Endpunktsicherheit

🟠 CVE-2026-33382: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-33382: High Schwachstelle

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it....

12. Juli 2026 Keine Kommentare
🟠 CVE-2026-38059: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-38059: High Schwachstelle

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can...

12. Juli 2026 Keine Kommentare
🟠 CVE-2026-38057: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-38057: High Schwachstelle

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests...

12. Juli 2026 Keine Kommentare
🟠 CVE-2026-56305: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-56305: High Schwachstelle

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords...

12. Juli 2026 Keine Kommentare
🟠 CVE-2026-56261: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56261: High Schwachstelle

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which...

12. Juli 2026 Keine Kommentare
🔴 CVE-2026-15378: Critical Schwachstelle CLOUD-SICHERHEIT

🔴 CVE-2026-15378: Critical Schwachstelle

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request...

12. Juli 2026 Keine Kommentare
🔴 CVE-2026-56765: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-56765: Critical Schwachstelle

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling...

12. Juli 2026 Keine Kommentare
🔴 CVE-2026-55500: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-55500: Critical Schwachstelle

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all...

12. Juli 2026 Keine Kommentare
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic ENDPUNKTSICHERHEIT

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called...

11. Juli 2026 Keine Kommentare
URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Thre ENDPUNKTSICHERHEIT

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Thre

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The...

11. Juli 2026 Keine Kommentare