Anwendungssicherheit
🟠 CVE-2026-49202: High Luecke in Acer Connect_M6E_5G_Firmware
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
🟠 CVE-2026-49190: High Luecke in Acer Connect_M6E_5G_Firmware
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
🔴 CVE-2026-8037: Critical Schwachstelle
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary...
🔴 CVE-2026-10840: Critical Schwachstelle
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue...
🔴 CVE-2019-25729: Critical Schwachstelle
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP...
🔴 CVE-2019-25727: Critical Schwachstelle
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files...
🔴 CVE-2026-4104: Critical Schwachstelle
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL...
🔴 CVE-2026-49191: Critical Luecke in Acer Connect_M6E_5G_Firmware
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling...
ANWENDUNGSSICHERHEIT
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular...
ANWENDUNGSSICHERHEIT
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to...