Anwendungssicherheit

🟠 CVE-2026-49202: High Luecke in Acer Connect_M6E_5G_Firmware ANWENDUNGSSICHERHEIT

🟠 CVE-2026-49202: High Luecke in Acer Connect_M6E_5G_Firmware

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

06. Juni 2026 Keine Kommentare
🟠 CVE-2026-49190: High Luecke in Acer Connect_M6E_5G_Firmware ANWENDUNGSSICHERHEIT

🟠 CVE-2026-49190: High Luecke in Acer Connect_M6E_5G_Firmware

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

06. Juni 2026 Keine Kommentare
🔴 CVE-2026-8037: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-8037: Critical Schwachstelle

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary...

06. Juni 2026 Keine Kommentare
🔴 CVE-2026-10840: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-10840: Critical Schwachstelle

A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue...

06. Juni 2026 Keine Kommentare
🔴 CVE-2019-25729: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2019-25729: Critical Schwachstelle

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP...

06. Juni 2026 Keine Kommentare
🔴 CVE-2019-25727: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2019-25727: Critical Schwachstelle

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files...

06. Juni 2026 Keine Kommentare
🔴 CVE-2026-4104: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-4104: Critical Schwachstelle

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL...

06. Juni 2026 Keine Kommentare
🔴 CVE-2026-49191: Critical Luecke in Acer Connect_M6E_5G_Firmware ANWENDUNGSSICHERHEIT

🔴 CVE-2026-49191: Critical Luecke in Acer Connect_M6E_5G_Firmware

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling...

06. Juni 2026 Keine Kommentare
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog ANWENDUNGSSICHERHEIT

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular...

05. Juni 2026 Keine Kommentare
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public ANWENDUNGSSICHERHEIT

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to...

05. Juni 2026 Keine Kommentare