Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.1
CVE-2026-63099
- EPSS 0.21%
- Veröffentlicht 17.07.2026 15:39:44
- Zuletzt bearbeitet 17.07.2026 18:04:04
TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. A...
6.9
CVE-2026-63098
- EPSS 0.32%
- Veröffentlicht 17.07.2026 15:38:08
- Zuletzt bearbeitet 30.07.2026 14:25:41
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication en...
1