Anwendungssicherheit
🔴 CVE-2026-33000: Critical Schwachstelle
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in...
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker...
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex...
🟠 CVE-2026-9157: High Schwachstelle
Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This...
🟠 CVE-2026-39461: High Luecke in Freebsd Freebsd
libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to...
🟠 CVE-2026-44047: High Schwachstelle
An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to...
🔴 CVE-2026-5433: Critical Schwachstelle
Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command...
🔴 CVE-2026-39531: Critical Schwachstelle
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit...
🔴 CVE-2026-48207: Critical Schwachstelle
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and...
🔴 CVE-2025-71211: Critical Schwachstelle
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and...