Anwendungssicherheit
🟠 CVE-2026-75931: High Schwachstelle
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries...
🟠 CVE-2026-75899: High Schwachstelle
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the...
🟠 CVE-2026-78206: High Schwachstelle
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or...
🟠 CVE-2026-9769: High Schwachstelle
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish()...
🟠 CVE-2026-4671: High Schwachstelle
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings...
🟠 CVE-2026-59561: High Schwachstelle
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed...
🟠 CVE-2026-78209: High Schwachstelle
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV...
🟠 CVE-2026-78317: High Schwachstelle
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
🟠 CVE-2026-78316: High Schwachstelle
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
🟠 CVE-2026-78315: High Schwachstelle
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.