Endpunktsicherheit
🟠 CVE-2025-60357: High Schwachstelle
AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
🟠 CVE-2026-63093: High Schwachstelle
Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by...
ENDPUNKTSICHERHEIT
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already...
ENDPUNKTSICHERHEIT
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to...
🟡 CVE-2026-44596: Medium Luecke in Spaceapplications Yamcs
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked...
🟡 CVE-2026-15022: Medium Schwachstelle
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored...
🟠 CVE-2026-63305: High Schwachstelle
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated...
🟠 CVE-2026-35147: High Schwachstelle
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's...
🟠 CVE-2026-57206: High Schwachstelle
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin...
🟠 CVE-2026-63306: High Schwachstelle
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs...