Endpunktsicherheit

🟠 CVE-2026-12228: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-12228: High Schwachstelle

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled...

20. Juli 2026 Keine Kommentare
🟠 CVE-2026-15631: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-15631: High Schwachstelle

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the...

20. Juli 2026 Keine Kommentare
🟠 CVE-2026-11826: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-11826: High Schwachstelle

OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a...

20. Juli 2026 Keine Kommentare
🔴 CVE-2026-16117: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-16117: Critical Schwachstelle

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded....

20. Juli 2026 Keine Kommentare
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage ENDPUNKTSICHERHEIT

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting...

19. Juli 2026 Keine Kommentare
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man ENDPUNKTSICHERHEIT

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition...

19. Juli 2026 Keine Kommentare
🟡 CVE-2026-63096: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-63096: Medium Schwachstelle

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound...

19. Juli 2026 Keine Kommentare
🟡 CVE-2026-63099: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-63099: Medium Schwachstelle

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to...

19. Juli 2026 Keine Kommentare
🟡 CVE-2026-63095: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-63095: Medium Schwachstelle

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to...

19. Juli 2026 Keine Kommentare
🟠 CVE-2026-63094: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-63094: High Schwachstelle

SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session...

19. Juli 2026 Keine Kommentare