Endpunktsicherheit
🟠 CVE-2026-33382: High Schwachstelle
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it....
🟠 CVE-2026-38059: High Schwachstelle
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can...
🟠 CVE-2026-38057: High Schwachstelle
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests...
🟠 CVE-2026-56305: High Schwachstelle
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords...
🟠 CVE-2026-56261: High Schwachstelle
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which...
🔴 CVE-2026-15378: Critical Schwachstelle
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request...
🔴 CVE-2026-56765: Critical Schwachstelle
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling...
🔴 CVE-2026-55500: Critical Schwachstelle
9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all...
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called...
ENDPUNKTSICHERHEIT
URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Thre
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The...