CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-66653 - Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
CVE-2026-66478 - Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
CVE-2026-66472 - Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
CVE-2026-66471 - Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
CVE-2026-66469 - Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
CVE-2026-66468 - Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versio
CVE-2026-66467 - Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-66466 - Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Up
CVE-2026-66465 - Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVE-2026-66464 - Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
CVE-2026-66463 - Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
CVE-2026-66462 - Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
CVE-2026-66461 - Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
CVE-2026-66460 - Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
CVE-2026-66459 - Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
CVE-2026-66458 - Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
CVE-2026-66456 - Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
CVE-2026-66455 - Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CVE-2026-66454 - Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
CVE-2026-66453 - Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
CVE-2026-66450 - Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
CVE-2026-66449 - Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
CVE-2026-66446 - Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
CVE-2026-66444 - Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
CVE-2026-66443 - Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
CVE-2026-66441 - Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
CVE-2026-66436 - Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
CVE-2026-66432 - Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
CVE-2026-66431 - Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLIN
CVE-2026-66430 - Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66429 - Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 vers
CVE-2026-66426 - Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
CVE-2026-66424 - Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
CVE-2026-65582 - Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
CVE-2026-65580 - Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-61984 - Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
CVE-2026-61980 - Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.
CVE-2026-61979 - Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
CVE-2026-61978 - Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.
CVE-2026-61974 - Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
CVE-2026-61969 - Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
CVE-2026-61967 - Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61966 - Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
CVE-2026-61965 - Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-61962 - Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVE-2026-61960 - Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
CVE-2026-48702 - Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.
CVE-2026-28189 - Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
CVE-2026-28188 - Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
CVE-2026-28187 - Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assista
CVE-2026-28186 - Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
CVE-2026-28185 - Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CVE-2026-28184 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-28182 - Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
CVE-2026-28181 - Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
CVE-2026-28176 - Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
CVE-2026-28175 - Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions
CVE-2026-28174 - Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-28173 - Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
CVE-2026-28170 - Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
CVE-2026-28168 - Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-28161 - Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
CVE-2026-28159 - Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28158 - Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-28157 - Subscriber Path Traversal in Do Lasso <= 358 versions.
CVE-2026-28156 - Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28155 - Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
CVE-2026-28149 - Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
CVE-2026-28148 - Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVE-2026-28142 - Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
CVE-2026-28008 - Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions
CVE-2026-28004 - Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
CVE-2026-28003 - Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
CVE-2026-28002 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-28001 - Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-27999 - Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
CVE-2026-27544 - Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVE-2026-27543 - Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
CVE-2026-27539 - Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
CVE-2026-27538 - Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-27537 - Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
CVE-2026-27536 - Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
CVE-2026-27535 - Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
CVE-2026-27380 - Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
CVE-2026-27345 - Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVE-2026-21832 - HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection i
CVE-2026-19716 - Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1
CVE-2025-62318 - HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenc
CVE-2025-62315 - HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-
CVE-2025-62314 - HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation cont
CVE-2026-73585 - A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration s
CVE-2026-73584 - A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during
CVE-2026-73583 - A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe des
CVE-2026-6471 - Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION priv
CVE-2026-6470 - Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of servi
CVE-2026-6469 - Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of d
CVE-2026-6464 - Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit executio
CVE-2026-49827 - WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1
CVE-2026-49478 - Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC)
CVE-2026-19385 - Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator
CVE-2026-18408 - Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server
CVE-2026-18024 - Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after th
CVE-2026-16241 - Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary den
CVE-2026-16239 - Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as th
CVE-2026-16238 - Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitr
CVE-2026-15742 - Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of add
CVE-2026-15741 - SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a s
CVE-2026-14681 - Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GS
CVE-2026-14680 - Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary c
CVE-2026-14679 - Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unkno
CVE-2026-14678 - Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. Th
CVE-2026-14677 - Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause
CVE-2026-14676 - Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary c
CVE-2026-14673 - Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege t
CVE-2026-14672 - Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to
CVE-2026-14671 - Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as t
CVE-2026-14670 - Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute
CVE-2026-14669 - Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to ex
CVE-2026-14668 - Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object c
CVE-2026-14666 - Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database owner
CVE-2026-14664 - Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the o
CVE-2026-14663 - Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via di
CVE-2026-14662 - Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged dat
CVE-2025-52640 - HCL AION is affected by a vulnerability where the shared storage used by product components is archi
CVE-2026-73629 - Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url
CVE-2026-73628 - Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in
CVE-2026-73627 - JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin
CVE-2026-73626 - JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in Py
CVE-2026-73625 - GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_o
CVE-2026-73624 - GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.d
