CVE-2026-45406 - Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Through eval
Autor Jun 26, 2026 0 1
CVE-2026-45405 - Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and certs:add
Autor Jun 26, 2026 0 1
CVE-2026-28385 - SSRF via image import from URL allows internal network probing by authenticated users
Autor Jun 26, 2026 0 1
CVE-2026-54636 - Dokku: OS Command Injection via app.json managed Cron
Autor Jun 26, 2026 0 1
CVE-2026-57231 - Podman: Malformed Image can trick podman run into leaking host environment variables into the container
Autor Jun 26, 2026 0 1
CVE-2026-55686 - Podman: WORKDIR symlink traversal vulnerability
Autor Jun 26, 2026 0 1
CVE-2026-48529 - GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
Autor Jun 26, 2026 0 1
CVE-2026-47206 - Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
Autor Jun 26, 2026 0 1
CVE-2026-54341 - Dragonfly: RESTORE operations may crash the server
Autor Jun 26, 2026 0 1
CVE-2026-56876 - extract-zip unvalidated symlink path traversal
Autor Jun 26, 2026 0 1
CVE-2026-55448 - mise: Local credential_command executes untrusted config
Autor Jun 26, 2026 0 1
CVE-2026-54557 - mise HTTP backend uses raw version path for install symlink destination
Autor Jun 26, 2026 0 1
CVE-2026-55441 - mise: Arbitrary command execution via task-include files in an untrusted, config-less repository
Autor Jun 26, 2026 0 1
CVE-2026-33646 - mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
Autor Jun 26, 2026 0 1
CVE-2026-47775 - Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
Autor Jun 26, 2026 0 1
Beste Berater für den Mittelstand geehrt / Karl-Theodor zu Guttenberg gratuliert als Mentor den Preisträgern
Autor Jun 26, 2026 0 1

