Endpunktsicherheit
🟡 CVE-2016-20083: Medium Schwachstelle
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling...
🟡 CVE-2026-8386: Medium Schwachstelle
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint,...
🟡 CVE-2026-11931: Medium Schwachstelle
Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file...
🔴 CVE-2026-36537: Critical Schwachstelle
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity...
AKTIV AUSGENUTZT – 🔴 CVE-2026-20262: Critical Luecke in Cisco Catalyst_Sd-Wan_Manager
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker...
Chinese hackers breach REDCap servers, steal medical research
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical...
ENDPUNKTSICHERHEIT
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as...
🟡 CVE-2016-20077: Medium Schwachstelle
WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by...
🟡 CVE-2016-20070: Medium Schwachstelle
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify...
🟠 CVE-2019-25746: High Schwachstelle
WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting...