CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-76325 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"
CVE-2026-76324 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"
CVE-2026-76323 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76322 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user"
CVE-2026-76321 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul
CVE-2026-76320 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul
CVE-2026-76319 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d
CVE-2026-76318 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
CVE-2026-76317 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76316 - In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who
CVE-2026-76315 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76314 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76313 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76312 - In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
CVE-2026-76311 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
CVE-2026-76310 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who
CVE-2026-76309 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d
CVE-2026-76263 - In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "powe
CVE-2026-76262 - In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus servi
CVE-2026-76261 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
CVE-2026-76260 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
CVE-2026-76259 - In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local
CVE-2026-76258 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
CVE-2026-76257 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
CVE-2026-76256 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
CVE-2026-76255 - In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13, a user who does not hold the
CVE-2026-76254 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated u
CVE-2026-76253 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
CVE-2026-76252 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who
CVE-2026-76251 - In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin"
CVE-2026-69550 - Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information
CVE-2026-63123 - Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev ser
CVE-2026-59992 - Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0
CVE-2025-36398 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0
CVE-2025-36255 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0
CVE-2025-36254 - IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0
CVE-2026-76827 - A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed
CVE-2026-76584 - A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some
CVE-2026-76583 - A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is a
CVE-2026-76582 - A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/syst
CVE-2026-76576 - A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDown
CVE-2026-76139 - A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a s
CVE-2026-75616 - An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmwa
CVE-2026-75596 - Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2
CVE-2026-75595 - Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.
CVE-2026-75569 - A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remot
CVE-2026-75476 - Tanium addressed a compression bomb vulnerability in Threat Response.
CVE-2026-69222 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2
CVE-2026-68555 - Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TUR
CVE-2026-68554 - Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path att
CVE-2026-68553 - Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticat
CVE-2026-68552 - Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthentic
CVE-2026-62727 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-61556 - LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 unt
CVE-2026-54743 - Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/l
CVE-2026-54741 - Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy b
CVE-2026-54740 - Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower
CVE-2026-54739 - Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's l
CVE-2026-54738 - Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web
CVE-2026-54494 - Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicH
CVE-2026-54493 - Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible create
CVE-2026-54492 - Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible create
CVE-2026-54491 - Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fet
CVE-2026-53549 - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa
CVE-2026-53548 - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa
CVE-2026-53547 - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa
CVE-2026-53546 - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa
CVE-2026-53545 - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa
CVE-2026-53542 - Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa
CVE-2026-4937 - IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 throug
CVE-2026-4936 - IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.0
CVE-2026-18849 - IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update pr
CVE-2026-18544 - IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image polic
CVE-2026-18102 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memor
CVE-2026-17015 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic
CVE-2026-14978 - HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclu
CVE-2026-14514 - IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial
CVE-2026-12634 - The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored s
CVE-2026-12633 - The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6
CVE-2026-12522 - The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers
CVE-2026-11617 - Tanium addressed a compression bomb vulnerability in Findings.
CVE-2026-76647 - Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JS
CVE-2026-76574 - A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the
CVE-2026-76572 - A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is
CVE-2026-75593 - BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and
CVE-2026-75112 - A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insuf
CVE-2026-74228 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-74227 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-74226 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-68901 - Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api
CVE-2026-68900 - Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/
CVE-2026-68899 - Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation
CVE-2026-68561 - Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) ru
CVE-2026-68560 - Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated
CVE-2026-68559 - Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/export
CVE-2026-68558 - Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integratio
CVE-2026-67189 - pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnera
CVE-2026-63722 - ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthentic
CVE-2026-63188 - Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto
CVE-2026-63187 - Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0,
CVE-2026-62317 - Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's
CVE-2026-61712 - BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and
CVE-2026-61711 - BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and
CVE-2026-55090 - Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/Exp
CVE-2026-55089 - Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/AP
CVE-2026-55088 - Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/expr
CVE-2026-55087 - Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-con
CVE-2026-55086 - Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and
CVE-2026-55085 - Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/dom
CVE-2026-54742 - Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.2
CVE-2026-22306 - Download of code without integrity check, inclusion of functionality from untrusted control sphere,
CVE-2026-19509 - Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q
CVE-2026-19508 - Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-20
CVE-2026-19507 - Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` all
CVE-2026-19506 - Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attack
CVE-2026-19505 - Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirks
CVE-2026-18871 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af
CVE-2026-18821 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-17590 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-32475. Reason:
CVE-2026-17414 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-17097 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-17091 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-17063 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 i
CVE-2026-17042 - IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.
CVE-2026-17028 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-16933 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95
CVE-2026-16919 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16917 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16914 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
CVE-2026-16913 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16911 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
CVE-2026-16909 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16903 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16901 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16897 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-16894 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16891 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
CVE-2026-16890 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
CVE-2026-16888 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info
CVE-2026-16886 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16885 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16883 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
CVE-2026-16882 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com
CVE-2026-16877 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
CVE-2026-16875 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm
CVE-2026-16874 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges
CVE-2026-16873 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve local privileg
CVE-2026-16872 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16869 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
CVE-2026-16866 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16865 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16864 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16862 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16857 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network tr
CVE-2026-16855 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-16852 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16851 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16850 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16849 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16848 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com
CVE-2026-16847 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16846 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16845 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16844 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com
CVE-2026-16842 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com
CVE-2026-16841 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16840 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16839 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info
CVE-2026-16838 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical fil
CVE-2026-16837 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16836 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16834 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16833 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to disclose kernel memor
CVE-2026-16831 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16829 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16827 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16825 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain
CVE-2026-16824 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16822 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p
CVE-2026-16724 - IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, an
CVE-2026-16707 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-16661 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95
CVE-2026-75619 - Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authen
CVE-2026-75618 - Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker
CVE-2026-70496 - A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a c
CVE-2026-61807 - Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier
CVE-2026-55703 - Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request
CVE-2026-55694 - Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /ap
CVE-2026-55643 - Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS flo
CVE-2026-55519 - Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generi
CVE-2026-55483 - Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.
CVE-2026-55482 - Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http
CVE-2026-50550 - Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users c
CVE-2026-49976 - Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission
CVE-2026-49870 - Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limi
CVE-2026-19321 - Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af
CVE-2026-19198 - Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkAc
CVE-2026-18848 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and
CVE-2026-18681 - IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.0
CVE-2026-18315 - The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Auth
CVE-2026-17494 - IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability
CVE-2026-17429 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95
CVE-2026-17100 - Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00
CVE-2026-17093 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW95
CVE-2026-16938 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and
CVE-2026-16930 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 i
CVE-2026-16835 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and
CVE-2026-16832 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and
CVE-2026-16828 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and
CVE-2026-16687 - IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and
CVE-2026-75149 - marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler
CVE-2026-73829 - Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote cl
CVE-2026-73541 - Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote
CVE-2026-73136 - Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obta
CVE-2026-72717 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-72716 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71871 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71869 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71868 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71867 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71866 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71865 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-71864 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-69159 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason:
CVE-2026-67581 - Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to ob
CVE-2026-66794 - A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This
CVE-2026-63652 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv
CVE-2026-63633 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode
CVE-2026-63117 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated R
CVE-2026-62682 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-62681 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-62680 - Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat
CVE-2026-61518 - ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id pa
CVE-2026-55648 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy
CVE-2026-55564 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_ge
CVE-2026-55194 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fr
CVE-2026-55193 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients us
CVE-2026-55192 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 deco
CVE-2026-55191 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients th
CVE-2026-32475 - Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Usin
CVE-2026-19875 - IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email
CVE-2026-19653 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-19234 - Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is af
CVE-2026-18874 - A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malici
CVE-2026-17183 - An authenticated user with permission to create or edit alert rules can bypass datasource query auth
CVE-2025-14603 - The application component processes user-supplied parameters insecurely, passing them into SQL queri
CVE-2025-14600 - An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized ad
CVE-2026-75583 - keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) g
CVE-2026-75147 - FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/r
CVE-2026-75146 - FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware