Anwendungssicherheit
🟠 CVE-2026-74893: High Schwachstelle
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to...
🟠 CVE-2026-74845: High Schwachstelle
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload...
🔴 CVE-2026-74891: Critical Schwachstelle
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access...
🔴 CVE-2026-74878: Critical Schwachstelle
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and...
ANWENDUNGSSICHERHEIT
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software...
ANWENDUNGSSICHERHEIT
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited...
🟠 CVE-2026-13424: High Schwachstelle
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons...
🟠 CVE-2026-10734: High Schwachstelle
The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up...
🟠 CVE-2026-18653: High Schwachstelle
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a...
🟠 CVE-2026-17581: High Schwachstelle
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the...