CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-18641 - A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to
CVE-2026-18632 - A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function
CVE-2026-18631 - A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the functio
CVE-2026-59913 - Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Auth
CVE-2026-59912 - Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Ac
CVE-2026-38447 - osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of
CVE-2026-38446 - A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitiza
CVE-2026-38444 - osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header displa
CVE-2026-18616 - A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the functio
CVE-2026-18615 - A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the functio
CVE-2026-18614 - A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo
CVE-2025-15631 - A cryptographic weakness exists in affected Omada devices where site credentials are protected using
CVE-2025-15630 - A race condition exists in the cloud-based Omada device adoption process when an attacker may be abl
CVE-2025-15629 - A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to
CVE-2025-15628 - Affected Omada devices rely on embedded certificates that are shared across deployments to establish
CVE-2025-15627 - A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded c
CVE-2025-15544 - A cryptographic weakness exists in the Omada device adoption process. During adoption, authenticati
CVE-2026-61524 - WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module ins
CVE-2026-61523 - WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that
CVE-2026-40717 - Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link
CVE-2026-18613 - A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plu
CVE-2026-18612 - A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plug
CVE-2025-9291 - A certification validation weakness exists in communication between affected Omada devices and cloud
CVE-2026-69153 - PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul
CVE-2026-69152 - The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior
CVE-2026-69151 - Angular is a development platform for building mobile and desktop web applications using TypeScript/
CVE-2026-69149 - Angular is a development platform for building mobile and desktop web applications using TypeScript/
CVE-2026-68945 - Angular is a development platform for building mobile and desktop web applications using TypeScript/
CVE-2026-68930 - Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handle
CVE-2026-68869 - Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not
CVE-2026-67612 - OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal tem
CVE-2026-67611 - OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with val
CVE-2026-67610 - OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client
CVE-2026-61372 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-41453 - Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allo
CVE-2026-41452 - Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that al
CVE-2026-39932 - OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree c
CVE-2026-39931 - OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configurat
CVE-2026-18718 - Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allow
CVE-2026-18610 - A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /
CVE-2026-18607 - A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN5
CVE-2026-18606 - A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is
CVE-2026-18605 - A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown funct
CVE-2026-18604 - A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This im
CVE-2026-18602 - A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-clien
CVE-2026-18477 - A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handl
CVE-2026-18243 - Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may
CVE-2026-18651 - A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs conn
CVE-2026-18568 - XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify
CVE-2026-18508 - A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink ta
CVE-2026-18248 - @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and re
CVE-2026-15430 - Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, ve
CVE-2026-67609 - Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a
CVE-2026-9487 - XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml()
CVE-2026-9390 - XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed
CVE-2026-69097 - GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attacke
CVE-2026-69096 - OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.
CVE-2026-69095 - OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path travers
CVE-2026-69094 - Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_tempora
CVE-2026-69093 - Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.ph
CVE-2026-69092 - Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAM
CVE-2026-69091 - Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when confi
CVE-2026-69090 - Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing au
CVE-2026-69089 - Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes it
CVE-2026-69088 - Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::
CVE-2026-69087 - The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerabilit
CVE-2026-69086 - SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-
CVE-2026-69085 - SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint
CVE-2026-69084 - SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-su
CVE-2026-69083 - SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetConten
CVE-2026-68587 - SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDelet
CVE-2026-68586 - SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionD
CVE-2026-68585 - SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlock
CVE-2026-68584 - SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where c
CVE-2026-67608 - Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a
CVE-2026-64827 - Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a
CVE-2026-18642 - Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Ins
CVE-2026-18601 - A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.ch
CVE-2026-18600 - A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.s
CVE-2026-18108 - Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_asser
CVE-2026-18092 - Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping
CVE-2026-18089 - Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses aga
CVE-2026-56609 - HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the a
CVE-2026-56608 - HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce
CVE-2026-2346 - Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App a
CVE-2026-18599 - A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread
CVE-2026-18598 - A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function
CVE-2026-18574 - An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Se
CVE-2026-69082 - CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deleti
CVE-2026-69079 - CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /ac
CVE-2026-69078 - CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PD
CVE-2026-68742 - A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not v
CVE-2026-33591 - A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker
CVE-2026-0392 - eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates ove
CVE-2026-69075 - FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlle
CVE-2026-63563 - Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the
CVE-2026-63545 - Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave
CVE-2026-62416 - Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial c
CVE-2026-60011 - Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly
CVE-2026-8794 - PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthe
CVE-2026-8793 - PaperCut NG/MF does not properly restrict excessive authentication attempts within its login compone
CVE-2026-28147 - Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Wid
CVE-2026-21555 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21554 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21553 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21552 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21551 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21550 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21549 - In modem, there is a possible improper input validation. This could lead to remote denial of service
CVE-2026-21548 - In nr modem, there is a possible improper input validation. This could lead to remote denial of serv
CVE-2026-18593 - A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the
CVE-2026-18592 - A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function
CVE-2026-18591 - A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by
CVE-2026-18590 - A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sy
CVE-2026-12259 - In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes download
CVE-2026-9593 - A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host s
CVE-2026-4793 - An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local
CVE-2026-18589 - A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_pas
CVE-2026-18588 - A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets
CVE-2026-18587 - A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown funct
CVE-2026-16572 - The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie
CVE-2026-16565 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 do
CVE-2026-16564 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 do
CVE-2026-16563 - The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publicatio
CVE-2026-16539 - The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value be
CVE-2026-16534 - The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's
CVE-2026-16532 - The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied
CVE-2026-16300 - The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, all
CVE-2026-16297 - The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserial
CVE-2026-16289 - The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing
CVE-2026-16276 - The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX
CVE-2026-16274 - The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership che
CVE-2026-16250 - The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be up
CVE-2026-16060 - The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly
CVE-2026-16057 - The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce
CVE-2026-15931 - The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value receiv
CVE-2026-15930 - The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed dur
CVE-2026-15383 - The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor Use
CVE-2026-15260 - The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on
CVE-2026-15254 - The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability che
CVE-2026-15231 - The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user
CVE-2026-14557 - The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an au
CVE-2026-13340 - The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files
CVE-2026-12965 - The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthentica
CVE-2026-12872 - The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor
CVE-2025-15673 - The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path o
CVE-2025-15672 - The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it
CVE-2026-6695 - A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a spe
CVE-2026-6694 - A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicio
CVE-2026-18585 - A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5
CVE-2026-18584 - A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up
CVE-2026-18583 - A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the func
CVE-2026-14682 - In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite
CVE-2026-13586 - In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS
CVE-2026-13506 - In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This
CVE-2026-12860 - In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omi
CVE-2026-12852 - In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length be
CVE-2026-12817 - In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data
CVE-2026-12816 - In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF sp
CVE-2026-12803 - In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (c
CVE-2026-12802 - In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decrypti
CVE-2026-58063 - In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted
CVE-2026-58062 - In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked
CVE-2026-58061 - In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag
CVE-2026-58060 - In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocatio
CVE-2026-58059 - In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished
CVE-2026-20498 - In geniezone, there is a possible escalation of privilege due to a missing permission check. This co
CVE-2026-20497 - In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead
CVE-2026-20496 - In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead
CVE-2026-20495 - In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This c
CVE-2026-20494 - In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to lo
CVE-2026-20493 - In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to l
CVE-2026-20492 - In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could l
CVE-2026-20491 - In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to
CVE-2026-20490 - In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to lo
CVE-2026-20489 - In display, there is a possible information disclosure due to an integer overflow. This could lead t
CVE-2026-20488 - In display, there is a possible information disclosure due to a missing bounds check. This could lea
CVE-2026-20486 - In imgsensor, there is a possible application crash due to incorrect error handling. This could lead
CVE-2026-20485 - In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to l
CVE-2026-20484 - In TFA, there is a possible information disclosure due to a missing permission check. This could lea
CVE-2026-20483 - In Telephony, there is a possible escalation of privilege due to a missing permission check. This co
CVE-2026-20482 - In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to
CVE-2026-20481 - In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead
CVE-2026-20480 - In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead
CVE-2026-20479 - In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to r
CVE-2026-20478 - In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead
CVE-2026-20477 - In display, there is a possible out of bounds write due to a missing bounds check. This could lead t
CVE-2026-20476 - In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to lo
CVE-2026-20475 - In display, there is a possible out of bounds write due to a missing bounds check. This could lead t
CVE-2026-20474 - In display, there is a possible escalation of privilege due to a race condition. This could lead to
CVE-2026-20473 - In display, there is a possible memory corruption due to use after free. This could lead to local es
CVE-2026-20472 - In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
CVE-2026-20471 - In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to loc
CVE-2026-20470 - In Telephony, there is a possible information disclosure due to a missing permission check. This cou
CVE-2026-20469 - In trusted_mem, there is a possible escalation of privilege due to improper input validation. This c
CVE-2026-20468 - In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to
CVE-2026-20467 - In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lea
CVE-2026-20466 - In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could l
CVE-2026-20465 - In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could
CVE-2026-20464 - In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead
CVE-2026-18582 - A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability aff
CVE-2026-8763 - In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and UR
CVE-2026-65875 - BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user
CVE-2026-59652 - In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
CVE-2026-59651 - In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC
CVE-2026-59650 - In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. Thi
CVE-2026-59649 - In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM m
CVE-2026-59648 - In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes.
CVE-2026-59647 - In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This
CVE-2026-59646 - In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24
CVE-2026-59645 - In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential I
CVE-2026-59644 - In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter
CVE-2026-59643 - In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. Th
CVE-2026-59642 - In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs
CVE-2026-59641 - In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path
CVE-2026-59640 - In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-ke
CVE-2026-59639 - In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero si
CVE-2026-59638 - In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite
CVE-2026-18581 - A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown
CVE-2026-15055 - In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from inpu
CVE-2026-12185 - In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before int
CVE-2026-3245 - A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrar
CVE-2026-18577 - An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-ce
CVE-2026-10848 - The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys
CVE-2026-9856 - A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbi
CVE-2026-65321 - PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attacker
CVE-2026-10774 - Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key tear
CVE-2026-68583 - luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blo
CVE-2026-68582 - Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerabi
CVE-2026-68581 - Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. B
CVE-2026-68580 - FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection chann
CVE-2026-68579 - FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard cli
CVE-2026-68578 - ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport,
CVE-2026-67357 - ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_serve
CVE-2026-67356 - ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with Hos
CVE-2025-71401 - better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherw
CVE-2025-71400 - better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability
CVE-2025-71399 - Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3,
CVE-2026-12231 - The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-18573 - A flaw was found in the keycloak-services component of Keycloak, which is used for managing authenti
CVE-2026-18572 - Keycloak provides authorization services that allow administrators to restrict access to resources b
CVE-2026-18571 - A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (
CVE-2026-18570 - A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services comp
CVE-2026-16540 - The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk
CVE-2026-16292 - The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on
CVE-2026-16291 - The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the
CVE-2026-16285 - The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorizat
CVE-2026-16273 - The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-expo
CVE-2026-16261 - The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a
CVE-2026-16256 - The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce check
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.