Anwendungssicherheit

🟠 CVE-2025-14871: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2025-14871: High Schwachstelle

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-78472: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-78472: High Schwachstelle

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27559: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27559: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27558: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27558: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execu...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27554: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27554: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27551: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27551: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27550: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27550: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27549: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27549: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27548: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27548: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27547: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27547: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials...

18. Sep. 2026 Keine Kommentare