CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-75145 - FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packe
CVE-2026-75144 - FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP pac
CVE-2026-75143 - FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavforma
CVE-2026-75142 - FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpeg
CVE-2026-75141 - FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an
CVE-2026-72530 - A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions
CVE-2026-72529 - A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions
CVE-2026-71470 - A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specificall
CVE-2026-50173 - Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps
CVE-2026-49441 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-49392 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-48162 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-48024 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-45798 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-44901 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-44256 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-44255 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-41424 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-20359 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork
CVE-2026-20358 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork
CVE-2026-20357 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork
CVE-2026-20327 - A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all
CVE-2026-20320 - A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an una
CVE-2026-20319 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo
CVE-2026-20318 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo
CVE-2026-20317 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo
CVE-2026-20315 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo
CVE-2026-20314 - A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact
CVE-2026-20302 - A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker wit
CVE-2026-20232 - A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series
CVE-2026-20231 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo
CVE-2026-20177 - A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 S
CVE-2026-20030 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork
CVE-2024-13942 - Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of boot
CVE-2026-64852 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-64851 - Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common form
CVE-2026-64850 - Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/
CVE-2026-63408 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-63407 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-62673 - Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess
CVE-2026-62672 - Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and func
CVE-2026-62671 - Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Gra
CVE-2026-62670 - Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav
CVE-2026-62669 - Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Gra
CVE-2026-62668 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-62667 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-62666 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-61842 - Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offset
CVE-2026-61690 - Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Co
CVE-2026-61607 - Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont
CVE-2026-53654 - Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a clie
CVE-2026-46343 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-44254 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1
CVE-2026-44253 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3
CVE-2026-44252 - Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4
CVE-2026-19672 - The tarfile module's tar and data extraction filters created directories outside the destination fo
CVE-2026-18430 - HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notificat
CVE-2026-16819 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-76614 - OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. Th
CVE-2026-76203 - Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer
CVE-2026-75956 - Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirector
CVE-2026-75955 - Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - co
CVE-2026-75954 - Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - S
CVE-2026-75953 - Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient addre
CVE-2026-75952 - Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Toke
CVE-2026-75951 - Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions)
CVE-2026-75950 - Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory
CVE-2026-75949 - Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessD
CVE-2026-71961 - Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that a
CVE-2026-71960 - Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnera
CVE-2026-71176 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special
CVE-2026-67268 - Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External
CVE-2026-67267 - Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Informat
CVE-2026-67266 - Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability
CVE-2026-58565 - Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A
CVE-2026-58564 - Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnera
CVE-2026-58562 - Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A
CVE-2026-56797 - Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condit
CVE-2026-56796 - Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File
CVE-2026-54793 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input Du
CVE-2026-53477 - Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Rac
CVE-2026-53452 - Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and
CVE-2026-53451 - Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and
CVE-2026-52889 - Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hi
CVE-2026-52834 - jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a cr
CVE-2026-52792 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects
CVE-2026-50149 - Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, whe
CVE-2026-49817 - Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vuln
CVE-2026-49816 - Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vuln
CVE-2026-49289 - The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20
CVE-2026-49283 - The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions
CVE-2026-49255 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-49253 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-48711 - SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SS
CVE-2026-47187 - SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue
CVE-2026-45742 - Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext
CVE-2026-45741 - Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP fun
CVE-2026-45274 - MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.p
CVE-2026-45273 - MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSe
CVE-2026-45272 - MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook.
CVE-2026-44829 - Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling
CVE-2026-40509 - OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The we
CVE-2026-40508 - OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal temp
CVE-2026-40507 - OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal t
CVE-2026-32802 - Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerabil
CVE-2026-23501 - Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Specia
CVE-2026-18756 - HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space
CVE-2026-18526 - HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerabi
CVE-2026-16818 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16817 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16816 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
CVE-2026-16814 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16706 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16703 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
CVE-2026-16690 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-16686 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported f
CVE-2026-16656 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges
CVE-2026-15961 - IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM P
CVE-2026-15078 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized
CVE-2026-15068 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to exe
CVE-2026-15065 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security r
CVE-2026-15061 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote a
CVE-2026-14970 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registrat
CVE-2026-76245 - stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federat
CVE-2026-76244 - stigmem-node contains an insecure default configuration vulnerability that allows federation traffic
CVE-2026-76243 - stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-
CVE-2026-76242 - stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separat
CVE-2026-76241 - stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration f
CVE-2026-76240 - stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defen
CVE-2026-76239 - Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subsc
CVE-2026-76238 - stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the de
CVE-2026-76237 - stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulner
CVE-2026-76236 - stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw i
CVE-2026-76234 - libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic i
CVE-2026-76233 - Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam
CVE-2026-76232 - Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv
CVE-2026-76231 - Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the herm
CVE-2026-76230 - Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm m
CVE-2026-76229 - Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability
CVE-2026-76228 - Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) con
CVE-2026-76227 - Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/
CVE-2026-76226 - Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in baz
CVE-2026-76225 - ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD C
CVE-2026-76224 - ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulne
CVE-2026-76223 - ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission che
CVE-2026-76222 - GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers
CVE-2026-76221 - GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator
CVE-2026-76220 - GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard
CVE-2026-76219 - GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from
CVE-2026-76218 - GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards un
CVE-2026-76217 - GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands
CVE-2026-76216 - Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals
CVE-2026-76215 - phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources i
CVE-2026-76214 - phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, be
CVE-2026-76213 - phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step whe
CVE-2026-76212 - phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declare
CVE-2026-76211 - phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endp
CVE-2026-76210 - phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TC
CVE-2026-76209 - phpMyFAQ versions before v4.1.6 fail to validate the security.enableRegistration setting in API endp
CVE-2026-76208 - phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::cr
CVE-2026-76207 - phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me to
CVE-2026-76206 - phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing u
CVE-2026-76205 - phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpo
CVE-2026-75920 - phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at con
CVE-2026-75919 - phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows
CVE-2026-75918 - phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user
CVE-2026-75917 - SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-t
CVE-2026-75916 - SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autoc
CVE-2026-75148 - cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds chec
CVE-2026-75114 - Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo <
CVE-2026-74804 - Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo
CVE-2026-74803 - Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image
CVE-2026-71694 - An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b456321217521
CVE-2026-70424 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname t
CVE-2026-70423 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML Externa
CVE-2026-70422 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special
CVE-2026-70421 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne
CVE-2026-65612 - nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a s
CVE-2026-65611 - nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem,
CVE-2026-65610 - nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attac
CVE-2026-65609 - nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-control
CVE-2026-56088 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special
CVE-2026-54796 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special
CVE-2026-54795 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special
CVE-2026-54794 - Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) v
CVE-2026-51367 - An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive i
CVE-2026-51366 - SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to
CVE-2026-50720 - The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the
CVE-2026-50719 - The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-cont
CVE-2026-43961 - A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio
CVE-2026-16019 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2024-58376 - Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 m
CVE-2020-37267 - Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authori
CVE-2019-25766 - Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comme
CVE-2026-76235 - A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every
CVE-2026-73394 - Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
CVE-2026-73391 - Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-73390 - Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVE-2026-73389 - Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
CVE-2026-73388 - Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
CVE-2026-73387 - Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
CVE-2026-73386 - Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2
CVE-2026-73385 - Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
CVE-2026-73384 - Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
CVE-2026-73364 - Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVE-2026-73363 - Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
CVE-2026-73354 - Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
CVE-2026-73347 - Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
CVE-2026-73185 - Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
CVE-2026-73184 - Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
CVE-2026-73183 - Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-73182 - Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
CVE-2026-67364 - Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's
CVE-2026-67363 - Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The
CVE-2026-66668 - Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
CVE-2026-66613 - Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-66596 - Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
CVE-2026-61986 - Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
CVE-2026-32552 - Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
CVE-2026-19490 - Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.
CVE-2026-19489 - Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.
CVE-2026-18372 - CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault adminis
CVE-2026-18371 - HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to
CVE-2026-16440 - In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a
CVE-2026-76166 - A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single
CVE-2026-76164 - AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission
CVE-2026-75900 - An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The ent
CVE-2026-75589 - Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with
CVE-2026-72889 - Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verif
CVE-2026-58088 - The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the cor
CVE-2026-58087 - The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dro
CVE-2026-58086 - As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed
CVE-2026-58085 - After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to ch
CVE-2026-58084 - To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the curren
CVE-2026-58083 - While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be
CVE-2026-58082 - The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate char
CVE-2026-58081 - Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the
CVE-2026-49425 - The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct
CVE-2026-49424 - The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux
CVE-2026-75981 - The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner
CVE-2026-49423 - When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremen
CVE-2026-15780 - The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vu
CVE-2026-15446 - The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data
CVE-2026-8810 - On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker
CVE-2026-49431 - The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an
CVE-2026-49430 - The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a
CVE-2026-49429 - The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to
CVE-2026-49428 - Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly fr
CVE-2026-49427 - Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) tran
CVE-2026-49426 - When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware