CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-57469 - Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the we
CVE-2026-53970 - ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby
CVE-2026-19884 - In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integra
CVE-2026-19837 - A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi
CVE-2026-19836 - A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some un
CVE-2026-19835 - A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u
CVE-2026-19834 - A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the
CVE-2026-16772 - In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to
CVE-2026-13198 - Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper
CVE-2026-13197 - Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper
CVE-2026-13196 - Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image ma
CVE-2026-13002 - A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An at
CVE-2026-69101 - Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authen
CVE-2026-58224 - A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integri
CVE-2026-19880 - Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows
CVE-2026-19879 - A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `wri
CVE-2026-73633 - Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an applica
CVE-2026-53472 - A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialU
CVE-2026-1621 - Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality al
CVE-2026-19871 - Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.
CVE-2026-19830 - A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an un
CVE-2026-19829 - A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability
CVE-2026-19828 - A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown
CVE-2026-19827 - A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStrea
CVE-2026-19768 - Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow
CVE-2026-73673 - Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability tha
CVE-2026-19870 - Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM b
CVE-2026-19826 - A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian
CVE-2026-19825 - A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. Th
CVE-2026-19824 - A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element i
CVE-2026-19823 - A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the f
CVE-2026-73630 - SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFileP
CVE-2026-73051 - actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 pa
CVE-2026-73049 - SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeVie
CVE-2026-73048 - SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFile
CVE-2026-72859 - Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment uplo
CVE-2026-72838 - FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-
CVE-2026-72837 - File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook aut
CVE-2026-72836 - FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home dire
CVE-2026-72835 - filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allo
CVE-2026-72834 - filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum
CVE-2026-72833 - The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege es
CVE-2026-72832 - Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the S
CVE-2026-72831 - The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization
CVE-2026-72830 - Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-
CVE-2026-72829 - The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in
CVE-2026-72828 - Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in Invit
CVE-2026-72827 - Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action param
CVE-2026-72826 - The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly create
CVE-2026-72825 - The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /r
CVE-2026-72824 - The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in
CVE-2026-72823 - The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in
CVE-2026-72822 - The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API
CVE-2026-72821 - Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio
CVE-2026-72820 - Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers
CVE-2026-72819 - Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin set
CVE-2026-72817 - go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middlewar
CVE-2026-72816 - go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/
CVE-2026-72815 - go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP mid
CVE-2026-72814 - The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerabi
CVE-2026-72813 - actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range hea
CVE-2026-72812 - SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshB
CVE-2026-72811 - SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query
CVE-2026-72810 - SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast
CVE-2026-19822 - A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the
CVE-2025-71405 - chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware
CVE-2026-19821 - A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the
CVE-2026-19815 - A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is th
CVE-2026-19814 - A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setM
CVE-2026-19813 - A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts th
CVE-2026-19812 - A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function U
CVE-2026-19794 - The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to
CVE-2026-19811 - A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element i
CVE-2026-19617 - A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) met
CVE-2026-18039 - The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied reg
CVE-2026-16810 - The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugi
CVE-2026-16739 - The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.4 does not verify that a payment-c
CVE-2026-15205 - The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie
CVE-2026-14290 - The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute v
CVE-2026-12949 - The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verifica
CVE-2026-12743 - The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vul
CVE-2026-19792 - A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapp
CVE-2026-19791 - A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addS
CVE-2025-10308 - The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver
CVE-2026-19790 - A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPo
CVE-2026-19789 - A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects th
CVE-2026-19788 - A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_devi
CVE-2026-19787 - A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unk
CVE-2026-19786 - A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown
CVE-2026-19785 - A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affect
CVE-2026-19784 - A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate o
CVE-2026-18109 - The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Aut
CVE-2026-19771 - A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown fun
CVE-2026-19770 - A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is th
CVE-2026-19767 - A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects so
CVE-2026-19765 - A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec8059361
CVE-2026-19764 - A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up
CVE-2026-19763 - A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUt
CVE-2026-19762 - A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Pat
CVE-2026-19761 - A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOri
CVE-2026-19758 - A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown p
CVE-2026-19757 - A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown cod
CVE-2026-3883 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19756 - A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of t
CVE-2026-19753 - A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the funct
CVE-2026-18532 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73843 - OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, i
CVE-2026-73842 - OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and
CVE-2026-73841 - OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, i
CVE-2026-73840 - OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and
CVE-2026-73667 - OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and
CVE-2026-73666 - OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo
CVE-2026-73665 - FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses i
CVE-2026-73664 - FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in B
CVE-2026-73663 - FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall modul
CVE-2026-73662 - FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits
CVE-2026-73661 - FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits
CVE-2026-73660 - FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module al
CVE-2026-73659 - Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.
CVE-2026-73658 - Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4
CVE-2026-73657 - Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4
CVE-2026-73489 - Russh is a Rust SSH client & server library. Prior to 0.62.4, an authenticated SSH client can cause
CVE-2026-73479 - dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the
CVE-2026-73428 - Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix
CVE-2026-73421 - NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, ap
CVE-2026-73420 - NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 an
CVE-2026-73417 - jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jup
CVE-2026-73416 - jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jup
CVE-2026-73408 - Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mys
CVE-2026-73305 - Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign cal
CVE-2026-73304 - Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api
CVE-2026-73302 - Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-co
CVE-2026-73039 - streama contains an insecure direct object reference vulnerability in ViewingStatusController that a
CVE-2026-72857 - Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowin
CVE-2026-72856 - Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/globa
CVE-2026-72855 - Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import
CVE-2026-72853 - Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's p
CVE-2026-72851 - Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered
CVE-2026-72850 - Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to
CVE-2026-72849 - Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff
CVE-2026-72842 - luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated Lu
CVE-2026-72841 - luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowin
CVE-2026-72840 - OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants writ
CVE-2026-72839 - filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is ena
CVE-2026-72776 - AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that al
CVE-2026-56865 - A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a request
CVE-2026-56864 - A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transpa
CVE-2026-56862 - Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of wheth
CVE-2026-56860 - Previously, resolving relative paths containing parent directory ('..') segments performed string co
CVE-2026-56859 - Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to
CVE-2026-56858 - Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled d
CVE-2026-56853 - When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connec
CVE-2026-33818 - Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recur
CVE-2026-19752 - A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477
CVE-2026-19751 - A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9
CVE-2026-19750 - A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue
CVE-2026-8715 - Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfi
CVE-2026-73480 - gdu fails to strip terminal escape sequences from directory and file names when printing paths after
CVE-2026-19749 - A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C
CVE-2026-19748 - A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3
CVE-2026-19483 - IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in l
CVE-2026-19297 - IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to
CVE-2026-18741 - Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the
CVE-2026-18715 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
CVE-2026-18671 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server threa
CVE-2026-18511 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based bu
CVE-2026-18509 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation
CVE-2026-18249 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges
CVE-2026-18193 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to im
CVE-2026-18101 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to imprope
CVE-2026-18086 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denia
CVE-2026-18077 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a sta
CVE-2026-18068 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a
CVE-2026-18020 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an of
CVE-2026-17649 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an
CVE-2026-17502 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an ou
CVE-2026-17482 - IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17481 - IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17476 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an im
CVE-2026-17473 - IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files
CVE-2026-17468 - IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session t
CVE-2026-17438 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify
CVE-2026-17272 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buf
CVE-2026-17226 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
CVE-2026-17216 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an in
CVE-2026-17212 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an ou
CVE-2026-17101 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensi
CVE-2026-17099 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to im
CVE-2026-17088 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive informa
CVE-2026-17078 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resou
CVE-2026-17077 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the u
CVE-2026-17076 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to impro
CVE-2026-17075 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perfo
CVE-2026-17074 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict
CVE-2026-17071 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulatio
CVE-2026-73669 - The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on a
CVE-2026-73656 - Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to
CVE-2026-73655 - Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to
CVE-2026-73654 - Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3
CVE-2026-73531 - django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauth
CVE-2026-73530 - Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that all
CVE-2026-72687 - A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request
CVE-2026-72686 - A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request contai
CVE-2026-72685 - A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit
CVE-2026-72684 - A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small
CVE-2026-72683 - A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simu
CVE-2026-72681 - Kibana Agent Builder does not correctly verify that the requesting user holds the privileges require
CVE-2026-72680 - Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from
CVE-2026-72679 - Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern ac
CVE-2026-72678 - Elasticsearch does not validate a size value taken from a user-supplied input before that value is u
CVE-2026-72677 - Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources
CVE-2026-72676 - Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the e
CVE-2026-72675 - Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unautho
CVE-2026-72674 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-72673 - Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private
CVE-2026-72672 - The Elastic Security capability that suggests existing field values while a user authors endpoint po
CVE-2026-72671 - A Kibana Machine Learning capability that removes a saved object from the current space accepts mach
CVE-2026-72670 - A lower privileged user who holds only the privilege to read agent policies can read the entire conf
CVE-2026-72669 - The state that Kibana stores for an Observability Onboarding flow is not bound to the user who creat
CVE-2026-72667 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-72666 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query
CVE-2026-72665 - Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic
CVE-2026-72664 - Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend respo
CVE-2026-72663 - Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data
CVE-2026-72661 - Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functiona
CVE-2026-72660 - Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead
CVE-2026-72659 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of servi
CVE-2026-72658 - Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Reque
CVE-2026-72657 - Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information d
CVE-2026-72656 - Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch
CVE-2026-72655 - Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case
CVE-2026-72653 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of servi
CVE-2026-72651 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of servi
CVE-2026-72650 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclos
CVE-2026-72648 - Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on
CVE-2026-72647 - Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data
CVE-2026-72645 - Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service
CVE-2026-72643 - Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user ide
CVE-2026-72642 - The native inference process that Elasticsearch uses to evaluate uploaded machine learning models ac
CVE-2026-72640 - The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation
CVE-2026-72639 - Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highligh
CVE-2026-72638 - Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manip
CVE-2026-72636 - Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial
CVE-2026-72632 - Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (
CVE-2026-72631 - Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privile
CVE-2026-72630 - Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abu
CVE-2026-72629 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-
CVE-2026-59714 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 bef
CVE-2026-49864 - wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client
CVE-2026-49096 - Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulati
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware