Anwendungssicherheit

🟠 CVE-2026-80354: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-80354: High Schwachstelle

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant...

12. Sep. 2026 Keine Kommentare
🟠 CVE-2026-64838: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-64838: High Schwachstelle

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users...

12. Sep. 2026 Keine Kommentare
🟠 CVE-2026-88862: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-88862: High Schwachstelle

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware....

12. Sep. 2026 Keine Kommentare
🟠 CVE-2026-64837: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-64837: High Schwachstelle

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS...

12. Sep. 2026 Keine Kommentare
🔴 CVE-2026-44950: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-44950: Critical Schwachstelle

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that...

12. Sep. 2026 Keine Kommentare
🔴 CVE-2026-78361: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-78361: Critical Schwachstelle

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of...

12. Sep. 2026 Keine Kommentare
🔴 CVE-2026-84939: Critical Luecke in Apache Freemarker ANWENDUNGSSICHERHEIT

🔴 CVE-2026-84939: Critical Luecke in Apache Freemarker

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to...

12. Sep. 2026 Keine Kommentare
🔴 CVE-2026-8323: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-8323: Critical Schwachstelle

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the...

12. Sep. 2026 Keine Kommentare
🔴 CVE-2026-9163: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-9163: Critical Schwachstelle

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System...

12. Sep. 2026 Keine Kommentare
🔴 CVE-2026-88278: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-88278: Critical Schwachstelle

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be...

12. Sep. 2026 Keine Kommentare