CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-60415 - Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).
CVE-2026-60414 - Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Ou
CVE-2026-60413 - Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Ou
CVE-2026-60412 - Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Ou
CVE-2026-60393 - Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component
CVE-2026-60392 - Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Ou
CVE-2026-60391 - Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Serv
CVE-2026-56874 - Rejected reason: reserved but not needed
CVE-2026-56873 - Rejected reason: reserved but not needed
CVE-2026-56872 - Rejected reason: reserved but not needed
CVE-2026-56871 - Rejected reason: reserved but not needed
CVE-2026-56870 - Rejected reason: reserved but not needed
CVE-2026-56869 - Rejected reason: reserved but not needed
CVE-2026-56868 - Rejected reason: reserved but not needed
CVE-2026-56867 - Rejected reason: reserved but not needed
CVE-2026-55593 - Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php e
CVE-2026-55426 - linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integ
CVE-2026-54543 - Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API comma
CVE-2026-54348 - Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.upd
CVE-2026-54347 - Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accept
CVE-2026-53759 - linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integ
CVE-2026-53458 - Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.
CVE-2026-53457 - Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.
CVE-2026-53456 - Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.
CVE-2026-53455 - Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.
CVE-2026-53454 - Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.
CVE-2026-53453 - Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.
CVE-2026-52817 - Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems.
CVE-2026-52793 - Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path i
CVE-2026-41921 - Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in
CVE-2026-18504 - fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are
CVE-2026-16732 - fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 adde
CVE-2026-15571 - A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used
CVE-2026-12632 - Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c tak
CVE-2026-12631 - The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscal
CVE-2026-76032 - Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handl
CVE-2026-75936 - Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-jav
CVE-2026-75935 - Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 migh
CVE-2026-75877 - A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function Syst
CVE-2026-75876 - A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected
CVE-2026-73529 - Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that
CVE-2026-73112 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73111 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73106 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73105 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73104 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73103 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-71676 - Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of servi
CVE-2026-71675 - An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_
CVE-2026-71417 - Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a no
CVE-2026-71322 - Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePerm
CVE-2026-71317 - Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did
CVE-2026-71308 - Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit
CVE-2026-71307 - Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/desti
CVE-2026-71303 - Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_H
CVE-2026-70666 - Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_u
CVE-2026-67443 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the
CVE-2026-67440 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the
CVE-2026-65985 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the
CVE-2026-65984 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST
CVE-2026-59915 - Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violati
CVE-2026-57826 - An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verificatio
CVE-2026-52829 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can det
CVE-2026-52739 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can termi
CVE-2026-52738 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a
CVE-2026-52737 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer
CVE-2026-52736 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer ca
CVE-2026-52735 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd
CVE-2026-52734 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can caus
CVE-2026-52733 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced cha
CVE-2026-52732 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can mon
CVE-2026-52731 - ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enab
CVE-2026-52481 - An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensiti
CVE-2026-52480 - An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensiti
CVE-2026-49500 - Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resoluti
CVE-2026-47721 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/
CVE-2026-47720 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengi
CVE-2026-47719 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE
CVE-2026-19671 - Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth,
CVE-2026-19670 - Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may
CVE-2026-12520 - The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located
CVE-2026-70667 - Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificat
CVE-2026-65959 - Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /
CVE-2026-55166 - Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME
CVE-2026-55165 - Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:13
CVE-2026-55164 - Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replac
CVE-2026-55163 - Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:29
CVE-2026-55162 - Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Di
CVE-2026-47630 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an a
CVE-2026-47629 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause impr
CVE-2026-47628 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an a
CVE-2026-47627 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path
CVE-2026-47606 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an a
CVE-2026-24185 - NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configura
CVE-2026-24184 - NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon com
CVE-2026-24183 - NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivilege
CVE-2026-17106 - The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and th
CVE-2025-9211 - Unescaped stored values in application security page in Otalio Ship Property Management System versi
CVE-2025-9210 - Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions b
CVE-2021-43718 - An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could
CVE-2026-75625 - Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest be
CVE-2026-75130 - Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute ma
CVE-2026-74046 - Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() func
CVE-2026-74044 - Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster
CVE-2026-74039 - Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows auth
CVE-2026-74038 - Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote
CVE-2026-73502 - kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.Val
CVE-2026-71880 - Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions
CVE-2026-71879 - Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integr
CVE-2026-71878 - Missing authentication in initial setup functionality left exposed after initial setup is completed
CVE-2026-71551 - Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabil
CVE-2026-69160 - OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and
CVE-2026-68927 - MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities i
CVE-2026-68924 - MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobs
CVE-2026-68923 - MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py pl
CVE-2026-68922 - MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobs
CVE-2026-67921 - Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the Cor
CVE-2026-67920 - An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migr
CVE-2026-67846 - Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a pote
CVE-2026-67262 - Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped
CVE-2026-66780 - A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, whi
CVE-2026-63643 - MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR hand
CVE-2026-63642 - MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in de
CVE-2026-63641 - MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies i
CVE-2026-63640 - MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecret
CVE-2026-61696 - Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007b
CVE-2026-54570 - AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnota
CVE-2026-54552 - sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplet
CVE-2026-53533 - aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rc
CVE-2026-52610 - An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote at
CVE-2026-52609 - A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attacke
CVE-2026-52608 - An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attack
CVE-2026-52607 - A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or e
CVE-2026-50167 - Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.
CVE-2026-50161 - libre is a generic library for real-time communications with asynchronous input and output support.
CVE-2026-50143 - The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, craw
CVE-2026-49452 - WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped
CVE-2026-48508 - Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPer
CVE-2026-44472 - Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account ac
CVE-2026-32657 - Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRai
CVE-2026-18392 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2021-43717 - An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped
CVE-2021-43716 - Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20.
CVE-2026-75924 - A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole
CVE-2026-75897 - Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of t
CVE-2026-73372 - Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1
CVE-2026-73336 - Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Impr
CVE-2026-72531 - Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0
CVE-2026-71573 - Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An
CVE-2026-71572 - Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0
CVE-2026-70415 - Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC
CVE-2026-69220 - The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w
CVE-2026-69219 - The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w
CVE-2026-67271 - Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated
CVE-2026-66783 - A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for K
CVE-2026-66782 - A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-li
CVE-2026-66781 - A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuri
CVE-2026-63337 - The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w
CVE-2026-63336 - The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w
CVE-2026-63335 - The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w
CVE-2026-61634 - The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact w
CVE-2026-61574 - authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Con
CVE-2026-57580 - authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Sourc
CVE-2026-55106 - authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action o
CVE-2026-54730 - authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google
CVE-2026-52723 - ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to
CVE-2026-52606 - A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attacke
CVE-2026-50578 - ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to
CVE-2026-50577 - ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to
CVE-2026-50576 - ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to
CVE-2026-50126 - Adaguc-server is an open source geographical information system to visualize, combine, compare and s
CVE-2026-49228 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-49225 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-49224 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-49223 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-49222 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-48744 - Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authori
CVE-2026-30250 - Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW!
CVE-2026-19869 - @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication ru
CVE-2026-18963 - A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core
CVE-2026-75926 - Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code runnin
CVE-2026-75915 - CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_ex
CVE-2026-75914 - CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th
CVE-2026-75913 - CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection
CVE-2026-75912 - CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool t
CVE-2026-75911 - CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter f
CVE-2026-75904 - libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The
CVE-2026-75859 - CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions fiel
CVE-2026-75858 - CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code
CVE-2026-75857 - CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias
CVE-2026-75856 - CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning l
CVE-2026-75485 - A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes.
CVE-2026-73834 - A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes.
CVE-2026-73373 - Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 -
CVE-2026-73371 - Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-
CVE-2026-73337 - Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insuff
CVE-2026-73073 - Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autol
CVE-2026-72532 - Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.
CVE-2026-71574 - Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.
CVE-2026-71477 - mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archi
CVE-2026-71365 - A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechan
CVE-2026-63328 - Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager
CVE-2026-62684 - File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing
CVE-2026-62357 - Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.IN
CVE-2026-55839 - Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Mark
CVE-2026-49227 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-49226 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-49221 - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor
CVE-2026-47245 - MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List componen
CVE-2026-46482 - ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA c
CVE-2026-45734 - MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consiste
CVE-2026-45129 - MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module doe
CVE-2026-45128 - MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does
CVE-2026-45127 - MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not vali
CVE-2026-45126 - MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module
CVE-2026-45125 - MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not san
CVE-2026-45124 - MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not chec
CVE-2026-45123 - MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not c
CVE-2026-45122 - MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate
CVE-2026-45121 - MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check per
CVE-2026-45120 - MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify pr
CVE-2026-45119 - MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module d
CVE-2026-45118 - MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a
CVE-2026-45117 - MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not
CVE-2026-45116 - MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly
CVE-2026-45115 - MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sa
CVE-2026-19501 - CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize sprea
CVE-2026-19500 - The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adeq
CVE-2026-15806 - The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWit
CVE-2026-12564 - A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() fu
CVE-2026-75898 - RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "In
CVE-2026-75890 - Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that a
CVE-2026-75872 - HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticat
CVE-2026-75784 - A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the functio
CVE-2026-75032 - A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems respons
CVE-2026-74015 - Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-74012 - Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue af
CVE-2026-74009 - Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versio
CVE-2026-74008 - Insertion of Sensitive Information Into Sent Data vulnerability in Averta LTD Shortcodes and extra f
CVE-2026-74007 - Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery
CVE-2026-74006 - Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
CVE-2026-74004 - Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <
CVE-2026-74003 - Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
CVE-2026-73997 - Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
CVE-2026-73996 - Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
CVE-2026-73995 - Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
CVE-2026-73994 - Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
CVE-2026-73426 - Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix
CVE-2026-73404 - Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-73400 - Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware