*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
A vulnerability has been found in jpadilla PyJWT up to 2.14.x and classified as problematic. Affected by this vulnerability is the function PyJWKClient.get_signing_key_from_jwt of the file jwt/api_jwt.py of the componen…
A vulnerability, which was classified as problematic, was found in rhukster dom-sanitizer up to 1.0.14. Affected is the function isDangerousUrl of the file Sanitizer.php of the component URL Sanitization. The manipulati…
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
A vulnerability, which was classified as critical, has been found in Brainstorm Force ConvertPlus Plugin up to 3.6.3 on WordPress. This impacts the function maybe_unserialize of the component cp_display_preview_modal. T…
A vulnerability classified as problematic was found in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scr…
A vulnerability classified as problematic has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The impacted element is an unknown function of the file frontend/update-account.php of th…
A vulnerability described as problematic has been identified in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipul…
A vulnerability marked as problematic has been reported in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop …
A vulnerability labeled as very critical has been found in Wind River Systems VxWorks 25.03. This issue affects some unknown processing of the component Memory Management Subsystem. The manipulation results in memory co…
A vulnerability identified as problematic has been detected in grpc grpc-js up to 1.13.5/1.14.4. This vulnerability affects unknown code. The manipulation leads to information disclosure. This vulnerability is documente…
A vulnerability categorized as critical has been discovered in Authlib up to 1.7.2. This affects the function JsonWebSignature.deserialize_json of the component Signature Verification. Executing a manipulation can lead …
A vulnerability was found in grpc grpc-js up to 1.13.0/1.14.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component RBAC. Performing a manipulation results in improper aut…
A vulnerability was found in BerriAI LiteLLM up to 1.102.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper authorization. This vulnerabi…
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]
A vulnerability was found in Apple iOS, iPadOS and macOS. It has been classified as critical. Affected is an unknown function. This manipulation causes out-of-bounds write. This vulnerability is tracked as CVE-2026-8695…
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers t…
A vulnerability was found in Ordasoft Vehicle Manager Extension up to 6.5.7 and classified as problematic. This impacts an unknown function. The manipulation results in cross site scripting. This vulnerability is identi…
A vulnerability has been found in Ordasoft Real Estate Manager Extension up to 1.0.0/6.7.8 and classified as problematic. This affects an unknown function. The manipulation leads to cross site scripting. This vulnerabil…
A vulnerability, which was classified as problematic, was found in Red Hat Enterprise Linux. The impacted element is an unknown function. Executing a manipulation can lead to path traversal. The identification of this v…
A vulnerability, which was classified as problematic, has been found in Wind River VxWorks up to 26.08. The affected element is an unknown function of the component IPNET subsystem. Performing a manipulation results in …
A vulnerability classified as critical was found in Meta Platforms moxygen. Impacted is the function MoQSession::dataStreamReadLoop of the component WebTransport. Such manipulation leads to use after free. This vulnerab…
A vulnerability classified as problematic has been found in Ordasoft Book Library Extension up to 6.4.5. This issue affects some unknown processing of the file site/views/view_book/tmpl/default.php of the component Book…
A vulnerability described as critical has been identified in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in m…
A vulnerability marked as critical has been reported in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentic…
A vulnerability labeled as critical has been found in ordasoft Book Library Extension 1.0.0-6.4.6. Affected by this issue is the function quote of the component Blacklist. Executing a manipulation can lead to sql inject…
A vulnerability identified as critical has been detected in ordasoft Vehicle Manager Extension up to 6.5.7. Affected by this vulnerability is an unknown functionality of the file site/vehiclemanager.php of the component…
A vulnerability categorized as critical has been discovered in Google Chrome. Affected is an unknown function of the component Codecs. Such manipulation leads to out-of-bounds read. This vulnerability is documented as C…
A vulnerability was found in Ordasoft Real Estate Manager Extension up to 6.7.8. It has been rated as critical. This impacts an unknown function of the file site/realestatemanager.php of the component Order By Clause. T…
A vulnerability was found in FastAdmin 1.6.1.20250430/1.6.5.20260602. It has been declared as critical. This affects an unknown function of the file application/database.php of the component Database Management. The man…
A vulnerability was found in GCC. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-102010. The attack…
A vulnerability was found in MODSetter SurfSense up to 2.0.3 and classified as critical. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component …
A vulnerability has been found in MODSetter SurfSense up to 0.0.36 and classified as problematic. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Expor…
A vulnerability, which was classified as critical, was found in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connect…
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
A vulnerability, which was classified as problematic, has been found in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Resto…
A vulnerability classified as very critical was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of th…
Deutschland stellt den Behördenfunk auf 5G um. Um die digitale Souveränität zu wahren, setzt der Bund auf offene Standards und schließt Risiko-Anbieter aus.
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted i…
A vulnerability classified as critical has been found in stringer-rss Stringer. Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery. This vulnerability is uniquely…
A vulnerability described as critical has been identified in dannymcc Bluehood up to 0.7.0. Affected by this vulnerability is an unknown functionality of the component API Handler. Executing a manipulation can lead to i…
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide c…
A vulnerability marked as critical has been reported in beaugunderson ip-address up to 10.5.0. Affected is the function isLinkLocal of the file src/ipv6.ts of the component Address6. Performing a manipulation results in…
A vulnerability labeled as problematic has been found in ooples token-optimizer-mcp up to 5.0.x. This impacts the function path.join of the file /api/session-summary of the component Dashboard HTTP Server. Such manipula…
A vulnerability identified as problematic has been detected in ooples token-optimizer-mcp up to 5.0.x. This affects an unknown function of the component smart_user. This manipulation of the argument Username causes os c…
A vulnerability categorized as critical has been discovered in Axios up to 1.19.x. The impacted element is an unknown function of the component fetch adapter. The manipulation results in improperly controlled modificati…
A vulnerability was found in beaugunderson ip-address up to 10.5.0. It has been rated as critical. The affected element is the function isPrivate of the file src/ipv6.ts of the component Address6. The manipulation leads…
A vulnerability was found in Axios up to 1.19.0. It has been declared as problematic. Impacted is an unknown function of the component Fetch Adapter. Executing a manipulation can lead to open redirect. This vulnerabilit…
A vulnerability was found in FreePBX up to 16.0.38/17.0.6 and classified as critical. This vulnerability affects unknown code of the component User Control Panel. Such manipulation leads to os command injection. This vu…
A vulnerability was found in FreePBX up to 17.0.8. It has been classified as critical. This issue affects some unknown processing of the component Documentation Generator. Performing a manipulation of the argument host …
A vulnerability has been found in beaugunderson ip-address up to 10.7.0 and classified as critical. This affects the function isInSubnet of the file src/common.ts. This manipulation causes improper input validation. Thi…
A vulnerability, which was classified as problematic, was found in FreePBX up to 16.0.3/17.0.5. Affected by this issue is some unknown functionality of the file musiconhold_additional.conf of the component Music on Hold…
A vulnerability, which was classified as problematic, has been found in beaugunderson ip-address up to 10.7.0. Affected by this vulnerability is the function Address6.isValid of the file src/ipv6.ts of the component IPv…
A vulnerability classified as critical was found in Axios. Affected is an unknown function. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The identification of t…
A vulnerability classified as problematic has been found in FreePBX up to 16.0.39/17.0.6. This impacts the function save_options of the component Superfecta Module. Performing a manipulation results in improper input va…
A vulnerability described as very critical has been identified in FreePBX up to 16.0.71/17.0.6. This affects an unknown function of the component Backup Module. Such manipulation leads to code injection. This vulnerabil…
A vulnerability marked as critical has been reported in FreePBX up to 16.0.9/17.0.4. The impacted element is an unknown function of the component Sound Language Upload/Conversion. This manipulation causes path traversal…