Anwendungssicherheit
🔴 CVE-2026-72826: Critical Schwachstelle
The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset...
🔴 CVE-2026-72824: Critical Schwachstelle
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a...
🔴 CVE-2026-72822: Critical Schwachstelle
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected
🔴 CVE-2026-72811: Critical Schwachstelle
SiYuan versions
ANWENDUNGSSICHERHEIT
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account....
ANWENDUNGSSICHERHEIT
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense...
🟠 CVE-2026-14679: High Schwachstelle
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count....
🟠 CVE-2026-18945: High Schwachstelle
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation...
🟠 CVE-2026-73618: High Schwachstelle
Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated...
🟠 CVE-2026-49478: High Schwachstelle
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly...