Anwendungssicherheit

🟠 CVE-2026-48236: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48236: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, ticketsuser,...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48234: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48234: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort and dir GET parameters are...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48233: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48233: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET parameter is concatenated into...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48232: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48232: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GET parameter is concatenated into...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48231: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48231: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters (tablename, indexname, sortby)...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48242: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48242: High Schwachstelle

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials...

23. Mai 2026 Keine Kommentare
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV ANWENDUNGSSICHERHEIT

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48241: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48241: High Schwachstelle

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to...

23. Mai 2026 Keine Kommentare
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root ANWENDUNGSSICHERHEIT

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked...

23. Mai 2026 Keine Kommentare
🟠 CVE-2026-48235: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-48235: High Schwachstelle

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude, and timestamp...

23. Mai 2026 Keine Kommentare