CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-63801 - In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free R
CVE-2026-63800 - In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnf
CVE-2026-63799 - In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Fix OOB clear_bit
CVE-2026-63798 - In the Linux kernel, the following vulnerability has been resolved: irqchip/imgpdc: Fix resource le
CVE-2026-63797 - In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free
CVE-2026-63796 - In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group b
CVE-2026-63795 - In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_
CVE-2026-63794 - In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Fix page overflow in
CVE-2026-63793 - In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize volume label ac
CVE-2026-53403 - In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_new_modelist to p
CVE-2026-53402 - In the Linux kernel, the following vulnerability has been resolved: fbdev: fbcon: fix out-of-bounds
CVE-2026-53401 - In the Linux kernel, the following vulnerability has been resolved: fbdev: omap2: fix use-after-fre
CVE-2026-53400 - In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registra
CVE-2026-53399 - In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on se
CVE-2026-53398 - In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decod
CVE-2026-53397 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SET
CVE-2026-53396 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak and ig
CVE-2026-53395 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dead ACL conflict gua
CVE-2026-53394 - In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocat
CVE-2026-53393 - In the Linux kernel, the following vulnerability has been resolved: nfsd: reset write verifier on d
CVE-2026-53392 - In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: reject zero fi
CVE-2026-53391 - In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length
CVE-2026-53390 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds read i
CVE-2026-53389 - In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: fix use-after-free
CVE-2026-53388 - In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before re
CVE-2026-53387 - In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bound
CVE-2026-53386 - In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: add bound
CVE-2026-53385 - In the Linux kernel, the following vulnerability has been resolved: vc_screen: fix null-ptr-deref i
CVE-2026-53384 - In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 825
CVE-2026-53383 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session
CVE-2026-53382 - In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer
CVE-2026-53381 - In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix UAF on submount u
CVE-2026-53380 - In the Linux kernel, the following vulnerability has been resolved: media: rzv2h-ivc: Fix concurren
CVE-2026-53379 - In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free contro
CVE-2026-53378 - In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property
CVE-2026-53377 - In the Linux kernel, the following vulnerability has been resolved: drm/msm: always recover the gpu
CVE-2026-53376 - In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound che
CVE-2026-53375 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial
CVE-2026-53374 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GAR
CVE-2026-53373 - In the Linux kernel, the following vulnerability has been resolved: mm/vma: do not try to unmap a V
CVE-2026-16229 - A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerab
CVE-2026-16228 - A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an
CVE-2026-16227 - A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0.
CVE-2026-53372 - In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Block PASID attachm
CVE-2026-53371 - In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: bound node_desc sys
CVE-2026-53370 - In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Improve validat
CVE-2026-53369 - In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with ov
CVE-2026-53368 - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency ca
CVE-2026-53367 - In the Linux kernel, the following vulnerability has been resolved: selinux: fix avdcache auditing
CVE-2026-16226 - A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the func
CVE-2026-16225 - A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the f
CVE-2026-16224 - A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown
CVE-2026-16223 - A vulnerability was determined in 1Panel-dev CordysCRM up to 1.4.1. Impacted is the function getSqlB
CVE-2026-16222 - A vulnerability was found in 1Panel-dev CordysCRM up to 1.4.1. This issue affects some unknown proce
CVE-2026-16220 - A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability af
CVE-2026-16219 - A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable o
CVE-2026-16218 - A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function
CVE-2026-16217 - A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulner
CVE-2026-16216 - A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function
CVE-2026-16215 - A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown fun
CVE-2026-16214 - A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function
CVE-2026-16213 - A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vu
CVE-2026-16212 - A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of
CVE-2026-16211 - A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impac
CVE-2026-16210 - A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_acti
CVE-2026-16209 - A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function o
CVE-2026-16208 - A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThr
CVE-2026-16207 - A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthent
CVE-2026-16206 - A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue af
CVE-2026-16205 - A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function ht
CVE-2026-16204 - A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_ru
CVE-2026-16203 - A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by
CVE-2026-16202 - A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by
CVE-2026-16201 - A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_
CVE-2026-16200 - A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_in
CVE-2026-16199 - A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function Exec
CVE-2026-16198 - A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown func
CVE-2026-16197 - A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is t
CVE-2026-16196 - A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrR
CVE-2026-16195 - A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function
CVE-2026-10130 - QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to
CVE-2026-16194 - A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.
CVE-2026-16156 - A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This af
CVE-2026-57857 - The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site
CVE-2026-16155 - A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by
CVE-2026-16154 - A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affect
CVE-2026-16152 - A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an un
CVE-2026-12228 - A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint o
CVE-2026-57848 - Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any
CVE-2026-53994 - ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The
CVE-2026-16151 - A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilt
CVE-2026-16150 - A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the funct
CVE-2026-16133 - A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the functio
CVE-2026-16131 - A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unkno
CVE-2026-16130 - A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function
CVE-2026-16129 - A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the
CVE-2026-16128 - A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receive
CVE-2026-16127 - A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get
CVE-2026-16126 - A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function h
CVE-2026-16125 - A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_n
CVE-2026-16124 - A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This aff
CVE-2026-16123 - A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is th
CVE-2026-16122 - A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulner
CVE-2026-16121 - A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isS
CVE-2026-9323 - The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in
CVE-2026-16120 - A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the func
CVE-2026-16119 - A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function Request
CVE-2026-16117 - Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix w
CVE-2026-11826 - OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_
CVE-2025-71398 - SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated us
CVE-2025-71397 - SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with O
CVE-2025-71396 - SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execut
CVE-2025-71395 - SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace fun
CVE-2025-71394 - SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER state
CVE-2025-71393 - SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native
CVE-2025-71392 - SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table an
CVE-2025-71391 - SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that a
CVE-2025-71390 - SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resol
CVE-2024-58370 - SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL
CVE-2024-58369 - SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functi
CVE-2024-58368 - SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API r
CVE-2024-58367 - SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, an
CVE-2024-58366 - SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type
CVE-2024-58365 - SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor wh
CVE-2024-58364 - SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span renderi
CVE-2024-58363 - SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches database
CVE-2024-58362 - SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signi
CVE-2024-58361 - SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser e
CVE-2024-58359 - SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism w
CVE-2024-58358 - SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that al
CVE-2024-58357 - SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() func
CVE-2024-58356 - SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERW
CVE-2023-54366 - SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREA
CVE-2026-9147 - uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and
CVE-2026-59173 - Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache
CVE-2026-16158 - Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal UR
CVE-2026-15631 - Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the reso
CVE-2026-16097 - A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C
CVE-2026-16096 - A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the funct
CVE-2026-16095 - A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the f
CVE-2026-16088 - A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the fu
CVE-2026-16085 - A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function
CVE-2026-47871 - VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation
CVE-2026-47870 - VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated us
CVE-2026-47869 - VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated u
CVE-2026-47868 - VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with
CVE-2026-47867 - VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with netwo
CVE-2026-47866 - VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the ne
CVE-2026-47865 - VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with netw
CVE-2026-16084 - A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch o
CVE-2026-16083 - A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhoo
CVE-2026-16082 - A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function
CVE-2026-16081 - A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown fu
CVE-2026-16077 - A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_r
CVE-2026-16076 - A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function
CVE-2026-9734 - The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in a
CVE-2026-16075 - A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function O
CVE-2026-57980 - Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows a
CVE-2026-56741 - JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3
CVE-2026-56740 - JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3
CVE-2026-56171 - Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthori
CVE-2026-54335 - Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaSc
CVE-2026-49485 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J
CVE-2026-48049 - @hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/iner
CVE-2026-48022 - @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Au
CVE-2026-44979 - @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a
CVE-2026-55518 - Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51,
CVE-2026-54498 - view_component is a framework for building reusable, testable, and encapsulated view components in R
CVE-2026-54497 - view_component is a framework for building reusable, testable, and encapsulated view components in R
CVE-2026-54490 - websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library
CVE-2026-54466 - websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame forma
CVE-2026-54244 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, t
CVE-2026-54243 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1,
CVE-2026-54242 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1,
CVE-2026-54163 - secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secu
CVE-2026-54159 - PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4
CVE-2026-53727 - css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/c
CVE-2026-52584 - Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensit
CVE-2026-52348 - cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-52203 - An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source par
CVE-2026-50274 - Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling
CVE-2026-50272 - dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in package
CVE-2026-50271 - Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that
CVE-2026-49977 - tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.
CVE-2026-48062 - CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in
CVE-2026-45785 - OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also kno
CVE-2026-45784 - rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80
CVE-2026-44891 - Netty is a network application framework for development of protocol servers and clients. Prior to 4
CVE-2026-16074 - A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_p
CVE-2026-13446 - IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptog
CVE-2026-13445 - IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile
CVE-2026-8861 - IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed te
CVE-2026-8859 - IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to u
CVE-2026-8635 - IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser
CVE-2026-8505 - IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic
CVE-2026-8481 - IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the
CVE-2026-8476 - IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the
CVE-2026-8056 - IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at
CVE-2026-7872 - IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files inclu
CVE-2026-7771 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a sp
CVE-2026-7755 - IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete v
CVE-2026-7754 - IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF)
CVE-2026-7667 - IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow po
CVE-2026-7364 - IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
CVE-2026-63030 - WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route c
CVE-2026-60137 - WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise
CVE-2026-55254 - NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator i
CVE-2026-54465 - websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-
CVE-2026-54464 - ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket s
CVE-2026-54463 - websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions
CVE-2026-54171 - Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware
CVE-2026-52199 - An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrar
CVE-2026-51833 - Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add
CVE-2026-50289 - systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterf
CVE-2026-50197 - Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipp
CVE-2026-50163 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/u
CVE-2026-50162 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/fi
CVE-2026-50151 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in
CVE-2026-4942 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message an
CVE-2026-4938 - IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
CVE-2026-49852 - joserfc is a Python library that provides an implementation of several JSON Object Signing and Encry
CVE-2026-49834 - sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier config
CVE-2026-49284 - SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7
CVE-2026-48978 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm UR
CVE-2026-48819 - Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3,
CVE-2026-48504 - OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagato
CVE-2026-48373 - Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitr
CVE-2026-46420 - setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers,
CVE-2026-45799 - Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0
CVE-2026-45704 - Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6,
CVE-2026-45260 - Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7,
CVE-2026-44974 - @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retaine
CVE-2026-44739 - Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6,
CVE-2026-43636 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-42168 - django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fi
CVE-2026-36669 - An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.
CVE-2026-16118 - A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_
CVE-2026-15995 - IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an at
CVE-2026-15415 - AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow en
CVE-2026-15322 - IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive inf
CVE-2026-15093 - IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to ma
CVE-2026-15091 - IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary sc
CVE-2026-15069 - IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary sc
CVE-2026-14979 - IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Inte
CVE-2026-14971 - IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguratio
CVE-2026-14501 - IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitra
CVE-2026-14499 - IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrar
CVE-2026-13473 - IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Stora
CVE-2026-13448 - IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution
CVE-2026-12283 - Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amaz
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.