*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler AD…
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its intern…
A coordinated cluster of 31 Russian-language Chrome extensions that present themselves as convenient “VPN for X” tools while quietly steering browser traffic through remotely controlled proxy infrastructure. Disclosed b…
A vulnerability classified as critical was found in Red Hat Enterprise Linux. Affected by this issue is the function kill of the component Namespace. Such manipulation leads to denial of service. This vulnerability is d…
A vulnerability classified as critical has been found in ljharb shell-quote up to 1.10.x. Affected by this vulnerability is the function quote. This manipulation causes os command injection. This vulnerability is regist…
A vulnerability described as problematic has been identified in Browserify pbkdf2 up to 3.1.6. Affected is the function pbkdf2Sync/pbkdf2 of the file lib/sync.js of the component JavaScript Fallback. The manipulation of…
The Pentagon has confirmed a major data breach involving a Defense Manpower Data Center (DMDC) information system, exposing sensitive personal information belonging to more than three million people. The incident affect…
A vulnerability marked as problematic has been reported in Red Hat Enterprise Linux. This impacts an unknown function of the component Flatpak. The manipulation leads to path traversal. This vulnerability is listed as C…
Signal-Konten gibts nun auch ohne Telefonnummer, vorerst für Android. Eine kleine Gebühr bremst Spammer. Neue Backups erleichtern bei iPhones den Wechsel.
A vulnerability labeled as critical has been found in LimeSurvey 7.3.0. This affects an unknown function of the component REST Survey Patching Endpoint. Executing a manipulation can lead to improper authorization. This …
A vulnerability identified as critical has been detected in Bitwarden Server 1.35.1/2026.4.0/2026.4.1. The impacted element is the function User_ReadBySsoUserOrganizationIdExternalId of the component SSO Login. Performi…
A vulnerability categorized as problematic has been discovered in htplugins HT Contact Form Plugin up to 2.10.2 on WordPress. The affected element is an unknown function. Such manipulation leads to cross site scripting.…
Apple hat wichtige Fehlerbehebungen für iOS 26, iPadOS 26 und mehrere ältere macOS-Versionen publiziert. Außerdem gibt es Bugfixes für die neuen Systeme.
A vulnerability was found in GestSup up to 3.2.61. It has been rated as problematic. Impacted is an unknown function of the component IMAP OAuth connector. This manipulation causes cross site scripting. The identificati…
A vulnerability was found in GestSup up to 3.2.61. It has been declared as problematic. This issue affects some unknown processing of the component IMAP Login Connector. The manipulation results in cross site scripting.…
A vulnerability was found in GestSup up to 3.2.61. It has been classified as problematic. This vulnerability affects unknown code of the file thread.php. The manipulation of the argument threadedit leads to improper aut…
A vulnerability was found in gz-yami mall4j up to 4.0 and classified as problematic. This affects an unknown part of the component FileController. Executing a manipulation can lead to cross site scripting. This vulnerab…
A vulnerability has been found in gz-yami mall4j up to 4.0 and classified as problematic. Affected by this issue is the function checkDelivery of the file A08_delivery_check_anonymous.py of the component DeliveryControl…
A vulnerability, which was classified as critical, was found in gz-yami mall4j up to 4.0. Affected by this vulnerability is an unknown functionality of the file A05_sys_menu_missing_perm.py of the component Session Auth…
A vulnerability, which was classified as problematic, has been found in gz-yami mall4j up to 4.0. Affected is an unknown function of the file A04_prodcomm_delete_anonymous.py of the component ProdCommController. This ma…
A vulnerability classified as critical was found in gz-yami mall4j up to 4.0. This impacts an unknown function of the component Token Refresh. The manipulation results in session expiration. This vulnerability is report…
A vulnerability classified as critical has been found in gz-yami mall4j up to 4.0. This affects the function updatePwd of the file /user/updatePwd of the component Password Reset. The manipulation of the argument Userna…
A vulnerability described as problematic has been identified in gz-yami mall4j up to 4.0. The impacted element is an unknown function of the file /user/addr/page of the component UserAddrController. Executing a manipula…
A vulnerability marked as critical has been reported in Zephyr Project Zephyr up to 4.4.1. The affected element is the function zsock_accepted_cb/zsock_received_cb/zsock_connected_cb/zsock_close_ctx of the file subsys/n…
A vulnerability labeled as problematic has been found in Zephyr Project Zephyr up to 4.4.1. Impacted is the function mcumgr_serial_extract_len of the file subsys/mgmt/mcumgr/transport/src/serial_util.c of the component …
A vulnerability identified as critical has been detected in Zephyr Project Zephyr up to 4.4.x. This issue affects the function parse_write_op of the file subsys/net/lib/lwm2m/lwm2m_message_handling.c of the component Lw…
A vulnerability categorized as problematic has been discovered in Google Angular. This vulnerability affects the function forcequirks of the file lib/HTMLParser.js of the component HTML Parser. The manipulation results …
A vulnerability was found in Nginx Proxy Manager up to 2.16.0. It has been rated as critical. This affects an unknown part. The manipulation of the argument advanced_config leads to improper privilege management. This v…
A vulnerability was found in cle-b httpdbg up to 2.2.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Web Interface. Executing a manipulation can lead to cros…
A vulnerability was found in Nginx Proxy Manager up to 2.16.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper restriction…
A vulnerability was found in amir20 Dozzle up to 11.1.1 and classified as problematic. Affected is an unknown function of the component Log Download Endpoint. Such manipulation leads to path traversal. This vulnerabilit…
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploit…
A vulnerability has been found in ZoneMinder up to 1.37.x and classified as problematic. This impacts the function output_file of the component Files View. This manipulation of the argument path causes path traversal. T…
A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.8.3. This affects an unknown function of the component getCurrentAttrViewImages. The manipulation results in improper authori…
A vulnerability, which was classified as problematic, has been found in ZoneMinder up to 1.38.3. The impacted element is the function index of the component FramesController. The manipulation leads to improper access co…
A vulnerability classified as critical was found in Siyuan Note SiYuan up to 3.8.3. The affected element is an unknown function of the file siyuan.db of the component Block Query Embed. Executing a manipulation can lead…
A vulnerability classified as problematic has been found in Cotonti up to 1.0.0. Impacted is an unknown function of the file admin.users.php. Performing a manipulation results in cross-site request forgery. This vulnera…
A vulnerability described as critical has been identified in ZoneMinder. This issue affects the function RemoteCameraHttp::GetResponse of the component HTTP Response Parser. Such manipulation leads to buffer overflow. T…
A vulnerability marked as critical has been reported in Open Source Robotics Robot Operating System. This vulnerability affects the function eval of the component Hz Verb. This manipulation of the argument filter causes…
A vulnerability labeled as problematic has been found in NestJS Nest up to 11.2.3/12.0.1. This affects the function ServerTCP#handleMessage/ServerRMQ#handleMessage of the component TCP Transport/RabbitMQ Transport. The …
A vulnerability identified as problematic has been detected in Laravel up to 12.68.x/13.29.x. Affected by this issue is some unknown functionality of the component Exception Debug Pages. The manipulation leads to cross …
A vulnerability categorized as problematic has been discovered in Red Hat Enterprise Linux. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to permission issues. This vulner…
A vulnerability was found in Red Hat Enterprise Linux. It has been rated as critical. Affected is an unknown function of the component System Helper. Performing a manipulation results in permission issues. This vulnerab…
A vulnerability was found in Facebook Proxygen 2024.10.28.00. It has been declared as critical. This impacts the function WebTransportImpl::terminateSessionStreams of the component WebTransport Session Streams. Such man…
A vulnerability was found in Red Hat Enterprise Linux. It has been classified as problematic. This affects an unknown function of the file .desktop of the component Vendor Extension Keys. This manipulation causes denial…
A vulnerability was found in Facebook Proxygen 2026.07.20.00 and classified as critical. The impacted element is the function HTTPTransaction::onWebTransportUniStream/HTTPTransaction::onWebTransportBidiStream of the com…
A vulnerability has been found in Facebook Proxygen 2026.07.20.00 and classified as critical. The affected element is the function QuicWtSession::closeSession of the component Quic Session. The manipulation leads to use…
A vulnerability, which was classified as problematic, was found in juliangruber brace-expansion up to 1.1.18/2.1.4/3.0.6/5.0.9. Impacted is the function parseCommaParts of the component Comma Parts. Executing a manipula…
A vulnerability, which was classified as critical, has been found in Wind River Systems VxWorks 25.03. This issue affects some unknown processing of the component Process Management Subsystem. Performing a manipulation …
A vulnerability classified as problematic was found in jpadilla PyJWT up to 2.13.x. This vulnerability affects the function RSAAlgorithm.from_jwk of the file jwt/api_jwk.py of the component PyJWKSet. Such manipulation l…
A vulnerability classified as critical has been found in jpadilla PyJWT up to 2.13.x. This affects the function HMACAlgorithm.prepare_key of the component HMAC Key Guard. This manipulation causes improper verification o…
A vulnerability described as problematic has been identified in jpadilla PyJWT up to 2.13.x. Affected by this issue is the function PyJWS._load of the file jwt/api_jws.py of the component JWS Loading. The manipulation r…
A vulnerability marked as critical has been reported in jpadilla PyJWT up to 2.13.x. Affected by this vulnerability is the function HMACAlgorithm.prepare_key of the file jwt/algorithms.py of the component raw-JWK detect…
A vulnerability labeled as critical has been found in jpadilla PyJWT up to 2.14.x. Affected is the function OKPAlgorithm.from_jwk of the file jwt/algorithms.py of the component OKPAlgorithm. Executing a manipulation can…