Anwendungssicherheit
🟠 CVE-2026-31984: High Luecke in Nozominetworks Guardian
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size...
🟠 CVE-2026-47831: High Schwachstelle
Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force...
🟠 CVE-2026-31985: High Schwachstelle
When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate...
🟠 CVE-2026-4256: High Schwachstelle
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP...
🟠 CVE-2026-47829: High Schwachstelle
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when...
🔴 CVE-2026-2342: Critical Schwachstelle
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS....
🔴 CVE-2026-12116: Critical Schwachstelle
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,...
🔴 CVE-2026-5955: Critical Schwachstelle
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret...
🔴 CVE-2026-15158: Critical Schwachstelle
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46...
AKTIV AUSGENUTZT – 🔴 CVE-2026-56291: Critical Luecke in Balbooa Forms
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads...