DE EN FR
hlukh.ch Letzter Cron-Tick: 20. Sept. 2026, 14:42 CEST · Snapshot erstellt: 20. Sept. 2026, 01:33 CEST · Neuestes Advisory-Datum: 2026-09-18 · source: github

Sicherheitswarnungen

Kuratiert aus öffentlich verfügbaren Advisories. Fokus auf Sichtbarkeit, Einordnung und schnellen Export. Ohne Clickbait.

Neueste Warnungen
GHSA-26VP-8GXG-V4PG org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
2026‑09‑18·GHSA-26VP-8GXG-V4PGKritisch
GitHub 2026‑09‑18 Kritisch
GHSA-2VH9-42VM-XMV2 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
2026‑09‑18·GHSA-2VH9-42VM-XMV2Kritisch
GitHub 2026‑09‑18 Kritisch
GHSA-3753-M2X2-Q623 File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
2026‑09‑18·GHSA-3753-M2X2-Q623Hoch
GitHub 2026‑09‑18 Hoch
GHSA-39WR-7Q6H-CF68 LMDeploy has an SSRF bypass
2026‑09‑18·GHSA-39WR-7Q6H-CF68Hoch
GitHub 2026‑09‑18 Hoch
GHSA-3HMM-RH5Q-GWWR LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
2026‑09‑18·GHSA-3HMM-RH5Q-GWWRHoch
GitHub 2026‑09‑18 Hoch
GHSA-3JP5-3H47-28QF Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
2026‑09‑18·GHSA-3JP5-3H47-28QFMittel
GitHub 2026‑09‑18 Mittel
GHSA-3RM2-H79C-8QW6 md-editor-v3: XSS via fenced-code language rendering bypass
2026‑09‑18·GHSA-3RM2-H79C-8QW6Mittel
GitHub 2026‑09‑18 Mittel
GHSA-3W57-8XMC-8V26 AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
2026‑09‑18·GHSA-3W57-8XMC-8V26Hoch
GitHub 2026‑09‑18 Hoch
GHSA-4227-9989-JRHX Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
2026‑09‑18·GHSA-4227-9989-JRHXHoch
GitHub 2026‑09‑18 Hoch
GHSA-59XW-QV23-J3RC Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
2026‑09‑18·GHSA-59XW-QV23-J3RCMittel
GitHub 2026‑09‑18 Mittel
GHSA-5GM3-9CRP-6G3V Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
2026‑09‑18·GHSA-5GM3-9CRP-6G3VMittel
GitHub 2026‑09‑18 Mittel
GHSA-5GMM-HJFJ-8FF7 Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)
2026‑09‑18·GHSA-5GMM-HJFJ-8FF7Mittel
GitHub 2026‑09‑18 Mittel
GHSA-5P39-CFHJ-2XMP AnyIO process-pool workers can block indefinitely on undrained stderr
2026‑09‑18·GHSA-5P39-CFHJ-2XMPMittel
GitHub 2026‑09‑18 Mittel
GHSA-5P54-WHVP-X327 AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
2026‑09‑18·GHSA-5P54-WHVP-X327Mittel
GitHub 2026‑09‑18 Mittel
GHSA-7Q85-XJ36-VMFC adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
2026‑09‑18·GHSA-7Q85-XJ36-VMFCHoch
GitHub 2026‑09‑18 Hoch
GHSA-7XV3-GF2G-498H Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
2026‑09‑18·GHSA-7XV3-GF2G-498HMittel
GitHub 2026‑09‑18 Mittel
GHSA-82R6-8W77-94W6 AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
2026‑09‑18·GHSA-82R6-8W77-94W6Kritisch
GitHub 2026‑09‑18 Kritisch
GHSA-9JJC-FW8X-FMWX io.moquette:moquette-broker has a Missing Authorization issue
2026‑09‑18·GHSA-9JJC-FW8X-FMWXHoch
GitHub 2026‑09‑18 Hoch
GHSA-9RCC-PMJ8-FFHR Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
2026‑09‑18·GHSA-9RCC-PMJ8-FFHRMittel
GitHub 2026‑09‑18 Mittel
GHSA-C8W2-FGVX-VHV4 kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and…
2026‑09‑18·GHSA-C8W2-FGVX-VHV4Kritisch
GitHub 2026‑09‑18 Kritisch
Seite 1 / 408 · 8160 Warnungen