Anwendungssicherheit
🟡 CVE-2026-12223: Medium Schwachstelle
A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf...
🟡 CVE-2025-15658: Medium Schwachstelle
Administrator Cross Site Scripting (XSS) in WP Emmet
🟡 CVE-2026-36521: Medium Schwachstelle
PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
🟡 CVE-2026-49294: Medium Schwachstelle
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are...
🟡 CVE-2016-20079: Medium Schwachstelle
WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files...
🟠 CVE-2026-47777: High Schwachstelle
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the...
🟠 CVE-2025-56814: High Schwachstelle
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell...
🟠 CVE-2025-68713: High Schwachstelle
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with...
🟠 CVE-2026-36670: High Schwachstelle
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows...
🔴 CVE-2026-36537: Critical Schwachstelle
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity...