Anwendungssicherheit
🔴 CVE-2026-14175: Critical Schwachstelle
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows...
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained...
ANWENDUNGSSICHERHEIT
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the...
🟠 CVE-2026-18587: High Schwachstelle
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config...
🟠 CVE-2026-18642: High Schwachstelle
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock:...
🟠 CVE-2026-18599: High Schwachstelle
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the...
🟠 CVE-2026-69088: High Schwachstelle
Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall()...
🟠 CVE-2026-16539: High Schwachstelle
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in...
🟠 CVE-2026-16572: High Schwachstelle
The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it...
🟠 CVE-2026-69096: High Schwachstelle
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS...