Anwendungssicherheit
🟠 CVE-2026-16252: High Schwachstelle
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an...
🟠 CVE-2026-16247: High Schwachstelle
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %ProgramData%...
🟠 CVE-2026-16246: High Schwachstelle
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone...
🟠 CVE-2026-64622: High Schwachstelle
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read...
🟠 CVE-2026-63760: High Schwachstelle
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested...
🟠 CVE-2026-63747: High Schwachstelle
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is...
🟠 CVE-2026-54910: High Schwachstelle
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two...
🟠 CVE-2026-62418: High Schwachstelle
Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope:...
🟠 CVE-2026-13142: High Schwachstelle
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a...
🟠 CVE-2026-13577: High Schwachstelle
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to...