CVE-2026-73623 - GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --tem
CVE-2026-73622 - GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submo
CVE-2026-73621 - GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, w
CVE-2026-73620 - GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReferenc
CVE-2026-73619 - GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that
CVE-2026-73618 - Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query executio
CVE-2026-73617 - Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integratio
CVE-2026-73616 - OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm admi
CVE-2026-73615 - Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolic
CVE-2026-73614 - Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evalu
CVE-2026-73613 - filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS u
CVE-2026-73612 - File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, r
CVE-2026-73611 - File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authent
CVE-2026-73610 - SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter th
CVE-2026-73609 - SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabe
CVE-2026-73608 - SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or maste
CVE-2026-73607 - SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/ge
CVE-2026-73606 - SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getR
CVE-2026-73605 - SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoi
CVE-2026-73604 - Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/cr
CVE-2026-73603 - Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech end
CVE-2026-73602 - Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allo
CVE-2026-73601 - Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node w
CVE-2026-73488 - Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /
CVE-2026-73487 - Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent n
CVE-2026-73486 - Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV p
CVE-2026-73485 - Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows
CVE-2026-73484 - Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to
CVE-2026-73483 - Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in t
CVE-2026-45819 - baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or co
CVE-2026-18368 - In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling o
CVE-2026-16455 - In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running
CVE-2026-12263 - Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are
CVE-2026-59507 - : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Impro
CVE-2026-59506 - : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to P
CVE-2026-59505 - : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (develope
CVE-2026-59504 - : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon t
CVE-2026-59503 - : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Informat
CVE-2026-59502 - : Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed
CVE-2026-59501 - : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (develope
CVE-2026-59500 - : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (develope
CVE-2026-59499 - : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Genera
CVE-2026-19484 - @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthent
CVE-2026-11970 - This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExt
CVE-2026-19696 - Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of ser
CVE-2026-19695 - Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
CVE-2026-19694 - TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
CVE-2026-19481 - @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who ca
CVE-2026-16459 - Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all vers
CVE-2026-16458 - Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since
CVE-2026-15413 - The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it
CVE-2026-14332 - The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a cap
CVE-2026-14298 - Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail t
CVE-2026-3639 - The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-11840 - Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions be
CVE-2026-18622 - Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, i
CVE-2026-18146 - The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo
CVE-2026-3835 - The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthoriz
CVE-2026-19088 - The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect o
CVE-2026-18945 - The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its
CVE-2026-14213 - The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that
CVE-2026-14182 - The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly val
CVE-2026-13610 - The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unaut
CVE-2026-13328 - The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on i
CVE-2026-72506 - VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains
CVE-2026-19182 - An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a l
CVE-2026-19135 - A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-
CVE-2026-18728 - A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, spec
CVE-2026-0301 - An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® s
CVE-2026-0299 - Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a loc
CVE-2026-0298 - An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) co
CVE-2026-0297 - A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a m
CVE-2026-0296 - Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an u
CVE-2026-0295 - A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenti
CVE-2026-0294 - A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Wind
CVE-2026-0293 - A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with
CVE-2026-0292 - An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Ag
CVE-2026-0291 - An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma
CVE-2026-0290 - An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Pri
CVE-2026-0289 - A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Bro
CVE-2026-50544 - NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version
CVE-2026-49819 - UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentica
CVE-2026-49473 - @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Ce
CVE-2026-48791 - sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0
CVE-2026-46688 - The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior t
CVE-2026-46382 - The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior t
CVE-2026-17431 - PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the outpu
CVE-2026-16770 - PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in
CVE-2026-71194 - In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving re
CVE-2026-71193 - In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the dupl
CVE-2026-49481 - UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability
CVE-2026-47718 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`,
CVE-2026-47717 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3
CVE-2026-15424 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-15141 - The web interface of the affected device relies on the HTTP referrer header as part of request valid
CVE-2026-7366 - IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21
CVE-2026-73519 - WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every buil
CVE-2026-73501 - kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() i
CVE-2026-73500 - etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33
CVE-2026-73499 - etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33
CVE-2026-73498 - MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).
CVE-2026-73495 - blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0
CVE-2026-73493 - Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.2
CVE-2026-73492 - Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, buil
CVE-2026-71846 - A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granti
CVE-2026-71473 - A flaw was found in the `search-v2-operator` component. A user with specific administrative permissi
CVE-2026-71471 - A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub clust
CVE-2026-71469 - A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests
CVE-2026-19003 - A data source definition containing an over-length file path setting may cause the MongoDB BI Connec
CVE-2026-18750 - vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and
CVE-2026-18749 - The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttac
CVE-2026-18744 - Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberSt
CVE-2026-18727 - A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflo
CVE-2026-18726 - A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local networ
CVE-2026-17485 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain s
CVE-2026-10534 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF
CVE-2024-27253 - IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass secur
CVE-2026-73491 - Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, buil
CVE-2026-73490 - Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, buil
CVE-2026-73430 - Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can caus
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware