Live Threat Intelligence Feed Kategorie #10
Sicherheitslücken (CVE)

Sicherheitslücken (CVE)

ENISA EUVD & CISA KEV Vulnerability Database. Dokumentierte CVEs, Severity Heatmaps, NIS-2 Relevant Advisories und Vendor Patch Bulletins.

Windows Tipps & SecurityBest AI browsers for Windows 11(19.09.2026 um 00:38 Uhr)
Sichere ProgrammierungAgent stdout Is Not Your Test Plan(19.09.2026 um 02:03 Uhr)
Sichere ProgrammierungThumbs Up with a Twist - Correction and Smoothing of Grip(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungAuth Provider Event History vs. Your Audit Log: SOC 2 Evidence(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungThe Deadline Used time.time(). Then the Laptop Slept.(19.09.2026 um 02:04 Uhr)
Windows Tipps & SecurityBest AI browsers for Windows 11(19.09.2026 um 00:38 Uhr)
Sichere ProgrammierungAgent stdout Is Not Your Test Plan(19.09.2026 um 02:03 Uhr)
Sichere ProgrammierungThumbs Up with a Twist - Correction and Smoothing of Grip(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungAuth Provider Event History vs. Your Audit Log: SOC 2 Evidence(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungThe Deadline Used time.time(). Then the Laptop Slept.(19.09.2026 um 02:04 Uhr)
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence

Sicherheitslücken (CVE)

Sicherheitslücken (CVE) DEV Community
WSO2 CVE-2026-5430: Authentication Bypass in API Management Infrastructure via JWT with Unsupported Algorithm

1. Basic Information Original Title: Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Source: SecurityWeek Published Date: September 16…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
The Events Calendar: Two Unauthenticated RCE Chains via Unapproved Comments

1. Basic Information Original Title: Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) «Hacker News» 🗞️🦾 IT BOLTWI…
Mit CVE-Validierung schneller reagieren: Wie Angriffsreife gemessen wird

LONDON (IT BOLTWISE) – Neue CVEs kommen oft schneller als die üblichen Validierungszyklen im Security-Betrieb.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs

Two ordinary agent-framework conveniences, a filterable vector search and a file-download tool, turned into remote code execution once an LLM's…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Missing Access Control in Rank Math SEO Schema Shortcode and Object Permission Checks

The schema snippet shortcode returned schema data for any post ID without checking whether the requester was allowed to view that post, disclosing…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Web Application Firewall Rule Bypass in Jetpack WAF Runtime

Jetpack's bundled Web Application Firewall did not clear its cached MATCHED_VAR/MATCHED_VARS metadata between rule evaluations, so a rule referencing…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Cross-Site Request Forgery in WooCommerce Product and Term Ordering

The WooCommerce admin AJAX handlers WC_AJAX::product_ordering() and WC_AJAX::term_ordering() changed the menu_order of products and taxonomy terms…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Unescaped Output in Enable Media Replace Error View

Enable Media Replace up to and including 4.1.8 printed the error message and error description into the error view without HTML escaping.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in WooCommerce Order Notes REST API v4

WooCommerce before 10.7.0 passed the REST API v4 order-note request field directly to add_order_note() without sanitization, storing the value…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Unescaped Attribute Output in Enable Media Replace Upsell View

Enable Media Replace up to and including 4.1.8 printed CSS class values into HTML attributes in the upsell view without escaping.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in Essential Addons for Elementor Pricing Table Title Tag

Essential Addons for Elementor before 6.6.10 does not validate the HTML tag name configured for the Pricing Table widget title before rendering it.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in TablePress Shortcode Debug Output

TablePress up to and including 3.2 renders shortcode render options through var_export() without escaping when the shortcode_debug attribute is set.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Missing Authorization and Stored XSS in MonsterInsights Admin Endpoints and Popular Posts Widget

This definition covers two distinct issue classes in MonsterInsights.1) Stored Cross-Site Scripting in the Popular Posts widget. In 8.1.0-8.13.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in Enable Media Replace Location Directory Field

Enable Media Replace up to and including 4.1.8 renders the 'location_dir' value into an HTML attribute on the media replace screen without escaping…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Cache Poisoning and Stored Cross-Site Scripting in WP Supercache

WP Super Cache stores the CDN URL and CNAME settings unescaped and substitutes them into the src/href attribute of every rewritten asset URL, so a…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Incorrect Permissions in Ultimate Addons for Elementor Notice Dismissal

The bundled Astra Notices library passed the client-supplied notice identifier straight to update_user_meta() and set_transient() when an admin…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in Essential Addons for Elementor Advanced Tabs

The Advanced Tabs widget rendered repeater tab titles through a custom HTML allowlist that permitted , and inline style attributes, and additionally…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Authenticated (Contributor+) Stored Cross-Site Scripting via CF7 and Gravity Forms Styler Form ID

