Anwendungssicherheit

🟠 CVE-2026-16252: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-16252: High Schwachstelle

A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-16247: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-16247: High Schwachstelle

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData%...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-16246: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-16246: High Schwachstelle

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-64622: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-64622: High Schwachstelle

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-63760: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-63760: High Schwachstelle

SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-63747: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-63747: High Schwachstelle

SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-54910: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-54910: High Schwachstelle

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-62418: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-62418: High Schwachstelle

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope:...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-13142: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-13142: High Schwachstelle

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a...

22. Juli 2026 Keine Kommentare
🟠 CVE-2026-13577: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-13577: High Schwachstelle

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to...

22. Juli 2026 Keine Kommentare