CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-47487 - NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files out
CVE-2026-24255 - NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacke
CVE-2026-24254 - NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attack
CVE-2026-24253 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds writ
CVE-2026-18830 - Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remot
CVE-2026-18790 - A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac
CVE-2026-18788 - A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted eleme
CVE-2026-69263 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69262 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69259 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69258 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69257 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69256 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69255 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-64634 - A vulnerability allowing local privilege escalation to the Reporter service context.
CVE-2026-64633 - A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-64631 - A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-64630 - A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared
CVE-2026-63456 - Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow
CVE-2026-63455 - Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow
CVE-2026-58075 - A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which ca
CVE-2026-58074 - A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
CVE-2026-58073 - A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonat
CVE-2026-58072 - A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management se
CVE-2026-58071 - A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the
CVE-2026-58067 - A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust ho
CVE-2026-56848 - A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly whil
CVE-2026-48121 - @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that
CVE-2026-18787 - A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function r
CVE-2026-18785 - A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is
CVE-2026-18784 - A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_rea
CVE-2026-18775 - A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects
CVE-2026-18774 - A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_
CVE-2026-15920 - An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.util
CVE-2026-15830 - An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contri
CVE-2026-15337 - An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.
CVE-2026-15314 - Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling
CVE-2026-15307 - An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups
CVE-2025-29296 - H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R0
CVE-2026-69254 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69253 - Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows.
CVE-2026-69252 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69110 - OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthentic
CVE-2026-69100 - LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execu
CVE-2026-69098 - kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection e
CVE-2026-25292 - Memory Corruption when processing untrusted user input in the fastboot command handler for audio fra
CVE-2026-25289 - Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Disco
CVE-2026-25288 - Transient DOS when processing a short target wake time channel usage response frame with insufficien
CVE-2026-24084 - Weak configuration when UE does not verify the consistency of its additional security capabilities w
CVE-2026-24083 - Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080 - Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079 - Cryptographic Issue while processing registration requests with malformed or missing authentication
CVE-2026-24078 - Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall S
CVE-2026-24077 - Information Disclosure when processing wireless network channel switch information with improperly f
CVE-2026-24076 - Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366 - Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801 - OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of custome
CVE-2026-18773 - A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is
CVE-2026-10032 - The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() with
CVE-2026-69251 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69250 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-68494 - The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number l
CVE-2026-67618 - marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors
CVE-2026-67200 - Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attacke
CVE-2026-67199 - Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block t
CVE-2026-67198 - Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatche
CVE-2026-67196 - Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that al
CVE-2026-67195 - Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attacke
CVE-2026-61515 - Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vul
CVE-2026-61514 - Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability t
CVE-2026-18770 - A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e
CVE-2026-18766 - A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763
CVE-2026-18650 - Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This is
CVE-2026-18401 - The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength con
CVE-2026-11368 - The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer w
CVE-2026-70368 - A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when hand
CVE-2026-70367 - A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when co
CVE-2026-17070 - Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Pr
CVE-2026-14337 - Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vu
CVE-2026-70373 - Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in s
CVE-2026-70372 - Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-c
CVE-2026-70371 - Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user
CVE-2026-70370 - Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-cont
CVE-2026-70369 - Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interp
CVE-2026-63252 - In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retaine
CVE-2026-63248 - In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access
CVE-2026-62927 - In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch t
CVE-2026-61387 - In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe:
CVE-2026-60007 - In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable erro
CVE-2026-58080 - In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configu
CVE-2026-18809 - Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was
CVE-2026-18806 - External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research
CVE-2026-10710 - A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buff
CVE-2026-10709 - A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buff
CVE-2026-66884 - Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Autho
CVE-2026-66883 - Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc
CVE-2026-10050 - In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the pass
CVE-2026-18772 - Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allo
CVE-2026-15721 - Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultan
CVE-2026-14838 - Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informati
CVE-2026-14804 - Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc.
CVE-2026-14465 - Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUM
CVE-2026-14219 - URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics
CVE-2026-14202 - Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUM
CVE-2026-14194 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bili
CVE-2026-14192 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-14175 - Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Cons
CVE-2026-67243 - freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability.
CVE-2026-18759 - The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-p
CVE-2026-18755 - A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to
CVE-2026-18754 - The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web serve
CVE-2026-18753 - The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web serve
CVE-2026-64565 - In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffe
CVE-2026-64564 - In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's o
CVE-2026-64563 - In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p
CVE-2026-64562 - In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS rig
CVE-2026-64561 - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obs
CVE-2026-16623 - The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before
CVE-2026-16618 - The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking
CVE-2026-16548 - The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat
CVE-2026-16547 - The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download f
CVE-2026-16546 - The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation chec
CVE-2026-16536 - The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a u
CVE-2026-16296 - The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlit
CVE-2026-16295 - The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its a
CVE-2026-16293 - The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and e
CVE-2026-16070 - The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being
CVE-2026-16069 - The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coo
CVE-2026-16068 - The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global
CVE-2026-16056 - The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check i
CVE-2026-16035 - The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-facto
CVE-2026-15958 - The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization check
CVE-2026-15233 - The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputti
CVE-2026-14939 - The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address
CVE-2026-14872 - The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not pro
CVE-2026-14848 - The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscripti
CVE-2026-14824 - The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question
CVE-2026-14816 - The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization o
CVE-2026-12698 - The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may s
CVE-2026-11366 - The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one
CVE-2026-10526 - The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making ser
CVE-2026-68744 - A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-alloc
CVE-2026-18739 - A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuf
CVE-2026-18569 - A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is par
CVE-2026-16881 - A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile
CVE-2026-42169 - A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This fla
CVE-2026-18723 - A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown
CVE-2026-18722 - A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurv
CVE-2026-18721 - A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown pr
CVE-2026-14818 - A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP s
CVE-2026-8508 - An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firm
CVE-2026-6837 - A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX65
CVE-2026-18720 - A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of
CVE-2026-17614 - A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.g
CVE-2026-18719 - A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2
CVE-2026-58045 - A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the
CVE-2026-58044 - A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding pro
CVE-2026-58042 - A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains
CVE-2026-58041 - A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#crea
CVE-2026-56846 - A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and
CVE-2026-56845 - An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds
CVE-2026-66326 - Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute
CVE-2026-66325 - Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke
CVE-2026-66322 - Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor
CVE-2026-66321 - Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
CVE-2026-66318 - Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo
CVE-2026-66317 - Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor
CVE-2026-66316 - Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor
CVE-2026-66315 - Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
CVE-2026-66314 - Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unaut
CVE-2026-66313 - Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor
CVE-2026-66312 - Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code ov
CVE-2026-66311 - Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform
CVE-2026-66310 - External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker
CVE-2026-65804 - Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows
CVE-2026-65802 - External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker
CVE-2026-62870 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a netw
CVE-2026-18686 - A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function
CVE-2026-18685 - A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the functio
CVE-2026-11836 - Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debu
CVE-2026-11835 - Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra
CVE-2026-67978 - An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (
CVE-2026-67673 - A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0.
CVE-2026-48399 - Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability th
CVE-2026-48333 - Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu
CVE-2026-48331 - Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that
CVE-2026-48330 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a
CVE-2026-48326 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a
CVE-2026-48323 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a
CVE-2026-48317 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically
CVE-2026-18684 - A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function rem
CVE-2026-18667 - A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privi
CVE-2026-69249 - python-cryptography is a package designed to expose cryptographic primitives and recipes to Python d
CVE-2026-69248 - cryptography is a package designed to expose cryptographic primitives and recipes to Python develope
CVE-2026-69247 - cryptography is a package designed to expose cryptographic primitives and recipes to Python develope
CVE-2026-67977 - An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allow
CVE-2026-67975 - Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscri
CVE-2026-67974 - A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message han
CVE-2026-67973 - An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (
CVE-2026-67970 - Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to
CVE-2026-67969 - An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the
CVE-2026-67617 - Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content ta
CVE-2026-67616 - Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability
CVE-2026-48115 - Misskey is an open source, federated social media platform. All Misskey servers running versions 202
CVE-2026-47746 - Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to
CVE-2026-46714 - Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to
CVE-2026-46713 - Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to
CVE-2026-46712 - Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior t
CVE-2026-18682 - A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown c
CVE-2026-10849 - The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response
CVE-2026-69246 - Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the req
CVE-2026-69245 - Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives
CVE-2026-69244 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an
CVE-2026-69243 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the
CVE-2026-69240 - Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dia
CVE-2026-67976 - The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-control
CVE-2026-67972 - An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where recei
CVE-2026-66065 - Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-
CVE-2026-52521 - A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary
CVE-2026-52520 - Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publis
CVE-2026-52102 - An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 all
CVE-2026-51775 - SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary co
CVE-2026-51190 - The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input t
CVE-2026-49132 - OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticate
CVE-2026-49131 - OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticate
CVE-2026-48113 - Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5,
CVE-2026-48063 - Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7
CVE-2026-48061 - Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0,
CVE-2026-41447 - FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attack
CVE-2026-18738 - Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauth
CVE-2026-18737 - Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to
CVE-2026-18736 - Shlink contains a server-side request forgery vulnerability that allows authenticated API key holder
CVE-2026-18733 - A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might
CVE-2026-18648 - A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function
CVE-2026-18647 - A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8f
CVE-2026-18646 - A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code
CVE-2026-18645 - A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_cont
CVE-2026-69198 - ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.
CVE-2026-69192 - ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to
CVE-2026-69185 - Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.
CVE-2026-68981 - Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API usi
CVE-2026-68980 - Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Para
CVE-2026-68979 - Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not e
CVE-2026-67599 - ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows a
CVE-2026-67598 - Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/ser
CVE-2026-66296 - Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows
CVE-2026-62354 - Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.
CVE-2026-58139 - The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any
CVE-2026-48031 - go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In v
CVE-2026-47211 - Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.