Anwendungssicherheit
🟡 CVE-2026-74866: Medium Schwachstelle
@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return...
🟡 CVE-2026-59296: Medium Schwachstelle
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous...
🟡 CVE-2026-59318: Medium Schwachstelle
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is...
🟡 CVE-2026-77769: Medium Schwachstelle
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc...
🟡 CVE-2026-77768: Medium Schwachstelle
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evalua...
🟡 CVE-2026-77763: Medium Schwachstelle
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target...
🟡 CVE-2026-16959: Medium Schwachstelle
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL...
🟡 CVE-2026-14601: Medium Schwachstelle
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in...
🟠 CVE-2026-16576: High Schwachstelle
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some...
🟠 CVE-2026-59279: High Schwachstelle
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions...