CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-14397 - Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacke
CVE-2026-14396 - Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to lea
CVE-2026-14395 - Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execu
CVE-2026-14394 - Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentiall
CVE-2026-14393 - Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar
CVE-2026-14392 - Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to pot
CVE-2026-14391 - Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attack
CVE-2026-14390 - Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti
CVE-2026-14389 - Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had c
CVE-2026-14388 - Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obt
CVE-2026-14387 - Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potent
CVE-2026-14386 - Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obt
CVE-2026-14385 - Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attack
CVE-2026-14384 - Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote atta
CVE-2026-14383 - Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker
CVE-2026-14382 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed
CVE-2026-14381 - Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote att
CVE-2026-11950 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-55793 - Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-leve
CVE-2026-54712 - OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation l
CVE-2026-54704 - OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation l
CVE-2026-54263 - Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3
CVE-2026-54262 - Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3
CVE-2026-54261 - Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3
CVE-2026-54260 - Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3
CVE-2026-54259 - Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3
CVE-2026-52190 - Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to
CVE-2026-52186 - SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to e
CVE-2026-38891 - An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 all
CVE-2026-36912 - A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE b
CVE-2026-36911 - A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleks
CVE-2026-36910 - An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341
CVE-2026-36909 - A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before
CVE-2026-58263 - Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4
CVE-2026-55886 - Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities
CVE-2026-55661 - Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3
CVE-2026-55660 - Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.
CVE-2026-55153 - mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c
CVE-2026-54786 - Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those
CVE-2026-54756 - Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities
CVE-2026-54720 - Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.
CVE-2026-54074 - Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote
CVE-2026-50521 - Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over
CVE-2026-14340 - An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a u
CVE-2026-58593 - NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote
CVE-2026-58592 - Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module
CVE-2026-58457 - Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command inj
CVE-2026-55688 - The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async
CVE-2026-54908 - Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are v
CVE-2026-54164 - API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior t
CVE-2026-49858 - API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.
CVE-2026-14363 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-14265 - Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced
CVE-2026-58517 - Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - W
CVE-2026-58451 - Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authen
CVE-2026-55628 - ImageMagick is free and open-source software used for editing and manipulating digital images. In ve
CVE-2026-55597 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-55595 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-55594 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-55577 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-55510 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53492 - containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI
CVE-2026-53489 - containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a b
CVE-2026-53467 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53466 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-51947 - An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pi
CVE-2026-50195 - containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a v
CVE-2026-50160 - Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from ve
CVE-2026-49119 - Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preproce
CVE-2026-47262 - containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2
CVE-2026-41121 - Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Befo
CVE-2026-38142 - An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint
CVE-2026-14358 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-13769 - Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like syst
CVE-2026-13760 - OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cd
CVE-2026-5051 - HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistent
CVE-2026-58521 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-58520 - URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediaw
CVE-2026-57737 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57736 - Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded
CVE-2026-57723 - Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS al
CVE-2026-57722 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-54428 - Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpCompo
CVE-2026-51946 - SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker
CVE-2026-49091 - Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Inject
CVE-2026-49090 - Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Exc
CVE-2026-46680 - containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1,
CVE-2026-58454 - JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution
CVE-2026-58453 - JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credential
CVE-2026-58452 - JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection
CVE-2026-57721 - Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configu
CVE-2026-57720 - Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Config
CVE-2026-57516 - Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that a
CVE-2026-56152 - Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure
CVE-2026-56151 - Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipula
CVE-2026-56150 - Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial
CVE-2026-56149 - Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial
CVE-2026-56148 - Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allo
CVE-2026-54399 - Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpCompone
CVE-2026-49088 - Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclos
CVE-2026-49087 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-34117 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subt
CVE-2026-34116 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.p
CVE-2026-34115 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_a
CVE-2026-34114 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_te
CVE-2026-34113 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.
CVE-2026-34112 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.ph
CVE-2026-34111 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_te
CVE-2026-34110 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_star
CVE-2026-34109 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (
CVE-2026-34108 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (li
CVE-2026-34107 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.ph
CVE-2026-34106 - Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.ph
CVE-2026-34105 - Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in trans
CVE-2026-34104 - Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in des
CVE-2026-34103 - Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subti
CVE-2026-34102 - Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_i
CVE-2026-34101 - Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_
CVE-2026-34100 - Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media
CVE-2026-34099 - Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_i
CVE-2026-34098 - Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source
CVE-2026-34097 - Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HT
CVE-2026-34096 - Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML
CVE-2026-27409 - Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Con
CVE-2026-20244 - A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attac
CVE-2026-20243 - A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attac
CVE-2026-20217 - A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote at
CVE-2026-20216 - A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, re
CVE-2026-20215 - A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attack
CVE-2026-20214 - A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attac
CVE-2026-20213 - A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attack
CVE-2026-20191 - A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arb
CVE-2026-13211 - The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authenticati
CVE-2026-12480 - Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an in
CVE-2026-8857 - A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program fi
CVE-2026-8480 - A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to
CVE-2026-58127 - PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerE
CVE-2026-58126 - PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows
CVE-2026-58038 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58037 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58036 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Med
CVE-2026-58033 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Med
CVE-2026-58032 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58030 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58029 - Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program fil
CVE-2026-58028 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58027 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Abu
CVE-2026-58026 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Med
CVE-2026-58025 - Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerabil
CVE-2026-58024 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Med
CVE-2026-57517 - Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthe
CVE-2026-24270 - NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A s
CVE-2026-24266 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-
CVE-2026-24264 - NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improp
CVE-2026-24260 - NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-
CVE-2026-24251 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper con
CVE-2026-24250 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper val
CVE-2026-24249 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserializat
CVE-2026-24248 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper con
CVE-2026-24247 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserializat
CVE-2026-24246 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper con
CVE-2026-24245 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserializat
CVE-2026-24244 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserializat
CVE-2026-24243 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserializat
CVE-2026-24242 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side
CVE-2026-24240 - NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserializat
CVE-2026-13707 - Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated wit
CVE-2026-13706 - Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability i
CVE-2025-23351 - NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user wi
CVE-2025-23350 - NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user wi
CVE-2025-15646 - HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the
CVE-2026-6688 - FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs lon
CVE-2026-6687 - FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XD
CVE-2026-6686 - FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyo
CVE-2026-6685 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following
CVE-2026-6684 - FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded
CVE-2026-6683 - FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata caus
CVE-2026-6682 - In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= f
CVE-2026-6283 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-5220 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-5142 - A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy
CVE-2026-5138 - A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-
CVE-2026-5135 - A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user w
CVE-2026-58399 - @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appe
CVE-2026-58035 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58034 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-58031 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-2891 - The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a
CVE-2026-23537 - A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that all
CVE-2026-14330 - Multiple unbounded alloca() calls in the PulseAudio protocol server.
CVE-2026-14324 - RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2026-13602 - We found a chain of combining multiple weaknesses in the product that could allow an attacker to bec
CVE-2026-12374 - Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the Privi
CVE-2026-5136 - A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignme
CVE-2026-57692 - Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. T
CVE-2026-53356 - In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread
CVE-2026-53355 - In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setu
CVE-2026-53354 - In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI er
CVE-2026-53353 - In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_
CVE-2026-53352 - In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MA
CVE-2026-53351 - In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_N
CVE-2026-53350 - In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL derefer
CVE-2026-53349 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destro
CVE-2026-53348 - In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: fix NULL pointer de
CVE-2026-53347 - In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal
CVE-2026-53346 - In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm m
CVE-2026-53345 - In the Linux kernel, the following vulnerability has been resolved: KVM: Don't WARN if memory is di
CVE-2026-53344 - In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize m
CVE-2026-53343 - In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte lo
CVE-2026-53342 - In the Linux kernel, the following vulnerability has been resolved: arm64: mm: call pagetable dtor
CVE-2026-53341 - In the Linux kernel, the following vulnerability has been resolved: fhandle: fix UAF due to unlocke
CVE-2026-53340 - In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix clock and pinctrl
CVE-2026-53339 - In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer
CVE-2026-53338 - In the Linux kernel, the following vulnerability has been resolved: net: airoha: Add NULL check for
CVE-2026-53337 - In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer
CVE-2026-53336 - In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix h
CVE-2026-53335 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: handle ctx a
CVE-2026-53334 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: handle ctx al
CVE-2026-53333 - In the Linux kernel, the following vulnerability has been resolved: mm/mincore: handle non-swap ent
CVE-2026-53332 - In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Registe
CVE-2026-53331 - In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid A
CVE-2026-53330 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bou
CVE-2026-53329 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_a
CVE-2026-53328 - In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on NULL c
CVE-2026-53327 - In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool(
CVE-2026-53326 - In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_p
CVE-2026-13603 - The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex,
CVE-2026-8387 - A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path tr
CVE-2026-5120 - A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 coul
CVE-2026-53909 - MCO does not correctly validate types of uploaded files. File upload validation functionality relies
CVE-2026-53908 - MCO is vulnerable to User Enumeration through authentication-related functionalities. The applicatio
CVE-2026-53907 - MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality
CVE-2026-53906 - MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to da
CVE-2026-53905 - MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hi
CVE-2026-53904 - MCO is vulnerable to Account Denial of Service due to improper implementation of password reset func
CVE-2026-53903 - MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servl
CVE-2026-53902 - MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-secti
CVE-2026-14198 - @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter valu
CVE-2026-14181 - @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the st
CVE-2026-13323 - In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with
CVE-2026-14258 - A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially cr
CVE-2026-13228 - The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab
CVE-2026-12142 - The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cro
CVE-2026-10095 - The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's
CVE-2026-27435 - Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Ac
CVE-2026-13454 - The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via th
CVE-2026-12754 - The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site
CVE-2026-56016 - CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entrop
CVE-2026-50043 - Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi
CVE-2026-13733 - The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.