CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
28656 CVEs gefunden (Seite 115/115)

CVE-2026-40596 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-40295 - Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when th

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-39824 - NewNTUnicodeString does not check for string length overflow. When provided with a string that overf

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 3.3
3.3

CVE-2026-9291 - Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-6406 - The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Doc

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-48700 - An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's pat

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-40172 - authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 throu

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-40166 - authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 throu

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-39970 - TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerabi

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-39969 - TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endp

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-39968 - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("C

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-39967 - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult que

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 3.1
3.1

CVE-2026-39966 - TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns fu

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-46727 - An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-42627 - In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tenso

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.2
6.2

CVE-2026-39965 - TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypas

🏢 Aws 📅 22.5.2026 📊 CVSS: 7.7
7.7

CVE-2026-39964 - TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-9255 - Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-42626 - HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connection

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.9
5.9

CVE-2026-37470 - An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authenticatio

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36228 - Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive i

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36227 - Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensiti

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-36226 - Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attac

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-34207 - TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP R

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.6
7.6

CVE-2026-33712 - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /ap

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-32253 - Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-28735 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-28445 - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the e

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 8.7
8.7

CVE-2026-28444 - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint auth

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-9251 - Missing authorization in the entry status management feature in Devolutions Server allows a non-admi

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-9249 - Unverified password change in Devolutions Server allows an attacker to change a user's password with

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 3.1
3.1

CVE-2026-9248 - Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 2.6
2.6

CVE-2026-9247 - Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 2.4
2.4

CVE-2026-9246 - Improper access control in the entry documentation and attachment features in Devolutions Server all

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9245 - Improper input validation in the external authentication provider flow in Devolutions Server allows

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.0
5.0

CVE-2026-9224 - Missing authorization in the user profile update feature in Devolutions Server allows an authenticat

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9223 - Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier all

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9047 - Improper handling of factor key state in the multi-factor authentication management feature in Devol

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.6
7.6

CVE-2026-8477 - Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in D

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 2.7
2.7

CVE-2026-7325 - Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-p

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-5171 - Improper access control in the entry activity log feature in Devolutions Server allows an authentica

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-42506 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-42502 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-39821 - The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASC

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.6
9.6

CVE-2026-27136 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-25681 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-25680 - Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2022-34363 - Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnera

🏢 Dell 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2022-31231 - Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Manage

🏢 Dell 📅 22.5.2026 📊 CVSS: 5.9
5.9

CVE-2026-9256 - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vu

🏢 Nginx 📅 22.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-8992 - An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8353 - Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A r

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.8
4.8

CVE-2026-8347 - Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express associ

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8340 - Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edi

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2025-46371 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algo

🏢 Dell 📅 22.5.2026 📊 CVSS: 3.6
3.6

CVE-2025-45145 - Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2025-32751 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information

🏢 Dell 📅 22.5.2026 📊 CVSS: 5.5
5.5

CVE-2021-21508 - Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Ma

🏢 Dell 📅 22.5.2026 📊 CVSS: 6.7
6.7

CVE-2026-9277 - shell-quote's `quote()` function did not validate object-token inputs against the operator model use

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-8997 - vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-8673 - Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows

🏢 Linux 📅 22.5.2026 📊 CVSS: 5.9
5.9

CVE-2026-8672 - Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Co

🏢 Linux 📅 22.5.2026 📊 CVSS: 5.1
5.1

CVE-2026-8671 - Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Lin

🏢 Linux 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8670 - Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allow

🏢 Linux 📅 22.5.2026 📊 CVSS: 9.6
9.6

CVE-2025-32749 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory

🏢 Dell 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2025-32747 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerabili

🏢 Dell 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2025-32746 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information

🏢 Dell 📅 22.5.2026 📊 CVSS: 4.0
4.0

CVE-2025-32745 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerabil

🏢 Dell 📅 22.5.2026 📊 CVSS: 4.2
4.2

CVE-2025-26483 - Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauth

🏢 Dell 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-44930 - An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF

🏢 Apache 📅 22.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-44618 - Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform

🏢 Apache 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-44417 - The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete

🏢 Apache 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-5755 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-5740 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-5308 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-4646 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-4635 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-3636 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-3473 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.9
5.9

CVE-2026-25608 - STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduc

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-25607 - Use of a weak password encoding algorithm in STER software allows the value of the password to be gu

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-25606 - A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-9011 - The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to author

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8692 - The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPr

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8684 - The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versio

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8679 - The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8381 - A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior vers

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-7798 - The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and C

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-7636 - The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable t

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-7615 - The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-5072 - A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-9104 - The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Titl

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-9018 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to P

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-7509 - The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7249 - The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-6864 - The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-4070 - The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-44409 - There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.7
5.7

CVE-2026-3481 - The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortc

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-2518 - The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activati

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-9054 - An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size woul

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-9053 - Mothra would respect a default value given by a website for HTML file upload forms. An attacker coul

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-4834 - The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in

🏢 Wordpress 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-46598 - For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, lead

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-46597 - An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet dec

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-46595 - Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if a

🏢 Suse 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-42508 - Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-39835 - SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHost

🏢 Suse 📅 22.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-39834 - When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in t

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-39833 - The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse cons

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-39832 - When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.c

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-39831 - The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-39830 - A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blo

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-39829 - The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public k

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-39828 - When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, th

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.3
6.3

CVE-2026-39827 - An authenticated SSH client that repeatedly opened channels which were rejected by the server caused

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-9264 - A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remo

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-34911 - A malicious actor with access to the network and low privileges could exploit a Path Traversal vulne

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 7.7
7.7

CVE-2026-34910 - A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-34909 - A malicious actor with access to the network could exploit a Path Traversal vulnerability found in U

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-34908 - A malicious actor with access to the network could exploit an Improper Access Control vulnerability

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-33000 - A malicious actor with access to the network and high privileges could exploit an Improper Input Val

🏢 Sonstige 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-5297 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-8435 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-8434 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8433 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8432 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8427 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8416 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8415 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8414 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8413 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8412 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controll

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8411 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8410 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8409 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8337 - Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have t

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8327 - Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and sess

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8245 - Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-8240 - Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8239 - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' end

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8238 - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' e

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8237 - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail`

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-8236 - Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-8139 - Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updat

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-7890 - In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7887 - For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A us

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 6.4
6.4

CVE-2026-7886 - Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] par

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-7882 - Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF to

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-7881 - Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express En

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-7879 - In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/d

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-6960 - The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil

🏢 Wordpress 📅 21.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-5091 - Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.1
5.1

CVE-2026-4929 - Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper out

🏢 Drupal 📅 21.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-4093 - In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter ren

🏢 Drupal 📅 21.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-22678 - Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template descr

🏢 Sonstige 📅 21.5.2026 📊 CVSS: 5.4
5.4
«« « Zurück Seite 115 von 115

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.