Anwendungssicherheit
🟠 CVE-2026-15215: High Schwachstelle
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions...
🔴 CVE-2026-71560: Critical Luecke in Apache Fory
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when...
🔴 CVE-2026-19264: Critical Schwachstelle
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto...
🔴 CVE-2022-4995: Critical Schwachstelle
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to...
🔴 CVE-2026-71558: Critical Luecke in Apache Fory
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0....
🔴 CVE-2026-16258: Critical Schwachstelle
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to...
ANWENDUNGSSICHERHEIT
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a...
ANWENDUNGSSICHERHEIT
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited...
🟡 CVE-2026-5158: Medium Schwachstelle
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site...
🟡 CVE-2026-18967: Medium Schwachstelle
A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as...