CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
18115 CVEs gefunden (Seite 3/73)

CVE-2026-79773 - Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter fil

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-79772 - Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicali

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-79771 - Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when p

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-79770 - Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-79769 - Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protec

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-79676 - NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen roo

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-79675 - NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in th

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-79674 - NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructor

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-70550 - An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticat

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-70548 - Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Art

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 3.5
3.5

CVE-2026-55640 - Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud ins

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-55582 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.4
8.4

CVE-2026-55581 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.4
8.4

CVE-2026-55580 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-55546 - QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() i

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-55539 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-55536 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connectio

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-55533 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-55532 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.6
7.6

CVE-2025-71407 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2025-71406 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2025-71346 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2024-58378 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2024-58377 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2023-54354 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2022-51000 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2022-50999 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2022-50998 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2021-47996 - Rejected reason: This CVE ID has been rejected as a duplicate.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-79717 - A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-70551 - A user who can read an existing remote VCS repository can replace its configured origin or supply an

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-69104 - An authenticated user may initiate repository migration operations without required repository permi

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.6
7.6

CVE-2026-55624 - MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-55541 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and prais

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-55540 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-55538 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses co

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-55537 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhoo

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-55535 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_ur

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-55534 - PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-55531 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post han

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-55530 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-55529 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_or

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.9
6.9

CVE-2026-55528 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-55527 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-55526 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-16599 - GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-16286 - Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Comput

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-15310 - When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-79655 - A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-79623 - A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-79622 - A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the

🏢 Adobe 📅 25.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-55525 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function val

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-79406 - A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-78887 - A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShar

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 3.7
3.7

CVE-2026-78886 - A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 3.7
3.7

CVE-2026-78885 - A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function f

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.6
5.6

CVE-2026-78581 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data m

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-77998 - Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter

🏢 Google 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-75803 - Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-63076 - Issue summary: OpenSSL CMP password based protection verification only checks whether the protection

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-63075 - Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting p

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-63074 - Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (ext

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-63073 - Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished na

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-63072 - Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwra

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-57863 - Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that all

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-54874 - Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes Op

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-18798 - Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation f

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-14457 - Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-79673 - Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, bu

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-79672 - Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints,

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-79671 - Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL fun

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-79670 - Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.8
4.8

CVE-2026-79669 - Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-79668 - Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endp

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-79667 - Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restr

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.6
7.6

CVE-2026-79666 - Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-79665 - Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope val

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-79664 - Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-79663 - Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.8
4.8

CVE-2026-79662 - Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClient

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.0
8.0

CVE-2026-79661 - Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-79660 - Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-79659 - Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo f

🏢 Hpe 📅 25.8.2026 📊 CVSS: 7.7
7.7

CVE-2026-79658 - Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-79657 - NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle load

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-78864 - A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function j

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-78684 - vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enfo

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-77997 - Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1

🏢 Joomla 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77996 - Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41

🏢 Joomla 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77824 - The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injectio

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-75971 - The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for Word

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-75908 - The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, an

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-57910 - Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network acce

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-57909 - A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an a

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-19949 - The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archi

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-18547 - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Mem

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-17587 - The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to au

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-79652 - A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services c

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-78863 - A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the f

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-59335 - Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Iden

🏢 Postgresql 📅 25.8.2026 📊 CVSS: 8.7
8.7

CVE-2026-55976 - Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allow

🏢 Apache 📅 25.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-53561 - An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive

🏢 Apache 📅 25.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-49845 - SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on

🏢 Apache 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-21758 - HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gat

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 3.7
3.7

CVE-2026-21754 - HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which cou

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-21753 - HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-12600 - Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78576 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78572 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78570 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-76128 - The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-75038 - UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-75037 - Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authenticati

🏢 Linux 📅 25.8.2026 📊 CVSS: 7.0
7.0

CVE-2026-49050 - General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinSch

🏢 Apache 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-16231 - hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-12878 - In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-78568 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78566 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78563 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78562 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77146 - The extension's invitation controller fails to stop processing after redirecting on invalid input (m

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77145 - The permission check for the frontend management update flow verified a different event than the one

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77144 - The frontend management plugin attributed a newly created event to the submitting user's organizer r

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77143 - The frontend topic editing flow does not verify on the server side that the requesting visitor owns

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77142 - The frontend company self-service editing feature relies on a template-level visibility flag to hide

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77141 - The extension resolves the targeted club record from a user-supplied request argument in its fronten

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77140 - The extension validates the HMAC of a frontend employee edit link only in the action that renders th

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77139 - The extension fails to validate a client-supplied template element key before using it to build file

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77138 - The extension fails to safely process untrusted client input of an attacker-controlled cookie direct

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77137 - The extension fails to properly sanitize user input before using it in a database query. As a result

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77136 - The extension passes the raw value of a form field configured as "This field contains the name of th

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77135 - The extension's user detail view fails to verify that a requested user record matches the configured

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77134 - The extension fails to require the dedicated admin confirmation token when processing an admin-appro

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77133 - The extension fails to restrict which frontend usergroups a logged-in user may assign to their own a

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77131 - When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in clear

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77130 - The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77129 - The extension passes an editor-configurable email subject string directly into a Fluid template sour

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77128 - The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthe

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-77127 - The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current use

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-63587 - The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-63586 - The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Ba

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-56096 - The extension passes the user-supplied search query parameter to Apache Solr without restricting adv

🏢 Apache 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-56095 - The extension's indexer passed every field value returned by content object rendering through PHP's

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-56094 - The extension allows a request-provided additionalFilters parameter to register a named siteHash fil

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-56093 - The extension's frontend detail-view document lookup does not apply the current site's siteHash filt

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-56092 - The extension forces empty frontend-group and subpage-inheritance restrictions onto page records dur

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-17548 - Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an au

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78701 - A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-78322 - A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-67578 - FA-50 all versions miss authentication for some configuration. An attacker with access to the vesse

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-66882 - Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshA

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-65633 - Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-59769 - FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has a

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-19851 - A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 c

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.7
7.7

CVE-2026-18512 - The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-18328 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-18323 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-18100 - The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress i

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-16601 - The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vu

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-78656 - A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown fun

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-69665 - SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If thi

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-68960 - A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-68959 - SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-68062 - SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-66109 - A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vu

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78654 - A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the funct

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-78638 - A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function u

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 3.3
3.3

CVE-2026-78478 - The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-78477 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78470 - The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-78467 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78272. Reason:

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78466 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason:

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2025-41741 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78637 - A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-13215 - The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superb

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-13214 - The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getcon

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-12561 - The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-76063 - The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cro

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-75930 - The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorizat

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-19943 - The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-19892 - The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover i

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-17089 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Re

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-14280 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Lo

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.6
6.6

CVE-2026-78685 - Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Un

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-75982 - The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPres

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 4.4
4.4

CVE-2026-75019 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-10627 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to au

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2025-9878 - The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-78683 - NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerabili

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.6
9.6

CVE-2026-78682 - NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-78681 - NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-78680 - NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot bina

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-78679 - GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-78678 - GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options g

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-78677 - GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-78676 - GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write opera

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-78675 - GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.4
8.4

CVE-2026-76846 - Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fa

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-76839 - Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-lis

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-75575 - Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauth

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-75574 - The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-72702 - Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referr

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-72701 - Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constan

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 3.7
3.7

CVE-2026-72700 - The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset an

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-72699 - The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumer

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-72698 - Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twi

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-72697 - Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig functio

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-72696 - Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile()

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.4
8.4

CVE-2026-72695 - Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that al

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-56710 - Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in th

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-56709 - Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function whe

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-56708 - Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delive

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-56707 - Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.7
7.7

CVE-2026-56706 - Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-56705 - Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowi

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-56704 - Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid

🏢 Mysql 📅 25.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-56703 - Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where V

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-56702 - Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUp

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-34968 - Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the data

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-34967 - Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-34964 - Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.8
5.8

CVE-2026-34959 - Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUE

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 4.7
4.7

CVE-2026-19801 - The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-16434 - Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Pref

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-15023 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to ge

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-10630 - The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses

🏢 Wordpress 📅 25.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-66766 - SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial o

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-59183 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-55373 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.2
6.2

CVE-2026-55371 - OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-55059 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-54920 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t

🏢 Sonstige 📅 25.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-53532 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-78435 - A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 3.8
3.8

CVE-2026-78434 - A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-78284 - Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-78282 - Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-78268 - Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat But

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-78267 - Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-78266 - Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-78265 - Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-78264 - Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-78263 - Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-78262 - Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-78259 - Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-77384 - libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the re

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-77337 - CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-68516 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-45404 - OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the

🏢 Sonstige 📅 24.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-32563 - Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 ver

🏢 Wordpress 📅 24.8.2026 📊 CVSS: 9.8
9.8
«« « Zurück Seite 3 von 73 Weiter » »»

🏢 CVE nach Hersteller

🛡️

Empfohlene IT-Security & Netzwerk-Hardware

Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware

✓ Geprüfte Qualität
2FA Hardware Key Bestseller

YubiKey 5 NFC (USB-A & NFC)

Verfügbarkeit & Preis prüfen ↗
Juice-Jacking Schutz Impuls-Tipp (~10€)

USB-Datenblocker (USB-Kondom)

Verfügbarkeit & Preis prüfen ↗
Mini Server & Pi-hole Top-Tipp

Raspberry Pi 5 (8GB RAM)

Verfügbarkeit & Preis prüfen ↗
Firewall & Router Netzwerk

UniFi Cloud Gateway Ultra

Verfügbarkeit & Preis prüfen ↗
OPNsense Hardware Profi-Firewall

Protectli Vault 4-Port

Verfügbarkeit & Preis prüfen ↗
MicroSD für Pi / Router Zubehör (~16€)

SanDisk Extreme Pro 128GB

Verfügbarkeit & Preis prüfen ↗
Alle IT-Sicherheit-Produkte bei Amazon durchsuchen → * Als Amazon-Partner verdienen wir an qualifizierten Verkäufen.