Anwendungssicherheit
🟡 CVE-2026-16087: Medium Schwachstelle
The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via...
🟡 CVE-2026-67311: Medium Schwachstelle
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects...
🟠 CVE-2026-15052: High Schwachstelle
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
🟠 CVE-2026-67297: High Schwachstelle
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious...
🟠 CVE-2026-67296: High Schwachstelle
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum...
🟠 CVE-2026-67290: High Schwachstelle
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types...
ANWENDUNGSSICHERHEIT
Mythos Asks the Right Question. It Doesn’t Answer It.
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part...
ANWENDUNGSSICHERHEIT
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI...
🟡 CVE-2026-14554: Medium Schwachstelle
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in...
🟠 CVE-2026-18446: High Schwachstelle
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference...