Anwendungssicherheit
🟠 CVE-2026-15560: High Schwachstelle
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an...
🟠 CVE-2026-15556: High Schwachstelle
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check...
🟠 CVE-2026-72562: High Schwachstelle
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the...
🟠 CVE-2026-72558: High Schwachstelle
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search...
🟠 CVE-2026-72557: High Schwachstelle
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP...
🟠 CVE-2026-72538: High Schwachstelle
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone...
🟠 CVE-2026-72537: High Schwachstelle
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to...
🟠 CVE-2026-72534: High Schwachstelle
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to...
🟠 CVE-2026-15555: High Schwachstelle
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling...
🔴 CVE-2026-13716: Critical Schwachstelle
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files...