CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-45234 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-100502 - Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint
CVE-2026-100501 - Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerabil
CVE-2026-100419 - gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checko
CVE-2026-100418 - Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/c
CVE-2026-100383 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-100382 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
CVE-2026-100381 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-9313 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-96879 - Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foun
CVE-2026-91769 - PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, wh
CVE-2026-91767 - php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to
CVE-2026-91766 - When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cook
CVE-2026-91765 - cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. A
CVE-2026-6103 - phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check
CVE-2026-57864 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-57443 - SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 an
CVE-2026-17545 - On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, A
CVE-2026-10758 - Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for an
CVE-2026-100417 - RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clip
CVE-2026-100391 - MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy rou
CVE-2026-100390 - Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field wh
CVE-2026-100389 - GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP conne
CVE-2026-100388 - RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file
CVE-2026-100387 - pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB
CVE-2026-100380 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-100379 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wik
CVE-2026-100378 - Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows A
CVE-2026-100377 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Med
CVE-2026-100376 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2026-100369 - CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking c
CVE-2025-1218 - The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet
CVE-2025-14181 - The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer ov
CVE-2026-96878 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-96877 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-96876 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-96875 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-93682 - When the HTTP stream wrapper follows a redirect and the response carries a Location header with an e
CVE-2026-5267 - Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an eve
CVE-2026-57861 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53990 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-100373 - OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.
CVE-2026-100372 - ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor
CVE-2026-100368 - CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations`
CVE-2026-100310 - GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACT
CVE-2026-100208 - Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execut
CVE-2026-97897 - A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unkno
CVE-2026-97896 - A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the fun
CVE-2026-97895 - A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of th
CVE-2026-97064 - X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled
CVE-2026-97063 - X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated end
CVE-2026-97060 - X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub
CVE-2026-84465 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad chec
CVE-2026-84464 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's Externa
CVE-2026-84463 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Know
CVE-2026-84461 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor l
CVE-2026-84460 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticate
CVE-2026-84458 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automa
CVE-2026-63216 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized opti
CVE-2026-63208 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft
CVE-2026-63207 - Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authentic
CVE-2026-63206 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sa
CVE-2026-63205 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or
CVE-2026-63204 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated
CVE-2026-63006 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-control
CVE-2026-61855 - Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certai
CVE-2026-55217 - GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-p
CVE-2026-55214 - GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated
CVE-2026-53629 - GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an att
CVE-2026-53628 - GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an admi
CVE-2026-53627 - GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged
CVE-2026-53626 - GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain con
CVE-2026-53625 - GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a techn
CVE-2026-53610 - GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can c
CVE-2026-49470 - GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based on
CVE-2026-49469 - GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an auth
CVE-2026-48482 - GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administra
CVE-2026-47679 - GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any l
CVE-2026-45801 - GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an auth
CVE-2026-100306 - TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing t
CVE-2026-100305 - TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submis
CVE-2026-100304 - TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermissio
CVE-2026-100303 - TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for
CVE-2026-100192 - X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/se
CVE-2026-97886 - A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d6
CVE-2026-97885 - A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3
CVE-2026-97884 - A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c
CVE-2026-97883 - A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec09
CVE-2026-97882 - A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d6
CVE-2026-93366 - Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated u
CVE-2026-91841 - A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user
CVE-2026-91840 - A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to esca
CVE-2026-91839 - A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fo
CVE-2026-91838 - A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivilege
CVE-2026-84462 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filte
CVE-2026-65828 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destr
CVE-2026-61525 - Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's ses
CVE-2026-56735 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad
CVE-2026-56734 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated
CVE-2026-56733 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this i
CVE-2026-56732 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in
CVE-2026-56731 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege
CVE-2026-56730 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization
CVE-2026-56728 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access
CVE-2026-56727 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zamma
CVE-2026-56726 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerabili
CVE-2026-56725 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unaut
CVE-2026-97879 - A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is
CVE-2026-97878 - A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anon
CVE-2026-97877 - A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the functi
CVE-2026-97871 - A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function
CVE-2026-95835 - Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a
CVE-2026-95834 - Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.4
CVE-2026-94445 - A malicious txtar could escape the intended execution context and force arbitrary writes to the play
CVE-2026-93365 - Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated u
CVE-2026-93364 - Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users w
CVE-2026-93363 - The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control
CVE-2026-91837 - A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivi
CVE-2026-89032 - BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic
CVE-2026-80432 - Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 b
CVE-2026-67421 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and
CVE-2026-67420 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and
CVE-2026-67419 - RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a q
CVE-2026-67415 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter
CVE-2026-67413 - RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the
CVE-2026-67412 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3
CVE-2026-67411 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and
CVE-2026-67410 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret
CVE-2026-67409 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.
CVE-2026-67408 - RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Mana
CVE-2026-67407 - RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 and 4.2.9 and 4.1.14 and 4.0.23
CVE-2026-67406 - RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, Sho
CVE-2026-67242 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp
CVE-2026-67241 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management
CVE-2026-67239 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.
CVE-2026-67237 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 ins
CVE-2026-67234 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1
CVE-2026-67230 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6,
CVE-2026-67227 - RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1
CVE-2026-67226 - RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-on
CVE-2026-67225 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6,
CVE-2026-67223 - RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2,
CVE-2026-67222 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6,
CVE-2026-66078 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.
CVE-2026-66073 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.
CVE-2026-66071 - RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.
CVE-2026-61837 - RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQ
CVE-2026-56729 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB
CVE-2026-56724 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue
CVE-2026-56723 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who c
CVE-2026-18320 - Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG an
CVE-2026-18312 - Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata withou
CVE-2026-18311 - Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML saniti
CVE-2026-100248 - The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of
CVE-2026-100237 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-97869 - A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerabi
CVE-2026-97868 - A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is t
CVE-2026-97469 - PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly c
CVE-2026-96874 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-92161 - FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other pro
CVE-2026-85293 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-85292 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-85291 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-85290 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-85289 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-85274 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-67236 - RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /l
CVE-2026-62262 - Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earl
CVE-2026-54790 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-50547 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-49850 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-44642 - Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_
CVE-2026-42324 - Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/
CVE-2026-42323 - Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/
CVE-2026-42322 - Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/
CVE-2026-39372 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-39353 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-33639 - InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments.
CVE-2026-100230 - Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on
CVE-2026-97866 - A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknow
CVE-2026-96812 - Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior
CVE-2026-93306 - IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW10
CVE-2026-93030 - FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XM
CVE-2026-88389 - Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString(
CVE-2026-84882 - IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle
CVE-2026-84862 - IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job s
CVE-2026-60101 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60100 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60099 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60098 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60097 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60096 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-98162 - In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection
CVE-2026-98161 - In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH bef
CVE-2026-98160 - In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatc
CVE-2026-97865 - A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Even
CVE-2026-97864 - A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the functi
CVE-2026-97222 - A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook cont
CVE-2026-93834 - A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main
CVE-2026-93647 - An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address.
CVE-2026-93643 - When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an
CVE-2026-93642 - An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z
CVE-2026-93641 - An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z
CVE-2026-85750 - Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload
CVE-2026-85542 - IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle
CVE-2026-85029 - IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, del
CVE-2026-84893 - IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticat
CVE-2026-84884 - IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible pla
CVE-2026-80431 - Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 bef
CVE-2026-80430 - Improper Link Resolution Before File Access in the drag source staging path of the drag and drop pro
CVE-2026-100190 - The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site sc
CVE-2026-100187 - The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that
CVE-2026-100177 - The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authori
CVE-2026-100176 - The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Us
CVE-2026-100174 - The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-s
CVE-2026-100172 - The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerabi
CVE-2026-100079 - In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister de
CVE-2026-100078 - In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correc
CVE-2026-100077 - In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before reti
CVE-2026-100076 - In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_fr
CVE-2026-100075 - In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ct
CVE-2026-100074 - In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as
CVE-2026-100073 - In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow
CVE-2026-100072 - In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_ge
CVE-2026-100071 - In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on
CVE-2026-100070 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind o
CVE-2026-95832 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour c
CVE-2026-88421 - Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0
CVE-2026-88420 - A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL p
CVE-2026-79153 - Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in
CVE-2026-78902 - Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute
CVE-2026-52622 - An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES
CVE-2026-51773 - An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker pr
CVE-2026-51772 - A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance.
CVE-2025-51457 - D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within t
CVE-2026-97622 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-62062. Reason:
CVE-2026-98159 - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: validate CL
CVE-2026-98158 - In the Linux kernel, the following vulnerability has been resolved: ppp_async: drop the errored fra
CVE-2026-98157 - In the Linux kernel, the following vulnerability has been resolved: EDAC/device_sysfs: Use kstrtoui
CVE-2026-98156 - In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use the DMA API for
CVE-2026-98155 - In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Address potential o
CVE-2026-98154 - In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix -EIO cleanup ord
CVE-2026-98153 - In the Linux kernel, the following vulnerability has been resolved: nvme: fix racy access to FDP pl
CVE-2026-98152 - In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix queue leak when
CVE-2026-98151 - In the Linux kernel, the following vulnerability has been resolved: bpf: Fix REG INVARIANTS VIOLATI
CVE-2026-98150 - In the Linux kernel, the following vulnerability has been resolved: bpf: Fix BPF_F_CPU validation f
CVE-2026-98149 - In the Linux kernel, the following vulnerability has been resolved: bpf: Fix percpu map update inde
CVE-2026-98148 - In the Linux kernel, the following vulnerability has been resolved: drm/gud: validate GUD_ROTATION_
CVE-2026-98147 - In the Linux kernel, the following vulnerability has been resolved: printk: Don't WARN on kthread_r
CVE-2026-98146 - In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Remove __counted
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware