Endpunktsicherheit
🟠 CVE-2026-82645: High Schwachstelle
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both...
🟠 CVE-2026-82641: High Schwachstelle
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream...
🟠 CVE-2026-82635: High Schwachstelle
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization....
🟠 CVE-2026-76585: High Schwachstelle
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received...
🔴 CVE-2026-82592: Critical Schwachstelle
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component...
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data,...
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers...
🟡 CVE-2026-18233: Medium Schwachstelle
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints...
🟠 CVE-2026-82472: High Schwachstelle
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated...
🟠 CVE-2026-82475: High Schwachstelle
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated...