Anwendungssicherheit
ANWENDUNGSSICHERHEIT
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server...
🟠 CVE-2026-54563: High Schwachstelle
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured...
🟠 CVE-2026-61427: High Schwachstelle
PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and...
🟠 CVE-2026-56398: High Luecke in Openwebui Open_Webui
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL...
🟠 CVE-2026-59762: High Schwachstelle
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. ...
🟠 CVE-2026-60085: High Schwachstelle
PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess,...
🟠 CVE-2026-54560: High Schwachstelle
Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without...
🟠 CVE-2026-61835: High Schwachstelle
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on...
🟠 CVE-2026-61644: High Schwachstelle
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and...
🟠 CVE-2026-14251: High Schwachstelle
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole...