Anwendungssicherheit
🔴 CVE-2026-71948: Critical Schwachstelle
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun...
🔴 CVE-2026-71947: Critical Schwachstelle
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun...
🔴 CVE-2026-71946: Critical Schwachstelle
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun...
🔴 CVE-2026-71945: Critical Schwachstelle
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom...
🔴 CVE-2026-71944: Critical Schwachstelle
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel...
ANWENDUNGSSICHERHEIT
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the...
ANWENDUNGSSICHERHEIT
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its...
🟡 CVE-2026-15211: Medium Schwachstelle
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token...
🟡 CVE-2026-19210: Medium Schwachstelle
A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the...
🟡 CVE-2026-48093: Medium Schwachstelle
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL...