CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
27067 CVEs gefunden (Seite 26/109)

CVE-2026-15939 - The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permissio

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 2.7
2.7

CVE-2026-15385 - The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX acti

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-15248 - The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-15241 - The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-15236 - The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to th

🏢 Google 📅 2.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-15206 - The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-15151 - The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-14938 - The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-14920 - ## Summary

🏢 Sonstige 📅 2.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-14864 - The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-14841 - The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-14817 - The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option value

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-13389 - The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-12586 - The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check o

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-11872 - The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 4.3
4.3

CVE-2025-15675 - The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign ima

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 4.8
4.8

CVE-2026-9335 - A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disc

🏢 F5 📅 2.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-8457 - The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all ve

🏢 Apple 📅 2.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-18352 - The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-13339 - The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to

🏢 Wordpress 📅 2.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-17002 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-18556 - Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Au

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-55735 - Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated att

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-55734 - Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.P

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-55733 - Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-54894 - Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67355 - guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the reques

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-67354 - guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Redirect

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-67353 - guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-67352 - luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url pa

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.6
7.6

CVE-2026-67344 - ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ...

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-67343 - ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-67342 - ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for t

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-67341 - ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUN

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-67340 - ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-67339 - guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from o

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-67338 - JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manage

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-67337 - better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when sess

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-67336 - better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and m

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.7
8.7

CVE-2026-67335 - better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonc

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-67334 - better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, ano

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 3.8
3.8

CVE-2026-67333 - better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validat

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-67332 - @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authoriza

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-67331 - better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM provider

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.3
8.3

CVE-2026-67330 - @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-be

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-67329 - @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contai

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-67328 - @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SS

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-67327 - better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-bet

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.3
8.3

CVE-2026-67326 - GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writ

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.0
7.0

CVE-2026-67325 - GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-67324 - GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of -

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-67323 - GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 8.4
8.4

CVE-2026-67322 - GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The

🏢 Aws 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67321 - axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypas

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67320 - axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controll

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67319 - axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request opt

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67318 - axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67317 - axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request b

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67316 - axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction whe

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67315 - axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67314 - axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subf

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67313 - axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing For

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67312 - axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67311 - Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource i

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-67310 - OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object referenc

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-67309 - Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes In

🏢 Nginx 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67308 - Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows

🏢 Wazuh 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67307 - Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_

🏢 Wazuh 📅 1.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-67306 - FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar R

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-67305 - FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-67304 - FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67303 - FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturn

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-67302 - FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the r

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-67301 - FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67300 - FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update m

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67299 - FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy f

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67298 - FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel h

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67297 - FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: ch

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67296 - FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67295 - FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, a

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-67294 - FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certific

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-67293 - FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname valida

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-67292 - FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket trans

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-67291 - FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_pro

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67290 - FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder wh

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-67289 - FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-67288 - FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request d

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-66402 - FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity valid

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-66401 - FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-u

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 2.1
2.1

CVE-2026-2411 - Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characterist

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-10773 - The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a stat

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-10772 - Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-20

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2025-71404 - better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) v

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2025-71403 - better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 7.1
7.1

CVE-2025-71402 - better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-sessi

🏢 Sonstige 📅 1.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-18536 - Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data:

🏢 Aws 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-6453 - The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and i

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-18435 - The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-18344 - The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Script

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-18062 - The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-18059 - The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensi

🏢 Google 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-17605 - The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerabl

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.6
6.6

CVE-2026-17580 - The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywher

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-17571 - The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-17555 - The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_da

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-16685 - The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Sh

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-16684 - The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fa

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-16635 - The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-16614 - The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulner

🏢 Google 📅 1.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-16144 - The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote C

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-16091 - The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plug

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-16090 - The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plug

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-16087 - The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to se

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-15964 - The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthent

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-15951 - The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-15950 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15662 - The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15649 - The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Si

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15645 - The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Si

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15644 - The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Si

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15601 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-15450 - The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file de

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-15052 - The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vul

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-15018 - The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'f

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-13458 - The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-11995 - The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder p

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-10782 - The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2025-14073 - The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosu

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-2916 - The Jeg Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in al

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-15988 - The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.8
8.8

CVE-2025-14469 - The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-15932 - The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-15368 - The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-15262 - The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fiel

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-15244 - The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-15234 - The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode a

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-14840 - The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-14839 - The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-status

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-14836 - The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit o

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-14823 - The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authori

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 2.2
2.2

CVE-2026-14822 - The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorizati

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-14596 - The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supp

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-14561 - The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-14315 - The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorizati

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-14309 - The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-tim

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-14292 - The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title befor

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-14214 - The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict wh

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 2.7
2.7

CVE-2026-14197 - The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 3.8
3.8

CVE-2026-14195 - The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handle

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 2.7
2.7

CVE-2026-13729 - The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on som

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-13725 - The Dynamic Pricing With Discount Rules for WooCommerce WordPress plugin before 5.0.0 does not valid

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-13604 - The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-13596 - The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a us

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-13329 - The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capabili

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-13158 - The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded duri

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-13157 - The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-12966 - The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requeste

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-12696 - The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field bef

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-11882 - The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth a

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 3.7
3.7

CVE-2026-10827 - The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style a

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 3.5
3.5

CVE-2025-15669 - The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.8
4.8

CVE-2026-3141 - The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a mis

🏢 Linux 📅 1.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-7623 - The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulne

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-15414 - The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in vers

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-15403 - The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection vi

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-15006 - The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin f

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-13362 - The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scr

🏢 Wordpress 📅 1.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-9044 - An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vul

🏢 Tp-link 📅 31.7.2026 📊 CVSS: 8.0
8.0

CVE-2026-54909 - pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-54787 - sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 3.1
3.1

CVE-2026-54785 - gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official

🏢 Google 📅 31.7.2026 📊 CVSS: 6.2
6.2

CVE-2026-54768 - WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user f

🏢 Wordpress 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-53573 - GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-45377 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-45376 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0

🏢 Postgresql 📅 31.7.2026 📊 CVSS: 5.5
5.5

CVE-2026-45330 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 4.9
4.9

CVE-2026-34641 - Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.8
7.8

CVE-2026-68771 - ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node tha

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-52371 - A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-52232 - A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-52134 - An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows at

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-51953 - An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management mo

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.4
7.4

CVE-2026-45086 - Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-68770 - sentence-transformers contains a security control bypass vulnerability that allows attackers to achi

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-65981 - Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.1
7.1

CVE-2026-51785 - An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary co

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-50986 - PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-38713 - TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR300

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-38710 - TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in th

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.2
7.2

CVE-2026-38708 - TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR300

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2025-69948 - SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_gro

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2025-69946 - SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-65841 - Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-62999 - Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-62959 - Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-62324 - Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodi

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-55825 - Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 3.1
3.1

CVE-2026-53599 - REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedE

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-53551 - free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (A

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-53510 - Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates atta

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-38711 - TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR300

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-18394 - Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow re

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.4
7.4

CVE-2026-57232 - Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 3.1
3.1

CVE-2026-55824 - Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the cr

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 2.6
2.6

CVE-2026-53505 - Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:pr

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-53504 - Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filt

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-53503 - Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:co

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-53502 - Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-53501 - Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC valid

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 8.2
8.2

CVE-2026-53500 - Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 8.2
8.2

CVE-2026-25552 - Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote att

🏢 Nginx 📅 31.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-18481 - Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might a

🏢 Aws 📅 31.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-18321 - Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 4.7
4.7

CVE-2026-55100 - hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-54737 - @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash d

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-54729 - DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-54725 - vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.6
9.6

CVE-2026-34497 - Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johns

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-34495 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-34490 - Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on And

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.5
5.5

CVE-2026-21662 - Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employe

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-67822 - Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSID

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-58048 - Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-58047 - HTTP Smuggling in cPanel allows potential leak of credentials.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-54707 - OnionShare is an open source tool that lets you securely and anonymously share files, host websites,

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-54706 - OnionShare is an open source tool that lets you securely and anonymously share files, host websites,

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 4.8
4.8

CVE-2026-52856 - Wings is the server control plane for Pterodactyl, a free, open-source game server management panel.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-52855 - Wings is the server control plane for Pterodactyl, a free, open-source game server management panel.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.9
9.9

CVE-2026-67607 - LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-1114

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-59232 - Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenti

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-59231 - Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows au

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-56571 - HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, nul

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-56570 - HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive inf

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-56569 - HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposur

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 4.0
4.0

CVE-2026-56568 - HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vul

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-56567 - HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the publi

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.1
5.1

CVE-2026-52857 - Wings is the server control plane for Pterodactyl, a free, open-source game server management panel.

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.5
5.5

CVE-2026-18141 - A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 8.2
8.2

CVE-2026-17566 - pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-s

🏢 Postgresql 📅 31.7.2026 📊 CVSS: 9.9
9.9

CVE-2026-17351 - The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assist

🏢 Postgresql 📅 31.7.2026 📊 CVSS: 9.0
9.0

CVE-2026-17350 - The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-17349 - /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, wh

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.6
9.6

CVE-2026-17348 - In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; t

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-17347 - The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an ex

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-17346 - The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pg

🏢 Postgresql 📅 31.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-16504 - Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a de

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-16503 - Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is publishe

🏢 Postgresql 📅 31.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-10686 - Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 5.8
5.8

CVE-2025-62347 - HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-67350 - Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthentic

🏢 Sonstige 📅 31.7.2026 📊 CVSS: 4.3
4.3
«« « Zurück Seite 26 von 109 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.