Anwendungssicherheit
ANWENDUNGSSICHERHEIT
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and...
🟡 CVE-2024-51454: Medium Schwachstelle
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1...
🟡 CVE-2024-54178: Medium Schwachstelle
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an...
🟠 CVE-2026-6858: High Schwachstelle
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to...
🟠 CVE-2026-4259: High Schwachstelle
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page,...
🟠 CVE-2026-56447: High Luecke in Misp-Project Misp
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the...
🟠 CVE-2026-56446: High Luecke in Misp-Project Misp
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because...
🟠 CVE-2026-44914: High Luecke in Apache Nifi
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions...
🟠 CVE-2026-44913: High Luecke in Apache Nifi
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting...
🟠 CVE-2026-10845: High Luecke in Ibm Websphere_Application_Server
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS...