CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-14564 - Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consul
CVE-2026-74843 - A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerabilit
CVE-2026-40126 - OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be
CVE-2026-74901 - openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where
CVE-2026-74900 - openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsula
CVE-2026-74899 - openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecut
CVE-2026-74896 - openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPattern
CVE-2026-74895 - openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isol
CVE-2026-74894 - openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token
CVE-2026-74893 - openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py tha
CVE-2026-74892 - openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telem
CVE-2026-74891 - openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server co
CVE-2026-74890 - openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCiph
CVE-2026-74889 - openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normali
CVE-2026-74888 - openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with ite
CVE-2026-74887 - openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PR
CVE-2026-74886 - openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the Plugin
CVE-2026-74885 - openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs mo
CVE-2026-74884 - openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path me
CVE-2026-74883 - openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo
CVE-2026-74882 - openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti
CVE-2026-74881 - openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_cr
CVE-2026-74880 - openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and
CVE-2026-74879 - openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready
CVE-2026-74878 - openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection
CVE-2026-74877 - openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the
CVE-2026-74876 - openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that cr
CVE-2026-74875 - openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra
CVE-2026-74874 - openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi
CVE-2026-74873 - openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in pro
CVE-2026-74872 - openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl
CVE-2026-74871 - openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mo
CVE-2026-74870 - openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm
CVE-2026-74869 - stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message hand
CVE-2026-74868 - SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service
CVE-2026-74867 - SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cooki
CVE-2026-74842 - A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452.
CVE-2026-74802 - SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl
CVE-2026-74801 - SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin
CVE-2026-74800 - SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin
CVE-2026-74799 - SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w
CVE-2026-74798 - SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool.
CVE-2026-74845 - Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulner
CVE-2026-58561 - Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vu
CVE-2026-58560 - Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vu
CVE-2026-49308 - Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vu
CVE-2026-49307 - Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of
CVE-2026-49306 - UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerab
CVE-2026-49305 - Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of
CVE-2026-49304 - Permission control vulnerability in the device key management module. Impact: Successful exploitatio
CVE-2026-49303 - Permission control vulnerability in the notification module. Impact: Successful exploitation of this
CVE-2026-49302 - Permission control vulnerability in the notification service module. Impact: Successful exploitation
CVE-2026-49301 - Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vuln
CVE-2026-20000 - A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is
CVE-2026-19999 - A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The a
CVE-2026-19998 - A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown f
CVE-2026-22072 - Loading arbitrary external URLs through WebView components introduces malicious JS code that can ste
CVE-2026-19997 - A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown p
CVE-2026-19996 - A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown cod
CVE-2026-19995 - A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi
CVE-2026-19994 - A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown func
CVE-2026-15623 - A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chroni
CVE-2026-74579 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mas
CVE-2026-19993 - A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u
CVE-2026-19992 - A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up
CVE-2026-19988 - A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the f
CVE-2026-19987 - A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. Th
CVE-2026-14832 - The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorizat
CVE-2026-13700 - The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a s
CVE-2026-19986 - A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted
CVE-2026-19984 - A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the functio
CVE-2026-19983 - A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE
CVE-2026-19982 - A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability af
CVE-2026-19981 - A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE
CVE-2026-19980 - A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930
CVE-2026-19979 - A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE
CVE-2026-19978 - A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292
CVE-2026-50602 - A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned t
CVE-2026-50601 - A security vulnerability has been identified in the Planet9 desktop application where a hardcoded re
CVE-2026-19977 - A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function http
CVE-2026-19976 - A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_
CVE-2026-19975 - A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transfer
CVE-2026-19974 - A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulne
CVE-2026-19973 - A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerabi
CVE-2026-19972 - A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknow
CVE-2026-19971 - A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-
CVE-2026-19970 - A vulnerability was detected in Open Asset Import Library Assimp 17c12da. This affects the function
CVE-2026-19969 - A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted
CVE-2026-19968 - A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is
CVE-2026-19967 - A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the fun
CVE-2026-19966 - A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affe
CVE-2026-19965 - A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the functi
CVE-2026-19964 - A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run
CVE-2026-19963 - A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function sta
CVE-2026-19962 - A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setW
CVE-2026-19961 - A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of
CVE-2026-19960 - A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function form
CVE-2026-19959 - A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu
CVE-2026-19958 - A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the fun
CVE-2026-19957 - A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetc
CVE-2026-19956 - A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is
CVE-2026-19955 - A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.
CVE-2026-74797 - OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command w
CVE-2026-74796 - OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during in
CVE-2026-74795 - Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parse
CVE-2026-74794 - Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the Objec
CVE-2026-74792 - Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested
CVE-2026-74791 - Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is c
CVE-2026-74790 - Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change
CVE-2026-74789 - Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statem
CVE-2026-74788 - Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnera
CVE-2026-74787 - Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin
CVE-2026-74786 - Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in whic
CVE-2026-74785 - Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluat
CVE-2026-74784 - Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that
CVE-2026-74783 - Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails t
CVE-2026-73062 - Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multipli
CVE-2026-73061 - Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al
CVE-2026-73060 - Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRan
CVE-2026-73059 - stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that c
CVE-2026-73058 - stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blockli
CVE-2026-73057 - stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing att
CVE-2026-73056 - SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte
CVE-2026-72888 - Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed mod
CVE-2026-72887 - Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OA
CVE-2026-19349 - Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 befo
CVE-2024-58375 - OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when u
CVE-2026-74251 - Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.
CVE-2026-74578 - In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force
CVE-2024-13784 - The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to
CVE-2026-2497 - The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_ord
CVE-2026-2357 - The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug
CVE-2026-18347 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-17608 - The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cro
CVE-2026-17604 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-17087 - The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerab
CVE-2026-13424 - The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to
CVE-2026-12998 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-10734 - The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_recor
CVE-2026-9767 - The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic S
CVE-2026-2283 - The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' paramet
CVE-2026-19934 - A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unkno
CVE-2026-19728 - The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify th
CVE-2026-19726 - The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuratio
CVE-2026-19725 - The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value
CVE-2026-19717 - The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisat
CVE-2026-19714 - The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google ide
CVE-2026-19712 - The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before ou
CVE-2026-19711 - The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against t
CVE-2026-19613 - The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of
CVE-2026-18653 - The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before u
CVE-2026-18402 - The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cr
CVE-2026-18316 - The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data du
CVE-2026-17582 - The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to,
CVE-2026-17581 - The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code In
CVE-2026-17533 - The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration
CVE-2026-16775 - The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulne
CVE-2026-16758 - The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortco
CVE-2026-15790 - The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u
CVE-2026-15604 - The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions
CVE-2026-15384 - The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce ve
CVE-2026-15351 - The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPr
CVE-2026-15345 - The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnera
CVE-2026-15056 - The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin
CVE-2026-13712 - The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow modul
CVE-2026-10035 - The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all
CVE-2026-19933 - A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0.
CVE-2026-19932 - A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects
CVE-2026-18432 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all v
CVE-2026-18385 - The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri
CVE-2026-17123 - The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in vers
CVE-2026-16779 - The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions
CVE-2026-16099 - The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to i
CVE-2026-16098 - The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all version
CVE-2026-16079 - The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attri
CVE-2026-15963 - The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to
CVE-2026-15726 - The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Sho
CVE-2026-15602 - The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQ
CVE-2026-15441 - The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and
CVE-2026-15066 - The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Ext
CVE-2026-15009 - The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin
CVE-2026-15002 - The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-14524 - The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insuf
CVE-2026-14498 - The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to
CVE-2026-13358 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress
CVE-2026-13167 - The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin fo
CVE-2026-12905 - The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to,
CVE-2026-12477 - The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Store
CVE-2026-11780 - The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to
CVE-2025-10005 - The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul
CVE-2026-2487 - The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s
CVE-2026-19930 - A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the
CVE-2026-19929 - A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplat
CVE-2026-19928 - A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of th
CVE-2026-19927 - A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of t
CVE-2026-19926 - A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected el
CVE-2026-19925 - A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some
CVE-2026-19924 - A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability
CVE-2026-19923 - A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown
CVE-2026-19922 - A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this is
CVE-2026-19921 - A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnera
CVE-2026-19920 - A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown f
CVE-2026-19919 - A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct
CVE-2026-19918 - A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects th
CVE-2026-19917 - A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unkn
CVE-2026-74767 - Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) fi
CVE-2026-74764 - Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When pr
CVE-2026-73055 - Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in ass
CVE-2026-73054 - SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoi
CVE-2026-73053 - SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func
CVE-2026-73052 - SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d
CVE-2026-73050 - SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op
CVE-2026-73047 - siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in
CVE-2026-73046 - SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl
CVE-2026-73045 - SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerabil
CVE-2026-73044 - SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored
CVE-2026-73043 - SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat
CVE-2026-73042 - SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing
CVE-2026-73041 - SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se
CVE-2026-19916 - A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is
CVE-2026-19906 - A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the func
CVE-2026-19905 - A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS
CVE-2026-18855 - The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f
CVE-2026-19904 - A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects
CVE-2026-19903 - A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown
CVE-2026-19901 - A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown functi
CVE-2026-19598 - The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalatio
CVE-2026-19900 - A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown
CVE-2026-19899 - A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected
CVE-2026-19898 - A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler
CVE-2026-19897 - A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login
CVE-2026-19896 - A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_
CVE-2026-19895 - A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects th
CVE-2026-19474 - @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not
CVE-2026-18549 - @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not
CVE-2026-18500 - @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verifi
CVE-2026-18165 - @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8
CVE-2026-15689 - Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisonin
CVE-2026-74577 - In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_tos i
CVE-2026-74576 - In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded recu
CVE-2026-74575 - In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain de
CVE-2026-74574 - In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup
CVE-2026-74573 - In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Requ
CVE-2026-74572 - In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock betw
CVE-2026-74571 - In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserv
CVE-2026-74570 - In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc si
CVE-2026-74569 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: wi
CVE-2026-74568 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race betw
CVE-2026-74567 - In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in
CVE-2026-74566 - In the Linux kernel, the following vulnerability has been resolved: keys: make keyring key-chunk by
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware