Anwendungssicherheit
🟠 CVE-2026-7368: High Schwachstelle
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials...
🟠 CVE-2026-50633: High Luecke in Apache Cxf
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if...
🟠 CVE-2026-50632: High Luecke in Apache Cxf
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified,...
🟠 CVE-2026-47209: High Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores...
🟠 CVE-2026-47139: High Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the...
🟠 CVE-2026-47691: High Schwachstelle
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's...
🟠 CVE-2026-47135: High Schwachstelle
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of...
🟠 CVE-2026-45674: High Schwachstelle
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's...
🟠 CVE-2026-12059: High Schwachstelle
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass...
🔴 CVE-2026-54133: Critical Schwachstelle
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP...