CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-68190 - In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB rea
CVE-2026-68189 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Protect UU
CVE-2026-68188 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session
CVE-2026-68187 - In the Linux kernel, the following vulnerability has been resolved: exec: fix unsigned loop counter
CVE-2026-68186 - In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: set have_execfd on
CVE-2026-68185 - In the Linux kernel, the following vulnerability has been resolved: LoongArch: Move jump_label_init
CVE-2026-68184 - In the Linux kernel, the following vulnerability has been resolved: cdrom: fix stack out-of-bounds
CVE-2026-68183 - In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix me
CVE-2026-68182 - In the Linux kernel, the following vulnerability has been resolved: comedi: comedi_parport: deal wi
CVE-2026-68181 - In the Linux kernel, the following vulnerability has been resolved: mei: bus: access mei_device und
CVE-2026-68180 - In the Linux kernel, the following vulnerability has been resolved: intel_th: fix MSC output device
CVE-2026-68179 - In the Linux kernel, the following vulnerability has been resolved: misc: nsm: only unlock nsm_dev
CVE-2026-68178 - In the Linux kernel, the following vulnerability has been resolved: misc: nsm: pin the module while
CVE-2026-68177 - In the Linux kernel, the following vulnerability has been resolved: tracing: Delay module ref count
CVE-2026-68176 - In the Linux kernel, the following vulnerability has been resolved: tracing: Fix mmiotrace possible
CVE-2026-68175 - In the Linux kernel, the following vulnerability has been resolved: tracing: Fix resource leak on m
CVE-2026-68174 - In the Linux kernel, the following vulnerability has been resolved: tracing: Fix union collision of
CVE-2026-68173 - In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready()
CVE-2026-68172 - In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handl
CVE-2026-68171 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-68170 - In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk refere
CVE-2026-68169 - In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: userspace: fix use-a
CVE-2026-68168 - In the Linux kernel, the following vulnerability has been resolved: afs: Fix afs_edit_dir_remove()
CVE-2026-68167 - In the Linux kernel, the following vulnerability has been resolved: btrfs: do not try compression f
CVE-2026-68166 - In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registrati
CVE-2026-68165 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: validate ranges
CVE-2026-68164 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow overlap
CVE-2026-68163 - In the Linux kernel, the following vulnerability has been resolved: mm/page_vma_mapped: fix device-
CVE-2026-68162 - In the Linux kernel, the following vulnerability has been resolved: sctp: avoid auth_enable sysctl
CVE-2026-68161 - In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets
CVE-2026-68160 - In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bound
CVE-2026-68159 - In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,u
CVE-2026-68158 - In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication ove
CVE-2026-68157 - In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH ty
CVE-2026-68156 - In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authoriz
CVE-2026-68155 - In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps adverti
CVE-2026-68154 - In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket typ
CVE-2026-68153 - In the Linux kernel, the following vulnerability has been resolved: libceph: remove debugfs files b
CVE-2026-68152 - In the Linux kernel, the following vulnerability has been resolved: amt: fix use-after-free in AMT
CVE-2026-68151 - In the Linux kernel, the following vulnerability has been resolved: binfmt_elf_fdpic: only honour t
CVE-2026-68150 - In the Linux kernel, the following vulnerability has been resolved: fs/super: fix emergency thaw do
CVE-2026-68149 - In the Linux kernel, the following vulnerability has been resolved: fs: preserve ACL_DONT_CACHE sta
CVE-2026-68148 - In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock
CVE-2026-68147 - In the Linux kernel, the following vulnerability has been resolved: fscrypt: Avoid dynamic allocati
CVE-2026-68146 - In the Linux kernel, the following vulnerability has been resolved: ftrace: Add global mutex to ser
CVE-2026-68145 - In the Linux kernel, the following vulnerability has been resolved: iomap: fix out-of-bounds bitmap
CVE-2026-68144 - In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free
CVE-2026-68143 - In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive ag
CVE-2026-68142 - In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN i
CVE-2026-68141 - In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in
CVE-2026-68140 - In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of
CVE-2026-68139 - In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Use sender devcom fo
CVE-2026-68138 - In the Linux kernel, the following vulnerability has been resolved: net/sched: serialize qdisc_rtab
CVE-2026-68137 - In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in
CVE-2026-68136 - In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregatio
CVE-2026-68135 - In the Linux kernel, the following vulnerability has been resolved: net: hip04: fix RX buffer leak
CVE-2026-68134 - In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing faci
CVE-2026-68133 - In the Linux kernel, the following vulnerability has been resolved: ice: fix PTP Call Trace during
CVE-2026-68132 - In the Linux kernel, the following vulnerability has been resolved: super: fix emergency thaw deadl
CVE-2026-68131 - In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result code
CVE-2026-68130 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer destroy_previous_s
CVE-2026-68129 - In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on allo
CVE-2026-68128 - In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype
CVE-2026-68127 - In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after p
CVE-2026-68126 - In the Linux kernel, the following vulnerability has been resolved: mac802154: hold an interface re
CVE-2026-68125 - In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames
CVE-2026-68124 - In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-lengt
CVE-2026-68123 - In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace
CVE-2026-68122 - In the Linux kernel, the following vulnerability has been resolved: ovpn: fix peer refcount leak in
CVE-2026-68121 - In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer af
CVE-2026-68120 - In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang c
CVE-2026-68119 - In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-
CVE-2026-68118 - In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exac
CVE-2026-68117 - In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the fai
CVE-2026-68116 - In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix source list cor
CVE-2026-68115 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx10: replace BUG_O
CVE-2026-68114 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12.1: replace BUG
CVE-2026-68113 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx12: replace BUG_O
CVE-2026-68112 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9.4.3: replace BU
CVE-2026-68111 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9: replace BUG_ON
CVE-2026-68110 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma4.4.2: replace B
CVE-2026-68109 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/sdma7.1: replace BUG
CVE-2026-68108 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer ove
CVE-2026-68107 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereadin
CVE-2026-68106 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix division by zer
CVE-2026-68105 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix kernel panic du
CVE-2026-68104 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_rem
CVE-2026-68103 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a re
CVE-2026-68102 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix aperture mappin
CVE-2026-68101 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-68100 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_subauth whe
CVE-2026-68099 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: restore DACL size on che
CVE-2026-68098 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to
CVE-2026-68097 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size agains
CVE-2026-68096 - In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking de
CVE-2026-68095 - In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix race between re
CVE-2026-68094 - In the Linux kernel, the following vulnerability has been resolved: sched_ext: Preserve rq tracking
CVE-2026-68093 - In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation
CVE-2026-59233 - Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.
CVE-2026-59090 - A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow
CVE-2026-19429 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19278 - A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an a
CVE-2026-18370 - entr is vulnerable to Heap-based buffer overflow in run_utility() function. The function allocates a
CVE-2026-13206 - Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi
CVE-2026-12984 - Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedde
CVE-2026-68092 - In the Linux kernel, the following vulnerability has been resolved: time/jiffies: Register jiffies
CVE-2026-68091 - In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after
CVE-2026-68090 - In the Linux kernel, the following vulnerability has been resolved: debugobjects: Plug race against
CVE-2026-68089 - In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized da
CVE-2026-68088 - In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: a
CVE-2026-68087 - In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in w
CVE-2026-68086 - In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty
CVE-2026-68085 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_
CVE-2026-68084 - In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location
CVE-2026-68083 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in k
CVE-2026-64941 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_v
CVE-2026-59088 - A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin wh
CVE-2026-72594 - A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-
CVE-2026-72593 - A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated rem
CVE-2026-72592 - An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated
CVE-2026-72591 - A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenti
CVE-2026-72590 - An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthentic
CVE-2026-72589 - An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthentic
CVE-2026-72588 - A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated
CVE-2026-72587 - A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remot
CVE-2026-72586 - A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated re
CVE-2026-72585 - Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-72584 - A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthen
CVE-2026-72583 - A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privile
CVE-2026-72582 - A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated rem
CVE-2026-72581 - A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allo
CVE-2026-72580 - An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote a
CVE-2026-72579 - An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attack
CVE-2026-72578 - A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticate
CVE-2026-72577 - Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker t
CVE-2026-72576 - A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authe
CVE-2026-72575 - An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote att
CVE-2026-72574 - A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote
CVE-2026-72573 - An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remot
CVE-2026-72572 - A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attac
CVE-2026-72571 - A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticat
CVE-2026-72570 - A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows
CVE-2026-72569 - A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated
CVE-2026-72568 - Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-72567 - An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows
CVE-2026-72566 - A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a lo
CVE-2026-72565 - A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attacke
CVE-2026-72564 - An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated re
CVE-2026-71394 - GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in
CVE-2026-71393 - GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c.
CVE-2026-71392 - GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() functio
CVE-2026-71391 - GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The share
CVE-2026-66642 - Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. T
CVE-2026-66486 - GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing func
CVE-2026-66485 - GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepat
CVE-2026-66484 - GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When e
CVE-2026-65948 - UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a
CVE-2026-65945 - Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgra
CVE-2026-65942 - TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recomme
CVE-2026-61899 - Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to downlo
CVE-2026-59087 - A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks f
CVE-2026-55814 - Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to
CVE-2026-55799 - Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are
CVE-2026-44416 - Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apach
CVE-2026-42537 - Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgr
CVE-2026-40920 - Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are re
CVE-2026-32227 - SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recomme
CVE-2026-28672 - Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in
CVE-2026-66915 - Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attac
CVE-2026-44630 - Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthentica
CVE-2026-19404 - A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintena
CVE-2026-66411 - DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket commu
CVE-2026-66410 - Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be
CVE-2026-66409 - DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networ
CVE-2026-66408 - The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physica
CVE-2026-66407 - DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
CVE-2026-66406 - DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A
CVE-2026-66405 - DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be lever
CVE-2026-66404 - DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Opera
CVE-2026-66403 - DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor ma
CVE-2026-21084 - Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access s
CVE-2026-21083 - Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to acc
CVE-2026-21082 - Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access se
CVE-2026-21081 - Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x a
CVE-2026-21080 - Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent
CVE-2026-21079 - Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attac
CVE-2026-21078 - Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to versio
CVE-2026-21077 - Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access se
CVE-2026-21076 - Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access se
CVE-2026-21075 - Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows rem
CVE-2026-21074 - Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute a
CVE-2026-21073 - Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers
CVE-2026-21072 - Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local
CVE-2026-21071 - Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows loca
CVE-2026-21070 - Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attacke
CVE-2026-21069 - Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Releas
CVE-2026-21068 - Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local
CVE-2026-21067 - Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to wr
CVE-2026-21066 - Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local a
CVE-2026-21065 - Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attacker
CVE-2026-21064 - Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause de
CVE-2026-21063 - Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows
CVE-2026-64940 - Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a pe
CVE-2026-57279 - Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an
CVE-2026-21062 - Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers t
CVE-2026-21061 - Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers
CVE-2026-21060 - Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attack
CVE-2026-21059 - Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release
CVE-2026-21058 - Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers
CVE-2026-19089 - The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded fi
CVE-2026-19077 - The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in
CVE-2026-19075 - All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vd
CVE-2026-19074 - The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin befor
CVE-2026-19053 - The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter bef
CVE-2026-19049 - The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before usin
CVE-2026-18960 - The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every aut
CVE-2026-18946 - The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copyin
CVE-2026-18934 - The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user
CVE-2026-18786 - The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to
CVE-2026-18666 - The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supp
CVE-2026-18470 - The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset requ
CVE-2026-18469 - The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attemp
CVE-2026-18468 - The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verificat
CVE-2026-18200 - The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated
CVE-2026-18030 - The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when p
CVE-2026-17542 - The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its f
CVE-2026-17541 - The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST
CVE-2026-17540 - The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management comma
CVE-2026-17023 - The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or
CVE-2026-17022 - The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ow
CVE-2026-17021 - The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some
CVE-2026-17020 - The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking
CVE-2026-17019 - The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing a
CVE-2026-17018 - The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorizatio
CVE-2026-17016 - The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does no
CVE-2026-17012 - The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does no
CVE-2026-17010 - The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post meta
CVE-2026-16985 - The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-
CVE-2026-16949 - The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter befor
CVE-2026-16299 - The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset
CVE-2026-16298 - The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset reques
CVE-2026-16257 - The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of it
CVE-2026-15238 - The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before up
CVE-2026-15237 - The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or owne
CVE-2026-15229 - The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price
CVE-2026-15047 - The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before out
CVE-2026-14941 - The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capab
CVE-2026-14860 - The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side
CVE-2026-14293 - The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before savi
CVE-2026-14238 - The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.