Anwendungssicherheit
🟠 CVE-2026-18361: High Schwachstelle
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore...
🟠 CVE-2026-18360: High Schwachstelle
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom...
🟠 CVE-2026-16969: High Schwachstelle
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets...
🟠 CVE-2026-44106: High Schwachstelle
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root,...
🟠 CVE-2026-44096: High Schwachstelle
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full...
🟠 CVE-2026-44093: High Schwachstelle
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as...
🟠 CVE-2026-16524: High Schwachstelle
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets...
🟠 CVE-2026-47858: High Schwachstelle
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against...
🟠 CVE-2026-47882: High Schwachstelle
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app)...
🟠 CVE-2026-44098: High Schwachstelle
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command...