Doorzoek en filter alle geregistreerde cyberdreigingen voor gemeenten.
57 dreigingen gevonden · pagina 4 van 5
langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs
CyberChef: Prototype pollution in Series Chart operation
CVE-2026-57439
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
CVE-2026-61604
Language Servers for AWS vulnerable to arbitrary file write
CVE-2026-12958
Language Servers for AWS Vulnerable to Arbitrary Code Execution
CVE-2026-12957
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
CVE-2026-63498
ZITADEL: MFA bypass via session reuse in Login V2
CVE-2026-85056
ZITADEL: Actions V1 sandbox escape: host file read via require()
CVE-2026-85057
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
CVE-2026-62368
Dozzle label filters do not restrict container event and statistics streams
CVE-2026-62286
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com