CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-59100 - LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authen
CVE-2026-59099 - Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthen
CVE-2026-59098 - LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-gen
CVE-2026-59097 - Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remot
CVE-2026-59096 - Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-con
CVE-2026-59095 - LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows au
CVE-2026-59094 - Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob patte
CVE-2026-59093 - Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the
CVE-2026-59092 - JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that
CVE-2026-58580 - LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorizati
CVE-2026-58579 - RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent updat
CVE-2026-58578 - LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vul
CVE-2026-58467 - Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that all
CVE-2026-58466 - AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthe
CVE-2026-58381 - A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_
CVE-2026-52187 - Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to
CVE-2025-71385 - Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api
CVE-2026-7311 - The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary fil
CVE-2026-58465 - Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in
CVE-2026-13743 - CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Veri
CVE-2026-8699 - A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management in
CVE-2026-55952 - The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried
CVE-2026-55950 - Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux
CVE-2026-54891 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerabili
CVE-2026-54887 - Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DT
CVE-2026-54886 - Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd mo
CVE-2026-53422 - Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authent
CVE-2026-50282 - Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and ve
CVE-2026-50281 - Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a
CVE-2026-44935 - Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.1
CVE-2024-58352 - Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attac
CVE-2024-14037 - Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attacke
CVE-2022-50973 - Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bi
CVE-2026-58455 - Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows
CVE-2026-44941 - A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 c
CVE-2026-9272 - In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adver
CVE-2026-8079 - In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenti
CVE-2026-56842 - A malicious actor with access to the network and under certain conditions could exploit an Incorrect
CVE-2026-56841 - A malicious actor with access to the network and low privileges could exploit an authenticated SQL I
CVE-2026-56004 - A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12
CVE-2026-55119 - A malicious actor with access to the network and low privileges could exploit an Improper Access Con
CVE-2026-55118 - A malicious actor with access to the network,low privileges and under certain conditions could explo
CVE-2026-55117 - A malicious actor with access to the network could exploit a Path Traversal vulnerability found in U
CVE-2026-55116 - A malicious actor with access to the network and under certain network configurations could exploit
CVE-2026-55115 - A malicious actor with access to the network and low privileges could exploit a Server-Side Request
CVE-2026-55114 - A malicious actor with access to the network and low privileges could exploit an Improper Access Con
CVE-2026-55113 - A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vuln
CVE-2026-55112 - A malicious actor with access to the network and low privileges and under certain conditions could e
CVE-2026-55111 - A malicious actor with access to the network could exploit a Path Traversal vulnerability found in U
CVE-2026-55110 - A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin R
CVE-2026-54409 - A malicious actor with access to the network and under certain conditions could exploit an Improper
CVE-2026-54408 - A malicious actor with access to the network could exploit an Improper Access Control vulnerability
CVE-2026-54407 - A malicious actor with access to the network could exploit an Improper Access Control vulnerability
CVE-2026-54406 - A malicious actor with access to the network and high privileges could exploit a Path Traversal vuln
CVE-2026-54405 - A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit
CVE-2026-54404 - A malicious actor with access to the network and low privileges could exploit a series of authentica
CVE-2026-54403 - A malicious actor with access to the network could exploit a Path Traversal vulnerability found in c
CVE-2026-54402 - A malicious actor with access to the network and low privileges could exploit an Improper Input Vali
CVE-2026-54401 - A malicious actor with access to the network and low privileges could exploit a Server-Side Request
CVE-2026-54400 - A malicious actor with access to the network and high privileges could exploit an Improper Access Co
CVE-2026-53358 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan time
CVE-2026-53357 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_soc
CVE-2026-50748 - A malicious actor with access to the network and low privileges could exploit an Improper Input Vali
CVE-2026-50747 - A malicious actor with access to the network and low privileges could exploit a series of authentica
CVE-2026-50746 - A malicious actor with access to the network could exploit an Improper Access Control vulnerability
CVE-2026-12168 - An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a loc
CVE-2026-12167 - The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local
CVE-2026-12166 - A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a
CVE-2026-4767 - Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allow
CVE-2026-5524 - The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote
CVE-2026-58653 - PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies b
CVE-2026-58652 - luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd se
CVE-2026-4772 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-4770 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-57766 - Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 ver
CVE-2026-57765 - Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
CVE-2026-57764 - Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
CVE-2026-57763 - Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
CVE-2026-57762 - Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
CVE-2026-57761 - Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
CVE-2026-57760 - Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Co
CVE-2026-57759 - Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
CVE-2026-57758 - Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 ve
CVE-2026-57757 - Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
CVE-2026-57756 - Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
CVE-2026-57755 - Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions.
CVE-2026-57754 - Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 version
CVE-2026-57753 - Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versio
CVE-2026-57752 - Contributor SQL Injection in iNET Webkit 1.2.4 versions.
CVE-2026-57751 - Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
CVE-2026-57750 - Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
CVE-2026-57749 - Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
CVE-2026-57748 - Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
CVE-2026-57747 - Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
CVE-2026-57746 - Subscriber Broken Access Control in Booked <= 3.0.0 versions.
CVE-2026-57731 - Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
CVE-2026-57730 - Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
CVE-2026-57690 - Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.
CVE-2026-57689 - Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
CVE-2026-57688 - Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
CVE-2026-57687 - Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
CVE-2026-57686 - Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
CVE-2026-57685 - Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 vers
CVE-2026-57684 - Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.
CVE-2026-57683 - Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
CVE-2026-57682 - Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
CVE-2026-57681 - Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
CVE-2026-57680 - Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
CVE-2026-57679 - Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
CVE-2026-57678 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57677 - Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions
CVE-2026-57675 - Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.
CVE-2026-57674 - Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
CVE-2026-57673 - Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions.
CVE-2026-57672 - Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.
CVE-2026-57671 - Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.
CVE-2026-57670 - Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.
CVE-2026-57669 - Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
CVE-2026-57625 - Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 version
CVE-2026-57624 - Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
CVE-2026-57623 - Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
CVE-2026-57621 - Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
CVE-2026-57426 - Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.
CVE-2026-57366 - Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.
CVE-2026-57362 - Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
CVE-2026-57361 - Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
CVE-2026-57360 - Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
CVE-2026-57359 - Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.
CVE-2026-57358 - Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions
CVE-2026-57357 - Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.
CVE-2026-57356 - Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
CVE-2026-57355 - Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
CVE-2026-57354 - Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
CVE-2026-57353 - Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
CVE-2026-57352 - Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCo
CVE-2026-57351 - Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.
CVE-2026-57350 - Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
CVE-2026-57349 - Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
CVE-2026-57348 - Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
CVE-2026-57347 - Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
CVE-2026-57345 - Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
CVE-2026-57344 - Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
CVE-2026-57343 - Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
CVE-2026-57342 - Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
CVE-2026-56037 - Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. T
CVE-2026-49779 - Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal
CVE-2026-42382 - Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
CVE-2026-39448 - Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
CVE-2026-27436 - Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
CVE-2026-27433 - Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
CVE-2026-27430 - Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
CVE-2026-27426 - Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
CVE-2026-27425 - Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
CVE-2026-27419 - Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
CVE-2026-27414 - Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
CVE-2026-27412 - Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
CVE-2026-27408 - Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
CVE-2026-27404 - Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
CVE-2026-27402 - Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
CVE-2026-27060 - Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object
CVE-2026-14449 - u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form com
CVE-2026-11946 - An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service
CVE-2025-69156 - Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
CVE-2025-69155 - Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
CVE-2025-69154 - Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
CVE-2025-69153 - Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69152 - Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versio
CVE-2025-69134 - Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 version
CVE-2025-69133 - Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69132 - Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
CVE-2025-69094 - Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-66076 - Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
CVE-2025-58902 - Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2026-54431 - In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Ke
CVE-2026-54430 - liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() functio
CVE-2026-9834 - The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is
CVE-2026-9188 - The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnera
CVE-2026-9145 - The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbi
CVE-2026-8482 - A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to
CVE-2026-8441 - The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' p
CVE-2026-14336 - PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith('
CVE-2026-14029 - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge
CVE-2026-13459 - The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization
CVE-2026-13369 - The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the att
CVE-2026-13252 - The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plu
CVE-2026-13251 - The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and
CVE-2026-12657 - The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab
CVE-2026-12472 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-12134 - The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerabl
CVE-2026-12122 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-11896 - The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Obj
CVE-2026-10104 - The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-9563 - In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not e
CVE-2026-8147 - In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoint
CVE-2026-33592 - An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service i
CVE-2026-5821 - The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to
CVE-2026-5348 - The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulne
CVE-2026-14249 - The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and incl
CVE-2026-13704 - The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored C
CVE-2026-13357 - The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' param
CVE-2026-11965 - The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completio
CVE-2026-11781 - The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the
CVE-2026-11600 - The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to u
CVE-2026-11592 - The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for Wo
CVE-2026-11578 - The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form subm
CVE-2026-10089 - The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom f
CVE-2026-10077 - The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from tre
CVE-2026-57278 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57277 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57276 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57275 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57274 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57273 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57272 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57271 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57270 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57269 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57268 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57267 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57266 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57265 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-57264 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-13132 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-13131 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-13125 - GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is
CVE-2026-55794 - Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control
CVE-2026-55792 - Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.1
CVE-2026-55791 - Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.
CVE-2026-50280 - Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the
CVE-2026-50279 - Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, the
CVE-2026-55790 - Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 t
CVE-2026-50284 - Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 t
CVE-2026-50283 - Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 thr
CVE-2026-14440 - Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal
CVE-2026-14439 - A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Serve
CVE-2026-14432 - Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar
CVE-2026-14431 - Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar
CVE-2026-14430 - Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute
CVE-2026-14429 - Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a
CVE-2026-14428 - Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.4
CVE-2026-14427 - Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who h
CVE-2026-14426 - Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced
CVE-2026-14425 - Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti
CVE-2026-14424 - Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to p
CVE-2026-14423 - Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia
CVE-2026-14422 - Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attack
CVE-2026-14421 - Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attac
CVE-2026-14420 - Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attack
CVE-2026-14419 - Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia
CVE-2026-14418 - Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.