Anwendungssicherheit

🟠 CVE-2026-61433: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-61433: High Schwachstelle

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-42533: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-42533: High Schwachstelle

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-61873: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-61873: High Schwachstelle

Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-57821: High Luecke in Apache Fineract ANWENDUNGSSICHERHEIT

🟠 CVE-2026-57821: High Luecke in Apache Fineract

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0....

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-56287: High Luecke in Apache Fineract ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56287: High Luecke in Apache Fineract

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-12281: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-12281: High Schwachstelle

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-55723: High Luecke in F5 Nginx_Ingress_Controller ANWENDUNGSSICHERHEIT

🟠 CVE-2026-55723: High Luecke in F5 Nginx_Ingress_Controller

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-56400: High Luecke in Openwebui Open_Webui ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56400: High Luecke in Openwebui Open_Webui

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-61430: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-61430: High Schwachstelle

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but...

17. Juli 2026 Keine Kommentare
🟠 CVE-2026-61836: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-61836: High Schwachstelle

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is...

17. Juli 2026 Keine Kommentare