Anwendungssicherheit
🟠 CVE-2026-70374: High Schwachstelle
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in...
🟠 CVE-2026-8761: High Schwachstelle
The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is...
🔴 CVE-2026-15360: Critical Schwachstelle
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in...
🔴 CVE-2026-15210: Critical Schwachstelle
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification...
ANWENDUNGSSICHERHEIT
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could...
ANWENDUNGSSICHERHEIT
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on...
🟠 CVE-2026-18770: High Schwachstelle
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code...
🟠 CVE-2026-18755: High Schwachstelle
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to...
🟠 CVE-2026-14838: High Schwachstelle
Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human...
🟠 CVE-2026-67200: High Schwachstelle
Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem...