Endpunktsicherheit

🟠 CVE-2026-68586: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-68586: High Schwachstelle

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the...

05. Aug. 2026 Keine Kommentare
🟠 CVE-2026-68584: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-68584: High Schwachstelle

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform...

05. Aug. 2026 Keine Kommentare
🔴 CVE-2026-69085: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-69085: Critical Schwachstelle

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly...

05. Aug. 2026 Keine Kommentare
🔴 CVE-2026-69084: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-69084: Critical Schwachstelle

SiYuan versions

05. Aug. 2026 Keine Kommentare
🔴 CVE-2026-69083: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-69083: Critical Schwachstelle

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens....

05. Aug. 2026 Keine Kommentare
New Pass-ta-key attacks let malware hijack Google-synced passkeys ENDPUNKTSICHERHEIT

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys...

04. Aug. 2026 Keine Kommentare
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts ENDPUNKTSICHERHEIT

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint,...

04. Aug. 2026 Keine Kommentare
🟡 CVE-2026-68582: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-68582: Medium Schwachstelle

Vikunja versions >= 0.24.0 and

04. Aug. 2026 Keine Kommentare
🟠 CVE-2025-71400: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2025-71400: High Schwachstelle

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated...

04. Aug. 2026 Keine Kommentare
🟠 CVE-2026-68581: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-68581: High Schwachstelle

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share...

04. Aug. 2026 Keine Kommentare