The Contact Form 7 and Gravity Forms styler blocks used the formId block attribute directly, concatenating it into a shortcode string that is then…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Improper Authorization in Magento Admin Shipment Controllers

The admin controllers that start, create and save an order shipment checked the broad 'Magento_Sales::shipment' ACL resource instead of the narrower…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
SQL Injection in All-in-One WP Migration and Backup Archive Restore

A flaw in the find-and-replace routine used when restoring a backup archive lets a crafted database value ending in an escaped backslash break out of…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Login and Register Security Guard Bypass in Essential Addons for Elementor

Every security guard in the Login/Register widget — nonce verification, reCAPTCHA, Cloudflare Turnstile and the OTP gate — only terminated the…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
PHP Object Injection in Rank Math SEO Schema REST Endpoint

The schema REST handler unserialized metadata that WordPress core had already unserialized, so a stored value whose first-pass result is itself a…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
SQL Injection in Drupal PostgreSQL Entity Query Condition

On PostgreSQL-backed Drupal sites, the case-insensitive entity query array condition concatenated the caller-supplied operator straight into a raw…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in Starter Templates SVG Upload

Starter Templates through 4.2.1 registers an upload_mimes filter that permits SVG uploads, but never sanitizes the uploaded SVG contents.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Information Disclosure in Elementor Website Builder REST Post Query

The Elementor REST post-query endpoint built its WP_Query arguments with post_status 'any' for authenticated requests without restricting results to…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Privilege Escalation in Rank Math SEO Automated SEO Fix

Rank Math SEO before 1.0.277 gated the automated 'fix site SEO' action only on the plugin's own rank_math_site_analysis capability, which…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) SecurityWeek
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

🛡️ Security Fix
vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) WinFuture News
Zero-Day wird ausgenutzt: Google rät Pixel-Usern dringend zum Update

Google hat eine als Zero-Day eingestufte Sicherheitslücke in Pixel-Smartphones geschlossen, die nach Angaben des Unternehmens bereits für einige…

🛡️ Security Fix
vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Latest from TechRadar
Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up

Cisco fixed critical ISE flaw (CVE‑2026‑76460) allowing unauthenticated API authentication bypassActively exploited; no workarounds exist—patching is…

🛡️ Security Fix
vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE)
Security Weekly - A CRA Resource: AI Is Outrunning Your Patch Program

AI is accelerating vulnerability discovery, while patching still depends on people, money, and…

YouTube Security Videos 95%
vor 1 Tag 4 Views
0
Weiterlesen ↗
Sicherheitslücken (CVE) Check Point Blog
AI Models Broke Their Own Containment: Key Findings from the July-August 2026 AI Threat Landscape

Between mid-July and early August 2026, models being evaluated internally by OpenAI, Anthropic, and Meta reached real production systems outside…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) theregister.com
Cisco drops another exploited zero-day, this time a perfect 10

Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack.

🛡️ Security Fix
vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) The Hacker News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) SecurityWeek
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.  

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) All CISA Advisories
Bransys ELD

View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) All CISA Advisories
Schneider Electric Modicon M340 Controller and Communication Modules

View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Weitere 36 Beiträge laden
Seite 15 von 1.000 • Gesamt: 436.602 Artikel
1 Quelle 15
Best AI browsers for Windows 11
1 Quelle 26
Agent stdout Is Not Your Test Plan
1 Quelle 26
VAST Extension type="pos" With a plcmt Child Still Validates. Stitchers Read type.
1 Quelle 26
Architectural Breakdown: A logo at 1.00:1 contrast passed every check we had
1 Quelle 26
Thumbs Up with a Twist - Correction and Smoothing of Grip
1 Quelle 26
Auth Provider Event History vs. Your Audit Log: SOC 2 Evidence
1 Quelle 26
The Deadline Used time.time(). Then the Laptop Slept.
1 Quelle 26
Kita's VLM Credit Review: How Vision Models Parse Bank Statements When Credit Bureaus Don't Exist
1 Quelle 29
Two CEL Authorization Gotchas in agentgateway: When Policy Logic Fails Open vs. Fails Closed
1 Quelle 26
One Shopify variant reported 999,999 units in stock — and it wasn't a bug
1 Quelle 26
AI agents consume all your memory in linux by default
1 Quelle 26
Screen sharing without screen mirroring: a phone-controlled TV display built on WebSockets and a QR code
Threat Hunter Status-Update verfassen
Community Stream
News-Deck Sicherheitslücken (CVE) 📖 0 · ⏭ 0 · 🗳️ 0

Karten werden geladen …

Links = lesen · Rechts = weitergehen · Hoch = vor · Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting