachstelle
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a...
🟠 CVE-2026-16616: High Schwachstelle
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by...
🟠 CVE-2026-12983: High Schwachstelle
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query,...
🟠 CVE-2024-58376: High Schwachstelle
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with...