CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-51287 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51286 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51285 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51284 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51283 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51282 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51281 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51280 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51279 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51278 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51277 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51276 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51265 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51264 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51262 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51258 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51257 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51256 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51255 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51253 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51250 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51249 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51248 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51247 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51246 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51245 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51243 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51242 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51241 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51240 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51239 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51238 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51237 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51236 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51234 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51233 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51232 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51231 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51230 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51229 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-18446 - fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI a
CVE-2026-10685 - The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth
CVE-2026-65636 - Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) all
CVE-2026-28145 - Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allow
CVE-2026-28144 - Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retri
CVE-2026-9611 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-68577 - Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID
CVE-2026-68576 - Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID
CVE-2026-68575 - Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID
CVE-2026-68574 - Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID
CVE-2026-18358 - A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is
CVE-2026-17592 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-17561 - Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecom
CVE-2026-15227 - Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenti
CVE-2026-46594 - A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Po
CVE-2026-46593 - A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neu
CVE-2025-67651 - A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers script
CVE-2025-67650 - An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Im
CVE-2025-67649 - A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neut
CVE-2026-64607 - HttpClient based on the classic i/o model fails to correctly release the underlying connection back
CVE-2026-62391 - The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server
CVE-2026-44615 - Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authe
CVE-2026-17567 - The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo
CVE-2026-16843 - Some Hikvision Networking Products are vulnerable to authenticated command execution due to insuffic
CVE-2026-18437 - The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to
CVE-2026-18436 - The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and inclu
CVE-2026-15722 - A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_fro
CVE-2026-11770 - A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search
CVE-2026-10079 - A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubern
CVE-2026-65313 - A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations
CVE-2026-65311 - The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an
CVE-2026-65310 - ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes
CVE-2026-65309 - ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords usi
CVE-2026-18218 - A flaw was found in the TokenManager component of the Keycloak identity management service. When an
CVE-2026-18217 - A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access
CVE-2026-18215 - Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a s
CVE-2026-18214 - Keycloak allows users to log in using Google accounts and can be configured to only allow users from
CVE-2026-18211 - A flaw was found in the secure-client-uris client policy executor within Keycloak core services. Thi
CVE-2026-18209 - A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC)
CVE-2026-18208 - A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keyclo
CVE-2026-18206 - A flaw was found in the keycloak-services component of Keycloak, which provides identity and access
CVE-2026-18203 - A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management
CVE-2026-16105 - A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certai
CVE-2026-8155 - The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private
CVE-2026-18452 - DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauth
CVE-2026-16236 - The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up
CVE-2026-15381 - The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter be
CVE-2026-15258 - The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise a
CVE-2026-15209 - The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ti
CVE-2026-15048 - The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its A
CVE-2026-14931 - The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor
CVE-2026-14930 - The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or owners
CVE-2026-14929 - The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply befo
CVE-2026-14928 - The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks b
CVE-2026-14927 - The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorizat
CVE-2026-14922 - WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and includin
CVE-2026-14921 - The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering
CVE-2026-14919 - The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting tes
CVE-2026-14862 - The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-tick
CVE-2026-14849 - The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and pay
CVE-2026-14847 - The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonc
CVE-2026-14845 - The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauth
CVE-2026-14843 - The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized
CVE-2026-14834 - The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an u
CVE-2026-14833 - The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data a
CVE-2026-14830 - The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout
CVE-2026-14554 - The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape paramete
CVE-2026-14483 - The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary Fi
CVE-2026-14333 - The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessibl
CVE-2026-14319 - The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint
CVE-2026-14317 - The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways t
CVE-2026-13609 - The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted
CVE-2026-13393 - The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certai
CVE-2026-13392 - The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget d
CVE-2026-12721 - The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from t
CVE-2026-12720 - The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when i
CVE-2026-12697 - The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs
CVE-2026-12695 - The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password
CVE-2026-12376 - The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to t
CVE-2026-12251 - The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities
CVE-2026-63223 - CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload valid
CVE-2026-63222 - CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without
CVE-2026-63221 - CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch()
CVE-2026-56673 - ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to
CVE-2026-56672 - ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file}
CVE-2026-56671 - ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.2
CVE-2026-56670 - ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.2
CVE-2026-63220 - CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure
CVE-2026-62323 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidat
CVE-2026-55502 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/p
CVE-2026-55499 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share
CVE-2026-55497 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbna
CVE-2026-55496 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/sea
CVE-2026-55495 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIV
CVE-2026-43833 - Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43832 - Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43831 - Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43830 - Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-43829 - Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-6890 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-6889 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18157 - A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the s
CVE-2026-14541 - An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider co
CVE-2026-14540 - A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool compon
CVE-2026-14539 - An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-
CVE-2026-14538 - An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql too
CVE-2026-14537 - Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versio
CVE-2026-58039 - A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files o
CVE-2026-66720 - The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC
CVE-2026-66421 - OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated
CVE-2026-66420 - MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that al
CVE-2026-66369 - The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single un
CVE-2026-66364 - The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauth
CVE-2026-66360 - The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mod
CVE-2026-66349 - The MMS server connection handler contains a flaw in its processing of BER-encoded request data. Wh
CVE-2026-65423 - An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a
CVE-2026-65421 - The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attack
CVE-2026-63550 - The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within co
CVE-2026-63362 - An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a re
CVE-2026-63035 - A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an
CVE-2026-63033 - A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body
CVE-2026-61893 - A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes T
CVE-2026-56758 - The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment.
CVE-2026-10031 - SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to
CVE-2026-68563 - A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevat
CVE-2026-68562 - A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a m
CVE-2026-64816 - RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File:
CVE-2026-63559 - An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a
CVE-2026-62845 - Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and
CVE-2026-62246 - Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a Te
CVE-2026-5846 - The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corr
CVE-2026-38709 - TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR300
CVE-2026-18064 - An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) ap
CVE-2026-12562 - The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug int
CVE-2026-68503 - LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.15
CVE-2026-68502 - LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.15
CVE-2026-68501 - Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.
CVE-2026-68500 - Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.
CVE-2026-68499 - re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's Str
CVE-2026-66803 - Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a ne
CVE-2026-66418 - OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthent
CVE-2026-61526 - AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions
CVE-2026-55777 - GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix syst
CVE-2026-55768 - GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix syst
CVE-2026-54715 - GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix syst
CVE-2026-52539 - Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environmen
CVE-2026-35847 - An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping
CVE-2025-69947 - SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
CVE-2025-69941 - SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=
CVE-2025-69938 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the param
CVE-2025-69937 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpo
CVE-2025-69936 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CVE-2025-69935 - CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and reven
CVE-2025-69934 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=
CVE-2025-69933 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1
CVE-2025-69931 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?
CVE-2025-69930 - CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.
CVE-2025-65342 - code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city
CVE-2025-65341 - Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
CVE-2025-65336 - Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price
CVE-2026-67594 - Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthen
CVE-2026-67550 - re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 valid
CVE-2026-67530 - WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhoo
CVE-2026-67529 - OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time
CVE-2026-67528 - OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/cust
CVE-2026-67527 - OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/wo
CVE-2026-67208 - Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remo
CVE-2026-67207 - Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController t
CVE-2026-67206 - Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController tha
CVE-2026-66756 - Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika:
CVE-2026-66755 - Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 thr
CVE-2026-65835 - Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, afte
CVE-2026-65834 - Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfig
CVE-2026-12946 - IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the
CVE-2026-11536 - IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability i
CVE-2026-10569 - IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevO
CVE-2025-51684 - CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sani
CVE-2026-66416 - Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attac
CVE-2026-66415 - Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that al
CVE-2026-66066 - Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2
CVE-2026-64870 - MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateSto
CVE-2026-61536 - Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3,
CVE-2026-59881 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the
CVE-2026-51272 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-48499 - Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path
CVE-2026-18245 - Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allo
CVE-2026-18140 - Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62
CVE-2026-15978 - SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang
CVE-2026-15977 - SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return A
CVE-2026-15976 - SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace reposit
CVE-2026-15974 - SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completio
CVE-2026-15971 - SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a s
CVE-2026-15969 - SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickle
CVE-2026-14227 - An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to
CVE-2026-13444 - IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector
CVE-2026-13435 - IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the Pyt
CVE-2026-12943 - IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management sys
CVE-2026-12942 - IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the s
CVE-2026-12733 - IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper res
CVE-2026-12118 - IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to
CVE-2026-11904 - IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
CVE-2026-10700 - IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its
CVE-2026-10695 - IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non
CVE-2026-10545 - IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an a
CVE-2026-10535 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid
CVE-2025-36374 - IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing
CVE-2025-0152 - IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6
CVE-2024-40683 - IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.
CVE-2024-25039 - IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6
CVE-2026-9322 - IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.