Anwendungssicherheit
🟠 CVE-2026-82478: High Schwachstelle
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServer...
🟠 CVE-2026-75807: High Schwachstelle
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to,...
🟠 CVE-2026-82472: High Schwachstelle
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated...
🟠 CVE-2026-82474: High Schwachstelle
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted...
🟠 CVE-2026-82463: High Schwachstelle
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate...
🟠 CVE-2026-82461: High Schwachstelle
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles....
🟠 CVE-2026-16061: High Schwachstelle
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one...
🟠 CVE-2026-82466: High Schwachstelle
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any...
🟠 CVE-2026-82450: High Schwachstelle
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import...
🔴 CVE-2026-82454: Critical Schwachstelle
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The...