Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2026-22646
- EPSS 0.04%
- Veröffentlicht 15.01.2026 13:15:01
- Zuletzt bearbeitet 29.01.2026 16:18:21
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can ...
5.3
CVE-2026-22645
- EPSS 0.05%
- Veröffentlicht 15.01.2026 13:14:38
- Zuletzt bearbeitet 29.01.2026 17:19:57
The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.
7.5
CVE-2026-22644
- EPSS 0.08%
- Veröffentlicht 15.01.2026 13:14:13
- Zuletzt bearbeitet 29.01.2026 17:23:06
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized a...
1