Anwendungssicherheit
🟡 CVE-2026-57279: Medium Schwachstelle
Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the...
🟡 CVE-2026-15047: Medium Schwachstelle
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context,...
🟠 CVE-2026-66403: High Schwachstelle
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log...
🟠 CVE-2026-66407: High Schwachstelle
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved...
🟠 CVE-2026-18469: High Schwachstelle
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived...
🟠 CVE-2026-19049: High Schwachstelle
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,...
🔴 CVE-2026-19053: Critical Schwachstelle
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a...
ANWENDUNGSSICHERHEIT
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in...
ANWENDUNGSSICHERHEIT
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS)...
🟡 CVE-2026-19337: Medium Schwachstelle
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of...