CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-44019 - Docling Core defines core data types and transformations for the document processing application Doc
CVE-2026-38158 - A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 all
CVE-2026-36425 - An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x242
CVE-2026-33731 - WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook h
CVE-2026-33692 - WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenti
CVE-2026-11889 - SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a pri
CVE-2024-34268 - EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was
CVE-2024-32389 - Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 al
CVE-2024-32387 - An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacke
CVE-2024-32386 - Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_2020080313204
CVE-2024-32385 - An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacke
CVE-2026-63397 - remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL sch
CVE-2026-63089 - WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time l
CVE-2026-62994 - CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to requ
CVE-2026-62963 - Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidire
CVE-2026-62309 - CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the
CVE-2026-62299 - CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 re
CVE-2026-62290 - cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and
CVE-2026-61718 - bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6
CVE-2026-61389 - An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger k
CVE-2026-60140 - An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger ke
CVE-2026-60063 - An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger k
CVE-2026-55629 - Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/servic
CVE-2026-54728 - bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1
CVE-2026-49998 - Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic
CVE-2026-44982 - CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/re
CVE-2026-44981 - CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI rout
CVE-2026-15449 - A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects ha
CVE-2026-15422 - The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately val
CVE-2026-15352 - A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). T
CVE-2026-54526 - Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on
CVE-2026-53536 - Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/
CVE-2026-53535 - Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync featur
CVE-2026-47089 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to us
CVE-2026-47088 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in neste
CVE-2026-47087 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked
CVE-2026-47086 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can by
CVE-2026-47085 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur
CVE-2026-47084 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypasse
CVE-2026-47083 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user
CVE-2026-47082 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skip
CVE-2026-47081 - An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE f
CVE-2026-46515 - Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was
CVE-2026-46514 - Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in
CVE-2026-46513 - Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API t
CVE-2026-46512 - Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply ac
CVE-2026-46404 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation
CVE-2026-46378 - Dasel is a command-line tool and library for querying, modifying, and transforming data structures.
CVE-2026-46377 - Dasel is a command-line tool and library for querying, modifying, and transforming data structures.
CVE-2026-46353 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation coul
CVE-2026-46351 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference ses
CVE-2026-46338 - PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 unti
CVE-2026-46687 - Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing inter
CVE-2026-46686 - Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user searc
CVE-2026-46341 - The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, craw
CVE-2026-46336 - Manyfold is an open source, self-hosted web application for managing a collection of 3d models, part
CVE-2026-45336 - HireFlow is a web-based interview management system for managing candidates, scheduling interviews,
CVE-2026-44970 - dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTr
CVE-2026-44969 - dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_to
CVE-2026-44968 - dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_comma
CVE-2026-15945 - A flaw was found in the group search functionality of the Keycloak server's administrative API. When
CVE-2026-15737 - AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for bui
CVE-2021-27137 - An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UP
CVE-2026-9046 - A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store
CVE-2026-6511 - During an internal security assessment, a potential improper access control vulnerability was discov
CVE-2026-63088 - stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unau
CVE-2026-63087 - Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote a
CVE-2026-63086 - text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability
CVE-2026-63085 - Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that
CVE-2026-57074 - XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse f
CVE-2026-57073 - HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse
CVE-2026-55548 - Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpo
CVE-2026-55407 - Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Pri
CVE-2026-55406 - Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Pri
CVE-2026-50012 - Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache
CVE-2026-47751 - Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests
CVE-2026-47729 - Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic corre
CVE-2026-46621 - Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python
CVE-2026-46562 - Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate use
CVE-2026-45795 - The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0,
CVE-2026-45612 - rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in sr
CVE-2026-45576 - zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `z
CVE-2026-45568 - zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Pyth
CVE-2026-45367 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J
CVE-2026-45325 - Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.034
CVE-2026-44632 - Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability ex
CVE-2026-44596 - Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token
CVE-2026-44595 - Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, lis
CVE-2026-3031 - Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image
CVE-2026-14371 - The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on th
CVE-2026-13401 - XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attrib
CVE-2026-13397 - HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attri
CVE-2026-13104 - A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese m
CVE-2026-13103 - A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively i
CVE-2026-10590 - A potential missing authentication vulnerability could allow a local privileged attacker to use WMI
CVE-2026-10589 - A potential out of bounds write vulnerability could allow a local privileged attacker to execute cod
CVE-2026-10588 - A potential vulnerability could allow a local privileged attacker to disclose the address of protect
CVE-2026-10587 - A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify powe
CVE-2025-45870 - LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOf
CVE-2026-63082 - Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control
CVE-2026-63081 - Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scri
CVE-2026-59867 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref v
CVE-2026-59866 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info
CVE-2026-59865 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-
CVE-2026-59864 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota
CVE-2026-57206 - SimpleChat is a secure AI conversation application with personal and group workspaces for document-g
CVE-2026-57205 - SimpleChat is a secure AI conversation application with personal and group workspaces for document-g
CVE-2026-55440 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t
CVE-2026-54733 - The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Dire
CVE-2026-54568 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.
CVE-2026-53598 - Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders
CVE-2026-53597 - Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3,
CVE-2026-45695 - Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, c
CVE-2026-14890 - SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable netw
CVE-2026-12379 - An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of t
CVE-2025-45868 - LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonSer
CVE-2026-59863 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kio
CVE-2026-59862 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let
CVE-2026-59861 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedd
CVE-2026-59860 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-g
CVE-2026-59859 - Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedde
CVE-2026-59237 - Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API contr
CVE-2026-14254 - A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout thre
CVE-2026-5674 - A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape s
CVE-2026-56456 - HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dash
CVE-2026-56455 - HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service
CVE-2026-56454 - HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TL
CVE-2026-56453 - HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remot
CVE-2026-35145 - HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The a
CVE-2026-35143 - HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to
CVE-2026-35142 - HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application inc
CVE-2026-35141 - HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote
CVE-2026-35140 - HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnera
CVE-2026-9494 - An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advan
CVE-2026-63306 - stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the
CVE-2026-63305 - AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint w
CVE-2026-63304 - AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/function
CVE-2026-12391 - An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-a
CVE-2026-11386 - An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubun
CVE-2025-71388 - stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChanne
CVE-2025-71377 - stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages rou
CVE-2024-58360 - stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only
CVE-2026-59249 - Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint
CVE-2026-35149 - HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation
CVE-2026-35148 - HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that
CVE-2026-35147 - HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The applic
CVE-2026-35146 - HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits use
CVE-2023-49900 - An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanit
CVE-2023-49899 - An unauthenticated remote attacker can execute any command on the affected device due to not correct
CVE-2026-22752 - Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Serv
CVE-2026-7543 - The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' pa
CVE-2026-6424 - Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kerne
CVE-2026-6423 - A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused
CVE-2026-58078 - Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 -
CVE-2026-15727 - The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_
CVE-2026-15651 - The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the
CVE-2026-15610 - The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulner
CVE-2026-15407 - The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to
CVE-2026-15350 - The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up t
CVE-2026-15324 - The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress
CVE-2026-15106 - The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulner
CVE-2026-15103 - The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress
CVE-2026-15099 - The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ste
CVE-2026-15022 - The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic S
CVE-2026-15021 - The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Pr
CVE-2026-15008 - The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for
CVE-2026-15005 - The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
CVE-2026-13767 - The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data i
CVE-2026-13755 - The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site S
CVE-2026-13754 - The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injecti
CVE-2026-13741 - The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege
CVE-2026-15925 - Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.1
CVE-2026-12979 - The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleti
CVE-2026-12978 - The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before ref
CVE-2026-12907 - The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -b
CVE-2026-12906 - The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX acti
CVE-2026-12869 - The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administra
CVE-2026-12684 - The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication
CVE-2026-12585 - The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity
CVE-2026-12525 - The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be wri
CVE-2026-12510 - The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversati
CVE-2026-12492 - The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-ti
CVE-2026-12395 - The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter b
CVE-2026-11866 - The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on seve
CVE-2026-11371 - The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summar
CVE-2026-53366 - In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on th
CVE-2026-15458 - The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' par
CVE-2026-15445 - The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' par
CVE-2026-15306 - The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is
CVE-2026-15013 - The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via
CVE-2026-13042 - The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con
CVE-2026-21729 - Loki queries with large limits can cause large memory allocations which can impact the availability
CVE-2026-15652 - The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerab
CVE-2026-15336 - The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions
CVE-2026-14987 - The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored C
CVE-2026-13005 - The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Sto
CVE-2026-12941 - The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is
CVE-2026-12753 - The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable t
CVE-2026-12434 - The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all
CVE-2026-12409 - The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages pl
CVE-2026-48863 - A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verificat
CVE-2026-3842 - A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine
CVE-2026-23538 - A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote
CVE-2026-1609 - A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is e
CVE-2026-15909 - A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3a
CVE-2026-15907 - A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of
CVE-2026-63175 - PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level vari
CVE-2026-62314 - Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream
CVE-2026-55652 - Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED
CVE-2026-55576 - MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow,
CVE-2026-55445 - Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript.
CVE-2026-55234 - Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server
CVE-2026-54458 - WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site
CVE-2026-53447 - Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in
CVE-2026-53446 - Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in mode
CVE-2026-53445 - Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method
CVE-2026-53444 - Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in p
CVE-2026-52893 - Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook i
CVE-2026-52892 - Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/c
CVE-2026-52891 - Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embe
CVE-2026-52890 - Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member
CVE-2026-50183 - WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Sc
CVE-2026-50182 - WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Refl
CVE-2026-49279 - WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerabi
CVE-2026-48795 - AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisj
CVE-2026-45313 - Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiS
CVE-2026-38974 - Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.p
CVE-2026-38755 - A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to c
CVE-2026-38754 - A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to ca
CVE-2026-38752 - A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attacker
CVE-2026-36590 - An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qo
CVE-2026-30623 - LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functional
CVE-2026-30618 - xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management a
CVE-2026-26719 - Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbi
CVE-2026-26718 - A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.
CVE-2026-15921 - Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js version
CVE-2025-65720 - An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a vi
CVE-2026-62361 - listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk
CVE-2026-62312 - 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacke
CVE-2026-59950 - The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MC
CVE-2026-56679 - 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the e
CVE-2026-56678 - 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /ap
CVE-2026-55608 - n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, a
CVE-2026-55410 - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris
CVE-2026-55399 - CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55.
CVE-2026-55398 - CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14
CVE-2026-54052 - n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, a
CVE-2026-52888 - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris
CVE-2026-52887 - NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris
CVE-2026-51380 - Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a p
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.