Anwendungssicherheit
🔴 CVE-2026-45721: Critical Schwachstelle
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that...
🔴 CVE-2026-35222: Critical Luecke in Joomla Joomla\!
Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
🔴 CVE-2026-35221: Critical Luecke in Joomla Joomla\!
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.
🔴 CVE-2026-48687: Critical Luecke in Pavel-Odintsov Fastnetmon
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function...
🔴 CVE-2026-45247: Critical Schwachstelle
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated...
🔴 CVE-2026-9543: Critical Schwachstelle
A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the...
ANWENDUNGSSICHERHEIT
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed...
ANWENDUNGSSICHERHEIT
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad...
🟠 CVE-2018-25368: High Schwachstelle
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an...
🟠 CVE-2026-45361: High Schwachstelle
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute...