CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-48336 - Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code
CVE-2026-48335 - Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code
CVE-2026-48334 - Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary
CVE-2026-48312 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result
CVE-2026-48302 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result
CVE-2026-48298 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-48296 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-48295 - CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that co
CVE-2026-48290 - CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could
CVE-2026-48287 - CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in a
CVE-2026-48275 - Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary cod
CVE-2026-47732 - Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP s
CVE-2026-47730 - Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes
CVE-2026-46640 - Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dyn
CVE-2026-46639 - Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compi
CVE-2026-46638 - Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a templ
CVE-2026-46637 - Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twi
CVE-2026-46635 - Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP
CVE-2026-46634 - Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inn
CVE-2026-46633 - Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quot
CVE-2026-46629 - Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and
CVE-2026-46628 - Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered
CVE-2026-46627 - Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template f
CVE-2026-45363 - ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and
CVE-2026-42447 - jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerab
CVE-2026-42049 - jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an
CVE-2026-38450 - An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitra
CVE-2026-21840 - HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, t
CVE-2026-15750 - A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the fu
CVE-2025-56361 - A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifi
CVE-2026-61520 - Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-
CVE-2026-59889 - jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson
CVE-2026-53486 - The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction
CVE-2026-52101 - An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensit
CVE-2026-52100 - Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a
CVE-2026-49978 - DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DO
CVE-2026-49855 - Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip
CVE-2026-49854 - Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional
CVE-2026-49853 - Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHT
CVE-2026-49477 - Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the
CVE-2026-49476 - Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the
CVE-2026-49459 - DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DO
CVE-2026-49458 - DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DO
CVE-2026-48816 - sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @s
CVE-2026-48815 - sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, th
CVE-2026-48801 - linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.proto
CVE-2026-48758 - sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, th
CVE-2026-48370 - Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary cod
CVE-2026-48369 - Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code
CVE-2026-48367 - After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary cod
CVE-2026-48366 - Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary cod
CVE-2026-48344 - Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabil
CVE-2026-48343 - Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execu
CVE-2026-48342 - Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary
CVE-2026-48341 - Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execu
CVE-2026-48340 - Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary
CVE-2026-48339 - Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code
CVE-2026-48338 - ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav
CVE-2026-48332 - ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a
CVE-2026-48329 - ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Se
CVE-2026-48328 - ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security
CVE-2026-48327 - ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary co
CVE-2026-48325 - ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could re
CVE-2026-48324 - ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQ
CVE-2026-48322 - ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability
CVE-2026-48321 - ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege es
CVE-2026-48320 - ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could ex
CVE-2026-48319 - ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav
CVE-2026-48318 - ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Trav
CVE-2026-48311 - Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execu
CVE-2026-48308 - Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Securi
CVE-2026-48284 - ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary
CVE-2026-48274 - After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary cod
CVE-2026-48272 - Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could r
CVE-2026-48270 - Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code
CVE-2026-48269 - Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrar
CVE-2026-48125 - UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from us
CVE-2026-47979 - Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of se
CVE-2026-47976 - Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary cod
CVE-2026-47971 - Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitr
CVE-2026-47475 - NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacke
CVE-2026-47473 - NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condit
CVE-2026-47472 - NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attac
CVE-2026-47471 - NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an at
CVE-2026-47470 - NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint,
CVE-2026-46644 - Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functio
CVE-2026-24272 - NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based b
CVE-2026-24271 - NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attack
CVE-2026-24268 - NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow.
CVE-2026-24259 - NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authent
CVE-2026-24238 - NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of
CVE-2026-24234 - NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, w
CVE-2026-24233 - NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model we
CVE-2026-24229 - NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component,
CVE-2026-24227 - NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted
CVE-2026-24226 - NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper contro
CVE-2026-24220 - NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacke
CVE-2026-15778 - Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 al
CVE-2026-15777 - Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who
CVE-2026-15776 - Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacke
CVE-2026-15775 - Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacke
CVE-2026-15774 - Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had co
CVE-2026-15773 - Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker
CVE-2026-15772 - Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker
CVE-2026-15771 - Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.
CVE-2026-15770 - Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain
CVE-2026-15769 - Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior
CVE-2026-15768 - Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a
CVE-2026-15767 - Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote
CVE-2026-15766 - Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obta
CVE-2026-15765 - Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convi
CVE-2026-15764 - Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker
CVE-2026-15749 - A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue af
CVE-2026-15738 - Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Con
CVE-2026-15643 - AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that en
CVE-2026-53633 - Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vite
CVE-2026-50659 - Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov
CVE-2026-50651 - Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
CVE-2026-50650 - Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a
CVE-2026-50649 - Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50648 - Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack
CVE-2026-50646 - Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local
CVE-2026-50528 - Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a
CVE-2026-50527 - Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a
CVE-2026-50526 - Improper link resolution before file access ('link following') in .NET allows an authorized attacker
CVE-2026-50525 - Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
CVE-2026-50524 - Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to
CVE-2026-48784 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-48761 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-48760 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-48747 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-48736 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-48489 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-48371 - Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
CVE-2026-48359 - Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('X
CVE-2026-48358 - Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could re
CVE-2026-48356 - Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that
CVE-2026-48355 - Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could
CVE-2026-48350 - Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Travers
CVE-2026-48349 - Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
CVE-2026-48348 - Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
CVE-2026-48347 - Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Com
CVE-2026-48346 - Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code ex
CVE-2026-48345 - Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Com
CVE-2026-48310 - Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directo
CVE-2026-48263 - Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could
CVE-2026-48262 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48261 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48260 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48259 - Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that coul
CVE-2026-48257 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48255 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48254 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48253 - Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An att
CVE-2026-48252 - Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability
CVE-2026-48069 - @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. P
CVE-2026-48068 - @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. P
CVE-2026-48038 - joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1,
CVE-2026-48001 - Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited dis
CVE-2026-48000 - Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result i
CVE-2026-47999 - Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
CVE-2026-47998 - Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi
CVE-2026-47997 - Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi
CVE-2026-47996 - Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary
CVE-2026-47995 - Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
CVE-2026-47994 - Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused
CVE-2026-47992 - Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command
CVE-2026-47988 - Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi
CVE-2026-47984 - Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi
CVE-2026-47737 - Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vuln
CVE-2026-47736 - Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY p
CVE-2026-47482 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missin
CVE-2026-47481 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an aut
CVE-2026-47480 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an unc
CVE-2026-47479 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncont
CVE-2026-47478 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the us
CVE-2026-47477 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stac
CVE-2026-47476 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncont
CVE-2026-47429 - Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on
CVE-2026-47428 - Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Brow
CVE-2026-47423 - DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurif
CVE-2026-47212 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45071 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45068 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-15714 - An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw
CVE-2026-15713 - A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctl
CVE-2026-15711 - A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to
CVE-2026-15709 - A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension.
CVE-2026-15410 - Post-authentication improper control of generation of code ('Code Injection') vulnerability has been
CVE-2026-15409 - A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work
CVE-2026-13001 - The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to mi
CVE-2026-5040 - TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker wh
CVE-2026-47767 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-47305 - Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locall
CVE-2026-47304 - Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a
CVE-2026-47303 - Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to ele
CVE-2026-47302 - Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
CVE-2026-47301 - Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate
CVE-2026-47300 - Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker t
CVE-2026-45755 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45754 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45753 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-45305 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45304 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45133 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45075 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45073 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45072 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-45070 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45069 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-45064 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
CVE-2026-45063 - Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
CVE-2026-15720 - In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mob
CVE-2026-15712 - A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) H
CVE-2026-15642 - Insertion of sensitive information into a file in the Recovery Kit response file generation feature
CVE-2026-15641 - Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1
CVE-2026-15637 - Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server
CVE-2026-15058 - Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 202
CVE-2026-62659 - A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already l
CVE-2026-62658 - A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow some
CVE-2026-62657 - A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000
CVE-2026-62656 - A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send sp
CVE-2026-62655 - A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to ca
CVE-2026-58638 - Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security
CVE-2026-58637 - Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate
CVE-2026-58634 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-58633 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-58632 - Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-58629 - Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2026-58628 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-58627 - Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny ser
CVE-2026-58626 - Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over
CVE-2026-58619 - Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges lo
CVE-2026-58617 - Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate
CVE-2026-58613 - Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr
CVE-2026-58594 - Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a
CVE-2026-58547 - Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to el
CVE-2026-58546 - Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
CVE-2026-58545 - Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature
CVE-2026-58544 - Use after free in Windows Management Services allows an authorized attacker to elevate privileges lo
CVE-2026-58543 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-58542 - Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
CVE-2026-58541 - Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized at
CVE-2026-58540 - Improper authorization in Windows Installer allows an authorized attacker to elevate privileges loca
CVE-2026-58539 - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
CVE-2026-58538 - Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate pri
CVE-2026-58537 - Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to el
CVE-2026-58536 - Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate pr
CVE-2026-58535 - Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
CVE-2026-58534 - Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to e
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.