Endpunktsicherheit
🔴 CVE-2026-63234: Critical Schwachstelle
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark...
🔴 CVE-2026-63233: Critical Schwachstelle
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall...
🔴 CVE-2026-63232: Critical Schwachstelle
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement...
Windows 11 KB5101684 update released with 42 changes and fixes
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional...
ENDPUNKTSICHERHEIT
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has...
🟡 CVE-2026-18047: Medium Schwachstelle
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for...
🟠 CVE-2026-14516: High Schwachstelle
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the...
🟠 CVE-2026-12800: High Schwachstelle
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter...
🟠 CVE-2026-14328: High Schwachstelle
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in...
🔴 CVE-2026-16462: Critical Schwachstelle
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL...