CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-79023 - Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-79022 - UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remo
CVE-2026-79021 - Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote att
CVE-2026-79020 - Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to pote
CVE-2026-79019 - Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote
CVE-2026-79018 - Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker t
CVE-2026-79017 - Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to by
CVE-2026-79016 - Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to o
CVE-2026-79015 - Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote
CVE-2026-79014 - Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had
CVE-2026-79013 - Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-79012 - Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote at
CVE-2026-79011 - UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le
CVE-2026-79010 - Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.
CVE-2026-79009 - UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leverag
CVE-2026-79008 - Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a rem
CVE-2026-79007 - Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who
CVE-2026-79006 - Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remo
CVE-2026-79005 - Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote
CVE-2026-79004 - Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who ha
CVE-2026-79003 - Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-79002 - Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote at
CVE-2026-79001 - Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote att
CVE-2026-79000 - Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 a
CVE-2026-78999 - Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote
CVE-2026-78991 - Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who h
CVE-2026-78990 - Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to e
CVE-2026-78989 - Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a
CVE-2026-78987 - Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypa
CVE-2026-78986 - Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who
CVE-2026-78985 - Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remot
CVE-2026-78984 - Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who
CVE-2026-78983 - Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co
CVE-2026-78981 - Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacke
CVE-2026-78980 - Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote att
CVE-2026-78979 - Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attack
CVE-2026-78978 - Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a
CVE-2026-78977 - Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote
CVE-2026-78976 - Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remo
CVE-2026-78975 - Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
CVE-2026-78974 - UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remo
CVE-2026-78969 - Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
CVE-2026-78968 - Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who
CVE-2026-78967 - Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker w
CVE-2026-78966 - Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote att
CVE-2026-78965 - Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
CVE-2026-78964 - Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker t
CVE-2026-78963 - Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-78962 - Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le
CVE-2026-78961 - Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker wh
CVE-2026-78960 - Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lev
CVE-2026-78959 - Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed
CVE-2026-78958 - Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who
CVE-2026-78957 - Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacke
CVE-2026-78956 - Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging so
CVE-2026-78955 - Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote a
CVE-2026-78954 - Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attac
CVE-2026-78953 - Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote atta
CVE-2026-78952 - Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remo
CVE-2026-78951 - Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
CVE-2026-78950 - Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to pote
CVE-2026-78949 - Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a
CVE-2026-78948 - Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execut
CVE-2026-78947 - Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lev
CVE-2026-78946 - Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-78945 - Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging
CVE-2026-78944 - Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leverag
CVE-2026-78943 - Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attack
CVE-2026-78942 - Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote at
CVE-2026-78941 - Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had c
CVE-2026-78940 - Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-78939 - Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who h
CVE-2026-78938 - Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar
CVE-2026-78937 - Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta
CVE-2026-78936 - Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a
CVE-2026-78935 - Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a
CVE-2026-78934 - Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker levera
CVE-2026-78915 - Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjace
CVE-2026-78914 - Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
CVE-2026-78913 - Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to po
CVE-2026-78912 - UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
CVE-2026-78911 - Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who
CVE-2026-78910 - Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute a
CVE-2026-78909 - Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging
CVE-2026-78908 - Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypa
CVE-2026-78907 - Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attac
CVE-2026-78906 - Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti
CVE-2026-78905 - Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti
CVE-2026-78904 - Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti
CVE-2026-78903 - Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacke
CVE-2026-78901 - Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar
CVE-2026-78900 - Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
CVE-2026-78899 - Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar
CVE-2026-78898 - Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attack
CVE-2026-78897 - Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacke
CVE-2026-78896 - Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attack
CVE-2026-78895 - Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypas
CVE-2026-78894 - Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had
CVE-2026-78893 - Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak s
CVE-2026-78892 - Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed
CVE-2026-78891 - Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execu
CVE-2026-77680 - An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after
CVE-2026-77357 - Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, ap
CVE-2026-75465 - The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Acce
CVE-2026-75421 - aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.
CVE-2026-72924 - GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the loca
CVE-2026-65105 - NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote att
CVE-2026-65099 - NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker
CVE-2026-65098 - NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at
CVE-2026-65097 - NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker co
CVE-2026-65096 - NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attack
CVE-2026-65093 - NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape.
CVE-2026-65092 - NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path tra
CVE-2026-65091 - NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS
CVE-2026-65090 - NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacke
CVE-2026-65089 - NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an
CVE-2026-65088 - NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using v
CVE-2026-65087 - NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected cred
CVE-2026-65086 - NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker c
CVE-2026-65085 - NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could
CVE-2026-65084 - NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker coul
CVE-2026-65083 - NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attack
CVE-2026-65082 - NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker
CVE-2026-65081 - NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker co
CVE-2026-55588 - ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORA
CVE-2026-53965 - The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In ve
CVE-2026-52491 - An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary
CVE-2026-52489 - Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to
CVE-2026-51368 - An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter comp
CVE-2026-39113 - Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil c
CVE-2026-77585 - The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH
CVE-2026-74932 - The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it
CVE-2026-68515 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-68514 - OpenEXR is the reference implementation and specification for the EXR image file format, widely used
CVE-2026-68513 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-66153 - The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux
CVE-2026-66152 - A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component al
CVE-2026-65367 - A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS
CVE-2026-64705 - A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and i
CVE-2026-59981 - OpenEXR is the reference implementation and specification for the EXR image file format, widely used
CVE-2026-55099 - icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 u
CVE-2026-45019 - Chainlit is a Python framework for building production-ready conversational AI applications. From 2.
CVE-2026-45018 - Chainlit is a Python framework for building production-ready conversational AI applications. From 2.
CVE-2026-43670 - A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. T
CVE-2026-43657 - A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and
CVE-2026-80050 - ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to mul
CVE-2026-80049 - Airbyte Platform resolves the workspace used for its authorization decision from a field the caller
CVE-2026-79788 - In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required
CVE-2026-79787 - Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configurat
CVE-2026-79786 - Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically va
CVE-2026-78379 - Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Ag
CVE-2026-65979 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-62986 - OpenEXR is the reference implementation and specification for the EXR image file format, widely used
CVE-2026-61555 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59985 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55663 - mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm packag
CVE-2026-55620 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-55619 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-55618 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-55609 - sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant s
CVE-2026-80051 - github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variabl
CVE-2026-79992 - A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing mal
CVE-2026-76198 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to
CVE-2026-76197 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a
CVE-2026-76195 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a
CVE-2026-76193 - Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that
CVE-2026-76189 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-75770 - Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-75769 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75768 - Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arb
CVE-2026-75767 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75766 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75752 - Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosu
CVE-2026-75750 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75749 - Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-71564 - Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi
CVE-2026-71444 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-71443 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result
CVE-2026-71442 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-71441 - Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sens
CVE-2026-71399 - Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code executio
CVE-2026-71382 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-71360 - CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could
CVE-2026-59984 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59983 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59982 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55637 - genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transp
CVE-2026-55623 - Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-55419 - Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exp
CVE-2026-48433 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48432 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48431 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48430 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48429 - Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in
CVE-2026-48428 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48427 - Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi
CVE-2026-48426 - Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi
CVE-2026-48425 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48424 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48423 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48422 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48421 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48420 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48419 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48418 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48417 - Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result i
CVE-2026-26211 - Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the log
CVE-2026-78468 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78270. Reason:
CVE-2026-75498 - Webkul QloApps does not validate request parameters before a database query. A remote, authenticated
CVE-2026-75497 - Webkul QloApps does not validate request parameters before a database query. A remote, authenticated
CVE-2026-75496 - Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before m
CVE-2026-64204 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-64203 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-64202 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-64201 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-59189 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59187 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59186 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59184 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55585 - QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, to
CVE-2026-55571 - djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe
CVE-2026-55557 - browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2,
CVE-2026-55553 - urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other re
CVE-2026-47626 - NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could
CVE-2026-47624 - NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privile
CVE-2026-24263 - NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could
CVE-2026-24262 - NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could
CVE-2026-24225 - NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be a
CVE-2026-24170 - NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where a
CVE-2026-24169 - NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated
CVE-2026-24168 - NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker
CVE-2026-24167 - NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authentica
CVE-2026-24166 - NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacke
CVE-2026-19913 - The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to
CVE-2026-19912 - The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vuln
CVE-2026-18445 - There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered i
CVE-2026-18444 - There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images
CVE-2026-16234 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-16233 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-13478 - The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ex
CVE-2026-13217 - The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the
CVE-2026-13216 - The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during dri
CVE-2026-79785 - X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anyla
CVE-2026-79784 - Vocos instantiates a class named by a configuration file without restricting which class may be name
CVE-2026-79783 - rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metada
CVE-2026-79782 - rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes sche
CVE-2026-79781 - rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read
CVE-2026-79780 - rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 re
CVE-2026-79779 - rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Ba
CVE-2026-79778 - rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware