Anwendungssicherheit
🟠 CVE-2026-44496: High Luecke in Axios Axios
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line...
🟠 CVE-2026-44488: High Luecke in Axios Axios
Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce...
🟠 CVE-2026-11774: High Schwachstelle
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t)...
🟠 CVE-2026-53777: High Schwachstelle
Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any...
🟠 CVE-2026-41700: High Luecke in Vmware Spring_For_Graphql
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick...
🟠 CVE-2026-41699: High Luecke in Vmware Spring_For_Graphql
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious...
🟠 CVE-2026-49982: High Schwachstelle
tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects...
🟠 CVE-2026-40998: High Schwachstelle
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's...
🟠 CVE-2026-40994: High Schwachstelle
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData....
🟠 CVE-2026-40999: High Schwachstelle
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances...