CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-72539 - An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authent
CVE-2026-72538 - An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to
CVE-2026-72537 - A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta
CVE-2026-72536 - A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo
CVE-2026-72535 - A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo
CVE-2026-72534 - A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta
CVE-2026-72533 - An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privi
CVE-2026-50237 - A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog
CVE-2026-50236 - An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supp
CVE-2026-13739 - A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF)
CVE-2026-13738 - CommServe contained an authorization bypass vulnerability affecting a limited set of command executi
CVE-2026-13737 - CommServe contained an allowlist bypass vulnerability affecting command execution authorization. So
CVE-2026-58231 - SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and s
CVE-2026-73162 - Affected versions of MISP cti-transmute expose several state-changing account operations as GET requ
CVE-2026-33922 - A path traversal vulnerability was discovered in the Offline archives functionality of the local web
CVE-2026-33921 - The Windows installer deployed Npcap leaving its access restriction option at the insecure default v
CVE-2026-73161 - Affected versions of cti-transmute improperly handle conversion-table values passed through the sear
CVE-2026-73160 - Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_
CVE-2026-73159 - Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into
CVE-2026-73158 - Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph con
CVE-2026-73157 - Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-b
CVE-2026-72694 - A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops priv
CVE-2026-72693 - `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that use
CVE-2026-71218 - A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JS
CVE-2026-71217 - A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted cont
CVE-2026-15567 - A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2
CVE-2026-15565 - A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint witho
CVE-2026-15563 - A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without auth
CVE-2026-15562 - A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or
CVE-2026-15561 - A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and cou
CVE-2026-15560 - when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs
CVE-2026-15556 - A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion
CVE-2026-15555 - A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicat
CVE-2026-15554 - the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any sh
CVE-2026-10579 - A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged
CVE-2026-73156 - Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Su
CVE-2026-73155 - Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on com
CVE-2026-73140 - Affected versions of cti-transmute fail to apply comment-level access-control rules when generating
CVE-2026-19519 - A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer ca
CVE-2026-19418 - The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective
CVE-2026-19518 - Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allo
CVE-2026-19517 - Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Thr
CVE-2026-19391 - A flaw was found in insights-core where the password redaction layer fails to recognize credentials
CVE-2026-16053 - Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to A
CVE-2026-8158 - The Signed Video Framework contained a buffer overflow issue which could lead the application usin
CVE-2026-6505 - The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could pote
CVE-2026-6181 - The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can onl
CVE-2026-5304 - An ACAP configuration file lacks input validation, which could potentially lead to privilege escalat
CVE-2026-5303 - The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could pote
CVE-2026-4757 - A VAPIX API parameter had improper input validation which could allow code execution and potentially
CVE-2026-19516 - A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re
CVE-2026-18348 - Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an a
CVE-2026-14549 - The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or non
CVE-2026-14548 - The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or non
CVE-2026-13716 - Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authent
CVE-2026-12052 - The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next
CVE-2026-12051 - The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contain
CVE-2026-11894 - The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci
CVE-2026-19425 - Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability
CVE-2026-16974 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-11985 - On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choic
CVE-2026-11893 - The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send(
CVE-2026-8917 - Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vul
CVE-2026-24330 - A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can impo
CVE-2026-24329 - A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a
CVE-2026-19424 - Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability.
CVE-2026-66779 - Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authe
CVE-2026-66778 - SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to in
CVE-2026-66777 - SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to bac
CVE-2026-66776 - SAP Approuter does not consistently enforce integrity verification on certain session-related reques
CVE-2026-66775 - SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by d
CVE-2026-66774 - SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges
CVE-2026-66773 - A malicious or compromised OData service could disclose sensitive authentication information and inj
CVE-2026-66772 - SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient author
CVE-2026-66771 - SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into
CVE-2026-66770 - Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could di
CVE-2026-66764 - Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks fo
CVE-2026-66763 - SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated w
CVE-2026-66761 - SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with lo
CVE-2026-66760 - SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker
CVE-2026-58248 - SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attack
CVE-2026-58247 - SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal
CVE-2026-58245 - SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within t
CVE-2026-58244 - SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check
CVE-2026-58243 - SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality
CVE-2026-58241 - SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard
CVE-2026-58239 - SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated
CVE-2026-58238 - SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenti
CVE-2026-58237 - WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality
CVE-2026-58236 - SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to by
CVE-2026-58235 - SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptograph
CVE-2026-58230 - SAP Approuter does not sufficiently validate certain token content under specific configurations. An
CVE-2026-44765 - Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence
CVE-2026-44764 - Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence
CVE-2026-44763 - SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient
CVE-2026-44762 - SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) confi
CVE-2026-44758 - SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to subm
CVE-2026-40130 - SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An
CVE-2026-34265 - SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors i
CVE-2026-8718 - tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles g
CVE-2026-48161 - react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the de
CVE-2026-11812 - The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation
CVE-2026-11811 - The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c
CVE-2025-30241 - Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize use
CVE-2025-30240 - The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB
CVE-2025-30239 - In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to
CVE-2025-30238 - In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-p
CVE-2025-30237 - The affected TP-Link Aginet devices contain a flaw in the web management interface where authenticat
CVE-2026-72919 - Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14,
CVE-2026-72918 - Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14,
CVE-2026-72917 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-72916 - Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14,
CVE-2026-72915 - Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until
CVE-2026-72914 - Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14,
CVE-2026-6426 - A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The des
CVE-2025-32736 - Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before
CVE-2026-73035 - npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injec
CVE-2026-73033 - Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in th
CVE-2026-73030 - unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_w
CVE-2026-72913 - Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS ha
CVE-2026-72912 - CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, Cy
CVE-2026-72911 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0,
CVE-2026-72910 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0,
CVE-2026-72909 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0,
CVE-2026-72908 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0,
CVE-2026-72907 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,
CVE-2026-72906 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,
CVE-2026-72905 - Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-72904 - Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a crit
CVE-2026-72903 - Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious
CVE-2026-72743 - SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability
CVE-2026-63622 - A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm
CVE-2026-48160 - react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19
CVE-2026-19411 - A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing N
CVE-2026-18982 - A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit
CVE-2026-18951 - A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI ov
CVE-2026-18950 - A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerabilit
CVE-2026-18949 - A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the da
CVE-2026-18948 - A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored i
CVE-2026-18947 - A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /mat
CVE-2026-18942 - A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their fe
CVE-2026-18941 - A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and t
CVE-2026-18621 - A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can b
CVE-2026-18620 - A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper au
CVE-2026-18618 - A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making
CVE-2026-18617 - A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vul
CVE-2026-18611 - A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticate
CVE-2026-18608 - A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which de
CVE-2026-16456 - A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create cus
CVE-2026-15581 - A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the
CVE-2026-15467 - A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user with
CVE-2026-14450 - A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the
CVE-2026-13717 - A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gat
CVE-2026-11810 - The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updateh
CVE-2026-11809 - The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitiali
CVE-2026-72902 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an a
CVE-2026-72901 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an a
CVE-2026-72886 - Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.c
CVE-2026-72885 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, dockerContextPath a
CVE-2026-72884 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in
CVE-2026-72883 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handl
CVE-2026-72882 - Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticat
CVE-2026-72881 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and
CVE-2026-72880 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertif
CVE-2026-72879 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryComma
CVE-2026-72878 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup an
CVE-2026-72877 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage fie
CVE-2026-72876 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swa
CVE-2026-72875 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefi
CVE-2026-72874 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository
CVE-2026-72873 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in
CVE-2026-71966 - CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability
CVE-2026-71965 - CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerabi
CVE-2026-69118 - Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template re
CVE-2026-69116 - FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vu
CVE-2026-69114 - Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the
CVE-2026-69112 - Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in
CVE-2026-44401 - Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown pa
CVE-2026-14886 - Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authoriz
CVE-2025-15683 - TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in
CVE-2025-15682 - TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its w
CVE-2025-15681 - TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has
CVE-2025-15680 - TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without suffici
CVE-2025-13294 - An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0
CVE-2025-13293 - A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthent
CVE-2026-72872 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBit
CVE-2026-72871 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated
CVE-2026-72870 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDock
CVE-2026-72869 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreB
CVE-2026-72868 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server
CVE-2026-72867 - Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomp
CVE-2026-72866 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handl
CVE-2026-72865 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update
CVE-2026-72864 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of
CVE-2026-72863 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket
CVE-2026-71969 - OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the
CVE-2026-71968 - OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Tr
CVE-2026-71967 - OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability
CVE-2026-71964 - CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file
CVE-2026-71962 - Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/
CVE-2026-6791 - When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde fu
CVE-2026-6368 - Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the inte
CVE-2026-68872 - The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon prov
CVE-2026-68871 - The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connec
CVE-2026-68870 - The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-sco
CVE-2026-59091 - A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote atta
CVE-2026-12339 - A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a cr
CVE-2026-72900 - Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application da
CVE-2026-72899 - Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or da
CVE-2026-72898 - Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password'
CVE-2026-72862 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mon
CVE-2026-72740 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src
CVE-2026-72739 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand()
CVE-2026-72738 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBack
CVE-2026-72737 - Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create,
CVE-2026-72736 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user
CVE-2026-72735 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigR
CVE-2026-72734 - Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server
CVE-2026-72733 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreB
CVE-2026-72732 - Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
CVE-2026-70622 - tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_
CVE-2026-48159 - use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-
CVE-2026-16626 - Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft
CVE-2026-10754 - Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic
CVE-2026-72731 - Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026
CVE-2026-72730 - Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
CVE-2026-72729 - Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0
CVE-2026-72728 - Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could subm
CVE-2026-72727 - Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0,
CVE-2026-71577 - A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectl
CVE-2026-71576 - A flaw was found in multicluster-global-hub. The manager component improperly validates the source i
CVE-2026-63623 - A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume
CVE-2026-56619 - HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficien
CVE-2026-40512 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35028 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35027 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35026 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35006 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-35005 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34423 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29517 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29033 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29032 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29031 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29030 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29029 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29028 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29027 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29026 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29025 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.