CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-49795 - Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49794 - Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker
CVE-2026-49793 - Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to
CVE-2026-49792 - Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to ex
CVE-2026-49791 - Improper link resolution before file access ('link following') in Windows Routing and Remote Access
CVE-2026-49790 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-49789 - Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges loca
CVE-2026-49788 - Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to de
CVE-2026-49787 - Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized atta
CVE-2026-49784 - Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
CVE-2026-49783 - Improperly implemented security check for standard in Windows Secure Boot allows an authorized attac
CVE-2026-49184 - Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-49183 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-49181 - Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to ele
CVE-2026-49180 - Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll)
CVE-2026-49178 - Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec
CVE-2026-49176 - Improper privilege management in Windows WalletService allows an authorized attacker to elevate priv
CVE-2026-49175 - Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locall
CVE-2026-49174 - Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker
CVE-2026-49173 - Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49172 - Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov
CVE-2026-49171 - Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local
CVE-2026-49170 - Insufficient granularity of access control in Windows StateRepository API allows an authorized attac
CVE-2026-49169 - Use after free in DNS Server allows an authorized attacker to execute code over a network.
CVE-2026-49168 - Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e
CVE-2026-49167 - Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-49166 - Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges loca
CVE-2026-49165 - Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo
CVE-2026-49164 - Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex
CVE-2026-49162 - Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege
CVE-2026-48581 - Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to ele
CVE-2026-48572 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-48571 - Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-48564 - Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over
CVE-2026-48561 - Improper neutralization of special elements used in a command ('command injection') in Copilot Chat
CVE-2026-47632 - Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate pr
CVE-2026-47296 - Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
CVE-2026-47282 - Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized
CVE-2026-45646 - Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker
CVE-2026-45496 - Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code
CVE-2026-44806 - Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unaut
CVE-2026-44800 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-42990 - Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code
CVE-2026-42982 - Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized a
CVE-2026-42975 - Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu
CVE-2026-42900 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-41087 - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
CVE-2026-40422 - Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose inf
CVE-2026-40400 - Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n
CVE-2026-40378 - Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (L
CVE-2026-36214 - osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS
CVE-2026-34349 - Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized att
CVE-2026-34348 - Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to discl
CVE-2026-34346 - Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all
CVE-2026-34328 - Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an author
CVE-2026-33842 - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
CVE-2026-15703 - A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulner
CVE-2026-15702 - A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateC
CVE-2026-15701 - A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is
CVE-2026-15700 - A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the functi
CVE-2026-15429 - A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v
CVE-2026-15428 - An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitizat
CVE-2026-15427 - An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1
CVE-2026-14646 - Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP
CVE-2026-14645 - Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configure
CVE-2026-9636 - A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules
CVE-2026-9292 - A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. T
CVE-2026-9128 - A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search
CVE-2026-9127 - A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect au
CVE-2026-9108 - A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation
CVE-2026-7494 - Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retri
CVE-2026-62644 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webm
CVE-2026-62643 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS)
CVE-2026-62642 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TN
CVE-2026-62641 - In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of
CVE-2026-60119 - Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated atta
CVE-2026-60118 - Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that all
CVE-2026-60082 - DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When t
CVE-2026-60081 - DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column
CVE-2026-59841 - A improper restriction of communication channel to intended endpoints vulnerability in Fortinet Fort
CVE-2026-59840 - A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.
CVE-2026-59839 - A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo
CVE-2026-59837 - A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all
CVE-2026-59836 - A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, Fort
CVE-2026-59835 - A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, F
CVE-2026-59205 - Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, i
CVE-2026-59204 - Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumul
CVE-2026-59203 - Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImageP
CVE-2026-59199 - Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger
CVE-2026-59198 - Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its
CVE-2026-58461 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-55954 - Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover
CVE-2026-55651 - Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposu
CVE-2026-52841 - Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth
CVE-2026-52840 - Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::conne
CVE-2026-52839 - Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter p
CVE-2026-52838 - Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrato
CVE-2026-23573 - An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
CVE-2026-15699 - A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function
CVE-2026-15698 - A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/update
CVE-2026-15697 - A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on o
CVE-2026-15392 - DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrust
CVE-2026-14504 - An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/b
CVE-2026-12707 - Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to un
CVE-2026-12659 - A denial-of-service security issue exists in the affected products. The security issue stems from im
CVE-2026-12523 - Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (
CVE-2026-11944 - openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging s
CVE-2026-11917 - A path traversal security issue exists within Rockwell Automation ThinManager® software due to impro
CVE-2026-11403 - A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow
CVE-2025-62826 - An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili
CVE-2025-62675 - An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili
CVE-2025-53379 - A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenti
CVE-2025-43892 - A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.
CVE-2025-11698 - A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.07
CVE-2026-9653 - A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication modul
CVE-2026-9140 - A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper
CVE-2026-8590 - Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterpris
CVE-2026-60114 - Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability
CVE-2026-58479 - Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerabil
CVE-2026-58478 - Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery
CVE-2026-58477 - Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerabilit
CVE-2026-58476 - Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery v
CVE-2026-58475 - Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting
CVE-2026-52837 - Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the
CVE-2026-51105 - Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a den
CVE-2026-15736 - Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: I
CVE-2026-15696 - A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function f
CVE-2026-15695 - A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpLi
CVE-2026-15694 - A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind o
CVE-2026-15265 - A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged atta
CVE-2026-14903 - Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker t
CVE-2026-14902 - An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacke
CVE-2026-10714 - A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass
CVE-2026-10672 - subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static
CVE-2026-10671 - In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kerne
CVE-2026-10670 - The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_
CVE-2026-10669 - On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xte
CVE-2026-10573 - A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from i
CVE-2025-12012 - A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially
CVE-2025-12011 - A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially all
CVE-2026-53566 - Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affe
CVE-2026-15693 - A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the fun
CVE-2026-8314 - A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the sim
CVE-2026-8313 - A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the lin
CVE-2026-8312 - A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the exp
CVE-2026-8085 - A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the mod
CVE-2026-62393 - Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper
CVE-2026-62392 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
CVE-2026-62390 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-53565 - Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citri
CVE-2026-49488 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-15719 - We are aware that exploit code for this is public however we are not aware of any attacks in the wil
CVE-2026-15718 - We are aware that exploit code for this is public however we are not aware of any attacks in the wil
CVE-2026-15692 - A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the functio
CVE-2026-15691 - A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSaf
CVE-2026-15305 - Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload e
CVE-2026-12588 - An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to t
CVE-2026-10577 - A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a ne
CVE-2026-9341 - The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulne
CVE-2026-15690 - A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function resp
CVE-2026-62422 - In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.14843
CVE-2026-15389 - A vulnerability relating to insufficient access control has been identified in the session managemen
CVE-2026-58319 - Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication.
CVE-2026-56451 - A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do n
CVE-2026-54429 - A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices d
CVE-2026-3014 - Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix s
CVE-2026-15043 - DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on tex
CVE-2026-14852 - Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2
CVE-2026-12478 - The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside t
CVE-2025-40945 - A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All
CVE-2026-9561 - Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the au
CVE-2026-8384 - In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an
CVE-2026-6790 - In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request
CVE-2026-59246 - Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 serv
CVE-2026-59084 - Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure
CVE-2026-59083 - Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo
CVE-2026-58229 - Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server
CVE-2026-57898 - In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments usin
CVE-2026-15416 - A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could all
CVE-2026-15183 - Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) version
CVE-2026-15076 - In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession com
CVE-2026-15075 - In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRe
CVE-2026-13699 - In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to v
CVE-2026-12606 - Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed tra
CVE-2026-10051 - In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in
CVE-2025-8412 - A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtu
CVE-2024-7708 - For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer
CVE-2026-6851 - An Improper link resolution before file access ('link following') vulnerability in the File Shredder
CVE-2026-59674 - A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allow
CVE-2026-15678 - A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an u
CVE-2026-15677 - A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown funct
CVE-2026-15676 - A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted eleme
CVE-2026-15675 - A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an un
CVE-2026-15672 - A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown
CVE-2026-15669 - A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.
CVE-2026-12988 - The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during t
CVE-2026-12583 - The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input tha
CVE-2026-12511 - The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using
CVE-2026-12482 - A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archi
CVE-2026-11567 - The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms
CVE-2026-11563 - The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file
CVE-2025-15665 - The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the
CVE-2026-15668 - A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the funct
CVE-2026-15629 - A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill
CVE-2026-15628 - A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue a
CVE-2026-15627 - A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability af
CVE-2026-15626 - A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function w
CVE-2026-7640 - The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type
CVE-2026-15625 - A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function
CVE-2026-15624 - A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerabil
CVE-2026-15622 - A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file
CVE-2026-11802 - The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Author
CVE-2026-11390 - The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-58233 - SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a
CVE-2026-44771 - SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated use
CVE-2026-44770 - SAP Create Single Payment does not perform necessary authorization checks for an authenticated user,
CVE-2026-44769 - SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to exec
CVE-2026-44768 - SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of th
CVE-2026-44767 - setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled abs
CVE-2026-44761 - SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials o
CVE-2026-44760 - Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages frame
CVE-2026-44759 - SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into
CVE-2026-44753 - SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted
CVE-2026-44752 - SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScr
CVE-2026-44747 - SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in
CVE-2026-44745 - SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under
CVE-2026-27690 - Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could s
CVE-2026-15621 - A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/wr
CVE-2026-15620 - A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the functio
CVE-2026-0487 - SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from a
CVE-2026-15619 - A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function
CVE-2026-15618 - A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the fun
CVE-2026-58489 - HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the
CVE-2026-58486 - HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1
CVE-2026-58102 - Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certi
CVE-2026-58101 - Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer derefer
CVE-2026-57856 - Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/
CVE-2026-57855 - Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/b
CVE-2026-15607 - A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the funct
CVE-2026-15605 - A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactMa
CVE-2026-62328 - 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that
CVE-2026-62327 - 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that
CVE-2026-62242 - Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allo
CVE-2026-62240 - CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url functi
CVE-2026-62239 - FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability
CVE-2026-62200 - OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow
CVE-2026-62199 - OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss in
CVE-2026-62198 - OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native
CVE-2026-62197 - OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accept
CVE-2026-62196 - OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where What
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.