Anwendungssicherheit

🟠 CVE-2026-70373: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70373: High Schwachstelle

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly...

06. Aug. 2026 Keine Kommentare
🟠 CVE-2026-70372: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70372: High Schwachstelle

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The...

06. Aug. 2026 Keine Kommentare
🟠 CVE-2026-70371: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70371: High Schwachstelle

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The...

06. Aug. 2026 Keine Kommentare
🟠 CVE-2026-70370: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70370: High Schwachstelle

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier...

06. Aug. 2026 Keine Kommentare
🟠 CVE-2026-70369: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-70369: High Schwachstelle

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE...

06. Aug. 2026 Keine Kommentare
🔴 CVE-2026-14804: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-14804: Critical Schwachstelle

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive...

06. Aug. 2026 Keine Kommentare
🔴 CVE-2026-18754: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-18754: Critical Schwachstelle

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure...

06. Aug. 2026 Keine Kommentare
🔴 CVE-2026-18753: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-18753: Critical Schwachstelle

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure...

06. Aug. 2026 Keine Kommentare
🔴 CVE-2026-61515: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-61515: Critical Schwachstelle

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute...

06. Aug. 2026 Keine Kommentare
🔴 CVE-2026-15721: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-15721: Critical Schwachstelle

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection....

06. Aug. 2026 Keine Kommentare