Anwendungssicherheit
ANWENDUNGSSICHERHEIT
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example „sk-1234“ Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's...
ANWENDUNGSSICHERHEIT
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to...
🟠 CVE-2026-90495: High Schwachstelle
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file...
🟠 CVE-2026-90668: High Schwachstelle
The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows...
🟠 CVE-2026-16482: High Schwachstelle
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare'...
🟠 CVE-2026-90651: High Schwachstelle
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and...
🟠 CVE-2026-84047: High Schwachstelle
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in...
🟠 CVE-2026-80491: High Schwachstelle
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL...
🟠 CVE-2026-78175: High Schwachstelle
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all...
🟠 CVE-2026-81742: High Schwachstelle
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read,...