Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| GHSA-w867-jm58-p9pv Source | n8n | Self-hosted apps | Medium | 24.06.2026 |
| CVE-2026-7086 Source | Docker Engine | OS & platform | Medium | 24.06.2026 |
| CVE-2026-41278 Source | Docker Engine | OS & platform | High | 24.06.2026 |
| CVE-2026-40878 Source | Docker Engine | OS & platform | Low | 24.06.2026 |
| CVE-2026-40875 Source | Docker Engine | OS & platform | High | 24.06.2026 |
| CVE-2026-40874 Source | Docker Engine | OS & platform | Medium | 24.06.2026 |
| CVE-2026-41862 Source | Redis | OS & platform | High | 24.06.2026 |
| CVE-2026-28381 Source | Grafana | OS & platform | Critical | 24.06.2026 |
| CVE-2026-6575 Source affects: ≥18.0 <18.4 |
PostgreSQL | OS & platform | Medium | 24.06.2026 |
| CVE-2026-6479 Source affects: <14.23; ≥15.0 <15.18; ≥16.0 <16.14; ≥17.0 <17.10; ≥18.0 <18.4 |
PostgreSQL | OS & platform | High | 24.06.2026 |
| CVE-2026-54318 Source affects: <2026.5.3 |
Home Assistant | Self-hosted apps | High | 24.06.2026 |
| CVE-2026-54317 Source affects: <2026.6.0 |
Home Assistant | Self-hosted apps | High | 24.06.2026 |
| CVE-2026-55667 Source | File Browser | Self-hosted apps | High | 23.06.2026 |
| CVE-2026-22874 Source | Gitea | Self-hosted apps | Critical | 21.06.2026 |
| CVE-2026-20896 Source | Gitea | Self-hosted apps | Critical | 21.06.2026 |
| CVE-2026-28740 Source | Gitea | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-27775 Source | Gitea | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-20779 Source | Gitea | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-25038 Source | Gitea | Self-hosted apps | Medium | 21.06.2026 |
| CVE-2026-24451 Source | Gitea | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-27761 Source | Gitea | Self-hosted apps | Medium | 21.06.2026 |
| CVE-2026-59966 Source | Tandoor Recipes | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-59963 Source | Tandoor Recipes | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-59962 Source | Tandoor Recipes | Self-hosted apps | Medium | 21.06.2026 |
| CVE-2026-59970 Source | Tandoor Recipes | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-59967 Source | Tandoor Recipes | Self-hosted apps | Medium | 21.06.2026 |
| GHSA-rjvx-x5h2-6px5 Source | Gitea | Self-hosted apps | High | 21.06.2026 |
| CVE-2026-27878 Source | Grafana | OS & platform | Medium | 20.06.2026 |
| CVE-2026-47847 Source | MariaDB | OS & platform | Medium | 20.06.2026 |
| CVE-2026-54762 Source | Traefik | OS & platform | Medium | 19.06.2026 |
| CVE-2026-47262 Source | containerd | OS & platform | Medium | 19.06.2026 |
| CVE-2026-53489 Source | containerd | OS & platform | High | 19.06.2026 |
| CVE-2026-50195 Source | containerd | OS & platform | Critical | 19.06.2026 |
| CVE-2026-53488 Source | containerd | OS & platform | Critical | 19.06.2026 |
| CVE-2026-53492 Source | containerd | OS & platform | Critical | 19.06.2026 |
| GHSA-q7j3-v8qv-22vq Source | OpenTofu | OS & platform | High | 18.06.2026 |
| CVE-2026-54317 Source | Home Assistant Core | Self-hosted apps | High | 18.06.2026 |
| CVE-2026-54318 Source | Home Assistant Core | Self-hosted apps | High | 17.06.2026 |
| CVE-2026-25779 Source A vulnerability in Gitea allows attackers to redirect users to external websites after login by using special characters in the redirect_to parameter, which can lead to phishing attacks. |
Gitea | Self-hosted apps | Medium | 14.06.2026 |
| CVE-2026-22555 Source A security vulnerability in Gitea allows read-only organization members to create repositories via API despite lacking permission, enabling them to steal all organization CI/CD secrets through malicious workflow files. |
Gitea | Self-hosted apps | High | 14.06.2026 |
| CVE-2026-28737 Source Gitea's 3D file viewer has a security vulnerability that allows attackers to inject malicious JavaScript code through crafted .gltf files, which then executes for any user who views the file. |
Gitea | Self-hosted apps | High | 14.06.2026 |
| CVE-2026-24791 Source A vulnerability in Gitea allows attackers with 'public-only' API tokens to access and modify private user data, even though these tokens should only be able to retrieve public information. |
Gitea | Self-hosted apps | High | 14.06.2026 |
| CVE-2026-6428 Source A SQL injection vulnerability in Koha library software allows authenticated staff users with reports access to read arbitrary data from the application database, including password hashes and personal information. |
MariaDB | OS & platform | High | 13.06.2026 |
| CVE-2026-11769 Source A vulnerability in the Grafana Operator allows malicious users to steal the Kubernetes service account token of the operator and gain elevated privileges by creating specially crafted Dashboard resources. affects: <5.24.0 |
Grafana | OS & platform | High | 13.06.2026 |
| CVE-2026-48165 Source A security vulnerability in MariaDB database software allows privileged users to execute commands on the server through certain system variables. This can lead to complete compromise of the database system. affects: ≥10.6.1 <10.6.27; ≥10.11.1 <10.11.18; ≥11.4.1 <11.4.12; ≥11.8.1 <11.8.8; =12.3.1 |
MariaDB | OS & platform | High | 12.06.2026 |
| CVE-2026-48163 Source A vulnerability in MariaDB database servers allows malicious nodes to execute arbitrary system commands on other servers when joining a database cluster. affects: ≥10.6.1 <10.6.27; ≥10.11.1 <10.11.18; ≥11.4.1 <11.4.12; ≥11.8.1 <11.8.8; =12.3.1 |
MariaDB | OS & platform | High | 12.06.2026 |
| CVE-2026-44173 Source MariaDB database server in certain versions failed to properly check file permissions, allowing users without appropriate rights to export data to files. This enables unauthorized access to sensitive database contents. affects: ≥10.6.1 <10.6.26; ≥10.11.1 <10.11.17; ≥11.4.1 <11.4.11; ≥11.8.1 <11.8.7; =12.3.1 |
MariaDB | OS & platform | Medium | 12.06.2026 |
| CVE-2026-44172 Source A vulnerability in MariaDB versions 3.3.18 and 3.4.8 allows SQL injection attacks despite using the mysql_real_escape_string() security function when using big5 character encoding. affects: =3.3.18; =3.4.8 |
MariaDB | OS & platform | Critical | 12.06.2026 |
| CVE-2026-44171 Source A vulnerability in MariaDB's mbstream backup tool allows attackers to create files outside the intended target directory through specially crafted archives, potentially leading to unauthorized file access. affects: ≥10.6.1 <10.6.26; ≥10.11.1 <10.11.17; ≥11.4.1 <11.4.11; ≥11.8.1 <11.8.7; =12.3.1 |
MariaDB | OS & platform | Medium | 12.06.2026 |
| CVE-2026-44170 Source A vulnerability in MariaDB on Windows systems allows users to execute system commands when the CONNECT engine with REST support is enabled, due to unsafe processing of HTTP attributes. affects: ≥10.6.1 <10.6.26; ≥10.11.1 <10.11.17; ≥11.4.1 <11.4.11; ≥11.8.1 <11.8.7; =12.3.1 |
MariaDB | OS & platform | Critical | 12.06.2026 |