Anwendungssicherheit
🟠 CVE-2026-45564: High Schwachstelle
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions////save...
🟠 CVE-2026-52758: High Luecke in Nsa Ghidra
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries...
🟠 CVE-2026-49498: High Luecke in Nsa Ghidra
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double...
🟠 CVE-2026-8071: High Schwachstelle
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used...
🔴 CVE-2026-53469: Critical Schwachstelle
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the...
🔴 CVE-2026-45550: Critical Schwachstelle
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check...
🔴 CVE-2026-53475: Critical Schwachstelle
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This...
🔴 CVE-2026-53474: Critical Schwachstelle
A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools...
🔴 CVE-2026-53471: Critical Schwachstelle
A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and...
🔴 CVE-2026-53470: Critical Schwachstelle
A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint....