Anwendungssicherheit

🟠 CVE-2026-68074: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-68074: High Schwachstelle

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-67588: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-67588: High Schwachstelle

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-67465: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-67465: High Schwachstelle

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-66257: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-66257: High Schwachstelle

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-15918: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-15918: High Schwachstelle

VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-54418: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-54418: High Schwachstelle

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-55739: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-55739: High Schwachstelle

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/dele...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-70375: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70375: High Schwachstelle

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-70374: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70374: High Schwachstelle

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-8761: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-8761: High Schwachstelle

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is...

07. Aug. 2026 Keine Kommentare