CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-68755 - A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68754 - A repository publisher without delete permission may modify protected package content under specific
CVE-2026-68753 - An unauthenticated user may access restricted Artifactory content when a credentialed remote reposit
CVE-2026-68752 - A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-67287 - Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An
CVE-2026-67286 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in S
CVE-2026-66382 - An authenticated user may write files outside the intended Artifactory work directory under specific
CVE-2026-66381 - A repository reader with cache-deploy permission may access content outside a configured upstream pa
CVE-2026-66380 - An authenticated user without repository read permission may access private OCI referrer metadata un
CVE-2026-66379 - An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378 - An authenticated user without repository read permission may access private NuGet metadata under spe
CVE-2026-66377 - An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66376 - Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66375 - A low-privilege authenticated user may permanently remove protected internal metadata across reposit
CVE-2026-50561 - Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platfor
CVE-2026-49349 - regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a regi
CVE-2026-49262 - In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy ro
CVE-2026-47234 - Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is e
CVE-2026-47233 - Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorIn
CVE-2026-18171 - Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest containe
CVE-2026-14479 - A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger
CVE-2026-14478 - A maliciously created executable, when executed on the victim's machine, may allow a local low-privi
CVE-2025-59324 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption an
CVE-2025-59323 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataSt
CVE-2025-59322 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors an
CVE-2025-59321 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails
CVE-2025-59320 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format
CVE-2025-59319 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intende
CVE-2026-67285 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Bu
CVE-2026-47232 - Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=exp
CVE-2026-47231 - Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-file
CVE-2026-47230 - Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-file
CVE-2026-47229 - Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.ph
CVE-2026-47228 - Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` reg
CVE-2026-47227 - Admidio is an open-source user management solution. `modules/categories.php` checks that the supplie
CVE-2026-16999 - Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Docu
CVE-2025-59327 - In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LU
CVE-2025-59326 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections acros
CVE-2025-59325 - CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allo
CVE-2026-71408 - A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 throu
CVE-2026-71407 - A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 throug
CVE-2026-70468 - A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.
CVE-2026-70467 - A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 thro
CVE-2026-70466 - A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, Forti
CVE-2026-57858 - Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in
CVE-2026-53996 - NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerabil
CVE-2026-47226 - Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidi
CVE-2026-26035 - An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through
CVE-2026-70560 - Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability
CVE-2026-70465 - A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet F
CVE-2026-18044 - The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient li
CVE-2026-17008 - The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver,
CVE-2026-16990 - The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-config
CVE-2026-16747 - The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission RE
CVE-2026-16621 - The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that pay
CVE-2026-15213 - The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its conve
CVE-2026-15045 - The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied w
CVE-2026-11325 - Description Cloudflare was recently notified by external researchers of vulnerabilities in this a
CVE-2026-68868 - The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied th
CVE-2026-67284 - Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud
CVE-2026-64955 - When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as form
CVE-2026-64952 - The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check
CVE-2026-64951 - A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expa
CVE-2026-18663 - A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed contro
CVE-2026-18652 - Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design st
CVE-2026-67283 - Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud
CVE-2026-67282 - Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unaut
CVE-2026-19566 - Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via un
CVE-2026-19426 - POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote a
CVE-2025-41771 - An authenticated attacker with low privileges can access an endpoint in the controller’s web interfa
CVE-2025-41770 - An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication in
CVE-2025-41769 - The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the defa
CVE-2026-66659 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-19594 - Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0
CVE-2026-19217 - The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting
CVE-2026-19073 - The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capab
CVE-2026-19052 - The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two ad
CVE-2026-19050 - The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and d
CVE-2026-18962 - The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is a
CVE-2026-18943 - The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its
CVE-2026-18789 - The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content ex
CVE-2026-18474 - The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before u
CVE-2026-18391 - The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unse
CVE-2026-18366 - The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, di
CVE-2026-18230 - The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before u
CVE-2026-18057 - The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled val
CVE-2026-18049 - The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce
CVE-2026-18048 - The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled val
CVE-2026-18046 - The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administr
CVE-2026-18035 - The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to RES
CVE-2026-17013 - The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter
CVE-2026-16977 - The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-contr
CVE-2026-16737 - The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership chec
CVE-2026-16538 - The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collec
CVE-2026-16294 - The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of
CVE-2026-16253 - The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authoriz
CVE-2026-16066 - The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field b
CVE-2026-16051 - The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages inst
CVE-2026-15388 - The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administr
CVE-2026-15249 - The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-s
CVE-2026-15039 - The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of i
CVE-2026-14925 - The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of it
CVE-2026-14859 - The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability
CVE-2026-14858 - The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning o
CVE-2026-14857 - The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before all
CVE-2026-13613 - The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied para
CVE-2026-13612 - The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the record
CVE-2026-13177 - The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order re
CVE-2026-13171 - The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-l
CVE-2026-13168 - The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer rec
CVE-2026-12976 - The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course be
CVE-2026-64954 - Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule
CVE-2026-12235 - The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when link
CVE-2026-12234 - The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/
CVE-2026-12233 - The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted
CVE-2026-12232 - The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/
CVE-2025-15687 - A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb o
CVE-2026-9318 - tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export funct
CVE-2026-19588 - Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buf
CVE-2026-19587 - Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allo
CVE-2026-18961 - The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for
CVE-2025-15686 - A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg
CVE-2025-15685 - A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functiona
CVE-2025-15684 - A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the f
CVE-2026-73122 - A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Managemen
CVE-2026-72526 - A flaw was found in the multicloud-integrations component. The Application propagation controller pr
CVE-2026-70398 - A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHA
CVE-2026-66878 - A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace a
CVE-2026-64927 - A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user wit
CVE-2026-6484 - In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
CVE-2026-68450 - In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on dup
CVE-2026-68449 - In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infini
CVE-2026-68448 - In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_
CVE-2026-68447 - In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU contr
CVE-2024-14044 - A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_c
CVE-2026-68446 - In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surfac
CVE-2026-68445 - In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mapp
CVE-2026-68444 - In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NULL der
CVE-2026-68443 - In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforce) St
CVE-2026-68442 - In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_F
CVE-2026-68441 - In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_REDIRE
CVE-2026-68440 - In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow w
CVE-2026-68439 - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix possibl
CVE-2026-68438 - In the Linux kernel, the following vulnerability has been resolved: smp: Make CSD lock acquisition
CVE-2026-68437 - In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fra
CVE-2026-68436 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc t
CVE-2026-68435 - In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mi
CVE-2026-68434 - In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL func
CVE-2026-68433 - In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version repl
CVE-2026-68432 - In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in
CVE-2026-68431 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU siz
CVE-2026-68430 - In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessar
CVE-2026-68429 - In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down to
CVE-2024-14043 - A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s
CVE-2026-73250 - Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64
CVE-2026-73249 - calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update
CVE-2026-73248 - calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_templ
CVE-2026-73247 - Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/mai
CVE-2026-73246 - Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/s
CVE-2026-73245 - Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/
CVE-2026-68067 - The login endpoint on the Mira cloud API accepts any format-valid string in the password field and r
CVE-2026-67568 - The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive heal
CVE-2026-67558 - The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a
CVE-2026-66875 - In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attac
CVE-2026-66340 - The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling,
CVE-2026-66098 - The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentic
CVE-2026-64934 - The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a
CVE-2026-5917 - libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=lib
CVE-2026-29036 - cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability
CVE-2026-19560 - Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execut
CVE-2026-19559 - Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute
CVE-2026-19558 - Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convin
CVE-2026-19557 - Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker
CVE-2026-19556 - Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute a
CVE-2026-18710 - A MongoDB driver component could write sensitive configuration information, including a credential u
CVE-2026-71290 - Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. Hostn
CVE-2026-66832 - When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live
CVE-2026-66154 - An insufficient certificate validation in a privileged communication workflow, was identified in a G
CVE-2026-66150 - Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Secur
CVE-2026-66149 - Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Secur
CVE-2026-66148 - An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI)
CVE-2026-66147 - An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in G
CVE-2026-63177 - Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access contro
CVE-2026-63134 - Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protec
CVE-2026-63133 - Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extrac
CVE-2026-55676 - Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) a
CVE-2026-48765 - TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator
CVE-2026-48763 - TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoi
CVE-2026-48762 - TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action
CVE-2026-29035 - CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_webso
CVE-2026-19579 - Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the ass
CVE-2026-19550 - A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on t
CVE-2026-18634 - An insecure handling of serialized objects vulnerability was found in the one of the service of GMS
CVE-2026-15606 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all v
CVE-2026-14863 - FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that all
CVE-2026-73283 - In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applica
CVE-2026-73282 - In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remo
CVE-2026-73281 - In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur o
CVE-2026-73244 - kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unau
CVE-2026-73243 - kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unau
CVE-2026-73242 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/li
CVE-2026-73241 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-sid
CVE-2026-73235 - FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SA
CVE-2026-73234 - FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileI
CVE-2026-73233 - FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displ
CVE-2026-73232 - ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to ca
CVE-2026-73231 - Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.
CVE-2026-73230 - Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3
CVE-2026-73229 - Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Dja
CVE-2026-73036 - Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Pyth
CVE-2026-73034 - DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers
CVE-2026-73032 - PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to e
CVE-2026-73031 - telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to
CVE-2026-71845 - A flaw was found in insights-client. The setDefault() function logs the value of every environment v
CVE-2026-71475 - A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can in
CVE-2026-71474 - A flaw was found in insights-client. When the application receives a non-200 response, it logs the r
CVE-2026-71468 - A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its c
CVE-2026-71467 - A flaw was found in search-v2-api. The authentication middleware in the affected component unconditi
CVE-2026-70339 - Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
CVE-2026-66146 - Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) a
CVE-2026-66145 - An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044)
CVE-2026-65655 - When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwa
CVE-2026-48813 - Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions pr
CVE-2026-48804 - python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-s
CVE-2026-45618 - LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possi
CVE-2026-19091 - The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPre
CVE-2026-18844 - The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bl
CVE-2026-16230 - The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insuffi
CVE-2026-13457 - The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Co
CVE-2024-14042 - A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/
CVE-2026-73228 - Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's r
CVE-2026-73227 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-73226 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-73225 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-73224 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-73223 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-73222 - Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the
CVE-2026-73221 - CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0
CVE-2026-72742 - DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters
CVE-2026-69119 - Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service
CVE-2026-69117 - NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including
CVE-2026-69115 - OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated us
CVE-2026-48809 - python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions pri
CVE-2026-48802 - python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to ver
CVE-2026-18712 - An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticate
CVE-2026-18711 - An issue in MongoDB Server's query execution engine could allow an authenticated user with read and
CVE-2026-18709 - An issue in MongoDB Server could allow an authenticated user with direct network access to a shard t
CVE-2026-18708 - An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with writ
CVE-2026-18707 - An issue in MongoDB Server could allow an authenticated user, including one with no assigned privile
CVE-2026-18706 - An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able t
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware