CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-44462 - Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via ba
CVE-2026-44461 - Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string
CVE-2026-41185 - When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI
CVE-2026-41184 - In Calico, the install-cni init container logs the rendered CNI configuration to standard output. Wh
CVE-2026-41160 - EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business l
CVE-2026-41141 - EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /ap
CVE-2026-38707 - A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware
CVE-2026-38704 - A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmw
CVE-2026-38703 - A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmwa
CVE-2026-38702 - A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmwa
CVE-2026-24444 - SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded pas
CVE-2026-48735 - pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this
CVE-2026-48526 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding J
CVE-2026-48525 - PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JW
CVE-2026-48524 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() f
CVE-2026-48523 - PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side a
CVE-2026-48522 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argu
CVE-2026-48156 - pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this
CVE-2026-48155 - pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this
CVE-2026-47762 - TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS
CVE-2026-47761 - TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS
CVE-2026-47760 - TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vuln
CVE-2026-47759 - TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS
CVE-2026-45017 - Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in File
CVE-2026-44672 - mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to bef
CVE-2026-44594 - esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local
CVE-2026-44593 - esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the leg
CVE-2026-44358 - Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitH
CVE-2026-41565 - CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify h
CVE-2026-35676 - phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password
CVE-2026-35675 - phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint
CVE-2026-35672 - phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default
CVE-2026-35671 - phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API us
CVE-2026-9828 - Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectI
CVE-2026-8990 - A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile a
CVE-2026-8980 - The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An au
CVE-2026-8979 - The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. A
CVE-2026-49238 - An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server comp
CVE-2026-49237 - An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete
CVE-2026-42250 - bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted
CVE-2026-37579 - An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cm
CVE-2026-37266 - An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker t
CVE-2026-9818 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9658 - Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections
CVE-2026-40914 - A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with securi
CVE-2026-9813 - FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the ext
CVE-2026-4377 - Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not requir
CVE-2026-47074 - Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCa
CVE-2026-46241 - In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-fre
CVE-2026-46240 - In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free
CVE-2026-46239 - In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime
CVE-2026-46238 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowne
CVE-2026-46237 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46236 - In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DM
CVE-2026-46235 - In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap ret
CVE-2026-46234 - In the Linux kernel, the following vulnerability has been resolved: vsock: fix buffer size clamping
CVE-2026-46233 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non
CVE-2026-46232 - In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_tou
CVE-2026-46231 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: put backbone r
CVE-2026-46230 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB re
CVE-2026-46229 - In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Clear VRAM on alloc
CVE-2026-46228 - In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix devres lifetime
CVE-2026-46227 - In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor af
CVE-2026-46226 - In the Linux kernel, the following vulnerability has been resolved: spi: fsl: fix controller deregi
CVE-2026-46225 - In the Linux kernel, the following vulnerability has been resolved: spi: rspi: fix controller dereg
CVE-2026-46224 - In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix bo leak in xe_dma_b
CVE-2026-46223 - In the Linux kernel, the following vulnerability has been resolved: cgroup: Defer css percpu_ref ki
CVE-2026-46222 - In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: Add mis
CVE-2026-46221 - In the Linux kernel, the following vulnerability has been resolved: EDAC/versalnet: Fix device name
CVE-2026-46220 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4: replace BUG_O
CVE-2026-46219 - In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-fre
CVE-2026-46218 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add bounds checking
CVE-2026-46217 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46216 - In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Add NULL check for
CVE-2026-46215 - In the Linux kernel, the following vulnerability has been resolved: drm: Set old handle to NULL bef
CVE-2026-46214 - In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix accept queue
CVE-2026-46213 - In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix UAF in in
CVE-2026-46212 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-af
CVE-2026-46211 - In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: fix error handling
CVE-2026-46210 - In the Linux kernel, the following vulnerability has been resolved: media: iris: fix use-after-free
CVE-2026-46209 - In the Linux kernel, the following vulnerability has been resolved: drm/gem: Fix inconsistent plane
CVE-2026-46208 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop tp_meter sessi
CVE-2026-46207 - In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload
CVE-2026-46206 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject new tp_meter
CVE-2026-46205 - In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Disall
CVE-2026-46204 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB re
CVE-2026-46203 - In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclo
CVE-2026-46202 - In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: run inactivit
CVE-2026-46201 - In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix dma-buf attachment
CVE-2026-46200 - In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix controller de
CVE-2026-46199 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB re
CVE-2026-46198 - In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix integer overflo
CVE-2026-46197 - In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: validate SVM ioctl
CVE-2026-46196 - In the Linux kernel, the following vulnerability has been resolved: tracepoint: balance regfunc() o
CVE-2026-46195 - In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffse
CVE-2026-46194 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46193 - In the Linux kernel, the following vulnerability has been resolved: xfrm: ah: account for ESN high
CVE-2026-46192 - In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: don't
CVE-2026-46191 - In the Linux kernel, the following vulnerability has been resolved: fbcon: Avoid OOB font access if
CVE-2026-46190 - In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: debugfs: fix out-
CVE-2026-46189 - In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double fre
CVE-2026-46188 - In the Linux kernel, the following vulnerability has been resolved: octeon_ep_vf: add NULL check fo
CVE-2026-46187 - In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: fix kthread lifetime
CVE-2026-46186 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: validate
CVE-2026-46185 - In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds r
CVE-2026-46184 - In the Linux kernel, the following vulnerability has been resolved: sound: ua101: fix division by z
CVE-2026-46183 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect
CVE-2026-46182 - In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Prevent ke
CVE-2026-46181 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix mis-use of RCU i
CVE-2026-46180 - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential u
CVE-2026-46179 - In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Don't allow pointer
CVE-2026-46178 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Fix resource leak on
CVE-2026-46177 - In the Linux kernel, the following vulnerability has been resolved: ipmi: Add limits to event and r
CVE-2026-46176 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix error path fall-
CVE-2026-46175 - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency ca
CVE-2026-46174 - In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Prevent improper i
CVE-2026-46173 - In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oop
CVE-2026-46172 - In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on err
CVE-2026-46171 - In the Linux kernel, the following vulnerability has been resolved: riscv: kvm: fix vector context
CVE-2026-46170 - In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: free s
CVE-2026-46169 - In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by va
CVE-2026-46168 - In the Linux kernel, the following vulnerability has been resolved: mptcp: fix scheduling with atom
CVE-2026-46167 - In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized h
CVE-2026-46166 - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: use safe list i
CVE-2026-46165 - In the Linux kernel, the following vulnerability has been resolved: openvswitch: vport: fix self-de
CVE-2026-46164 - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in creat
CVE-2026-46163 - In the Linux kernel, the following vulnerability has been resolved: wifi: b43legacy: enforce bounds
CVE-2026-46162 - In the Linux kernel, the following vulnerability has been resolved: ice: fix double free in ice_sf_
CVE-2026-46161 - In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix divide-by-zero i
CVE-2026-46160 - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix missing last_unlink_
CVE-2026-46159 - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix btrfs_ioctl_space_in
CVE-2026-46158 - In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always
CVE-2026-46157 - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix data race a
CVE-2026-46156 - In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix potential ADE in
CVE-2026-46155 - In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds r
CVE-2026-46154 - In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under
CVE-2026-46153 - In the Linux kernel, the following vulnerability has been resolved: 8021q: delete cleared egress Qo
CVE-2026-46152 - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'sta
CVE-2026-46151 - In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix heap leak in IE
CVE-2026-46150 - In the Linux kernel, the following vulnerability has been resolved: fanotify: fix false positive on
CVE-2026-46149 - In the Linux kernel, the following vulnerability has been resolved: scsi: target: configfs: Bound s
CVE-2026-46148 - In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: contr
CVE-2026-46147 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix pin leak and pu
CVE-2026-46146 - In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Avoid potentia
CVE-2026-46145 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Validate rx_hash_key
CVE-2026-46144 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Fix error unwind in
CVE-2026-46143 - In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm-lpass-dai: Fi
CVE-2026-46142 - In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix VF illegal regi
CVE-2026-46141 - In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: fix kmemleak caus
CVE-2026-46140 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: validate WMT
CVE-2026-46139 - In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zer
CVE-2026-46138 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB r
CVE-2026-46137 - In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix po
CVE-2026-46136 - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix a poten
CVE-2026-46135 - In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICR
CVE-2026-46134 - In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec:
CVE-2026-46133 - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcode
CVE-2026-46132 - In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_br
CVE-2026-46131 - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: check for nEPT/nNPT i
CVE-2026-46130 - In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading pari
CVE-2026-46129 - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in creat
CVE-2026-46128 - In the Linux kernel, the following vulnerability has been resolved: ipmi: Check event message buffe
CVE-2026-46127 - In the Linux kernel, the following vulnerability has been resolved: RDMA/ocrdma: Don't NULL deref u
CVE-2026-46126 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Fix mana_destroy_wq_
CVE-2026-46125 - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station
CVE-2026-46124 - In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number fr
CVE-2026-46123 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx
CVE-2026-46122 - In the Linux kernel, the following vulnerability has been resolved: wifi: b43: enforce bounds check
CVE-2026-46121 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect
CVE-2026-46120 - In the Linux kernel, the following vulnerability has been resolved: ip6_gre: Use cached t->net in i
CVE-2026-46119 - In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds
CVE-2026-46118 - In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Fix null p
CVE-2026-46117 - In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggera
CVE-2026-46116 - In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_s
CVE-2026-46115 - In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biove
CVE-2026-46114 - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject non-8-byte ATO
CVE-2026-46113 - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use
CVE-2026-46112 - In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix unlocked call to
CVE-2026-46111 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potent
CVE-2026-46110 - In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Prevent NULL deref
CVE-2026-46109 - In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: fix memory leak on u
CVE-2026-46108 - In the Linux kernel, the following vulnerability has been resolved: ipmi:si: Return state to normal
CVE-2026-46107 - In the Linux kernel, the following vulnerability has been resolved: dm-thin: fix metadata refcount
CVE-2026-46106 - In the Linux kernel, the following vulnerability has been resolved: eventfs: Hold eventfs_mutex and
CVE-2026-46105 - In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Limit NVMe reque
CVE-2026-46104 - In the Linux kernel, the following vulnerability has been resolved: selinux: use sk blob accessor i
CVE-2025-48977 - Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can r
CVE-2026-9807 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.1
CVE-2026-9804 - A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-leve
CVE-2026-9015 - The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for Wo
CVE-2026-8689 - The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missin
CVE-2026-7526 - The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all version
CVE-2026-7048 - The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to tim
CVE-2026-6937 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress
CVE-2026-6226 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege esc
CVE-2026-4408 - A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers an
CVE-2026-4334 - The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headl
CVE-2024-47097 - Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a re
CVE-2024-47096 - Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a re
CVE-2026-9806 - A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute
CVE-2026-9618 - The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authori
CVE-2026-9227 - The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all v
CVE-2026-8682 - The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnera
CVE-2026-7862 - The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access t
CVE-2026-7797 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress
CVE-2026-7660 - The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th
CVE-2026-7651 - The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, Us
CVE-2026-7634 - The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Us
CVE-2026-7621 - The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized acces
CVE-2026-7552 - The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
CVE-2026-7052 - The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S
CVE-2026-6455 - The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery le
CVE-2026-6427 - The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions u
CVE-2026-44604 - A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extract
CVE-2026-9803 - A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker c
CVE-2026-9802 - A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage
CVE-2026-9801 - A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator
CVE-2026-9798 - A flaw was found in Keycloak, an open-source identity and access management solution. When a user ac
CVE-2026-9673 - Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via
CVE-2026-9644 - The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scr
CVE-2026-9009 - The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code E
CVE-2026-7533 - The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v
CVE-2026-3173 - The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all v
CVE-2026-9796 - A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can expl
CVE-2026-9795 - A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator wit
CVE-2026-9794 - A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by s
CVE-2026-9793 - A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted
CVE-2026-9792 - A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc`
CVE-2026-9791 - A flaw was found in Keycloak. An authenticated user with existing organization membership can exploi
CVE-2026-9241 - The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Autho
CVE-2026-9228 - The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct
CVE-2026-7802 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all v
CVE-2026-5737 - The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all v
CVE-2026-32999 - Insufficient character filtering in backup agent signing module on Comet Backup server allows authen
CVE-2026-32998 - This vulnerability in Veeam Service Provider Console allows for remote code execution.
CVE-2026-32997 - A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary
CVE-2026-32996 - This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
CVE-2026-32995 - The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4
CVE-2026-2374 - The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-9789 - A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to
CVE-2026-8915 - Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss
CVE-2026-4888 - The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPr
CVE-2026-9739 - Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we i
CVE-2026-46544 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.
CVE-2026-46538 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.
CVE-2026-46416 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.
CVE-2026-46414 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.
CVE-2026-46402 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.
CVE-2026-45322 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microso
CVE-2026-9208 - Tanium addressed an unauthorized code execution vulnerability in Connect.
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.