CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-79773 - Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter fil
CVE-2026-79772 - Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicali
CVE-2026-79771 - Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when p
CVE-2026-79770 - Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the
CVE-2026-79769 - Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protec
CVE-2026-79676 - NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen roo
CVE-2026-79675 - NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in th
CVE-2026-79674 - NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructor
CVE-2026-70550 - An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticat
CVE-2026-70548 - Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Art
CVE-2026-55640 - Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud ins
CVE-2026-55582 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0
CVE-2026-55581 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0
CVE-2026-55580 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0
CVE-2026-55546 - QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() i
CVE-2026-55539 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function
CVE-2026-55536 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connectio
CVE-2026-55533 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows
CVE-2026-55532 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin
CVE-2025-71407 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-71406 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-71346 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2024-58378 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2024-58377 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2023-54354 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-51000 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-50999 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-50998 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2021-47996 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-79717 - A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server
CVE-2026-70551 - A user who can read an existing remote VCS repository can replace its configured origin or supply an
CVE-2026-69104 - An authenticated user may initiate repository migration operations without required repository permi
CVE-2026-55624 - MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba
CVE-2026-55541 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and prais
CVE-2026-55540 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses
CVE-2026-55538 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses co
CVE-2026-55537 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhoo
CVE-2026-55535 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_ur
CVE-2026-55534 - PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents
CVE-2026-55531 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post han
CVE-2026-55530 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the
CVE-2026-55529 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_or
CVE-2026-55528 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server
CVE-2026-55527 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor
CVE-2026-55526 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc
CVE-2026-16599 - GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The
CVE-2026-16286 - Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Comput
CVE-2026-15310 - When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use
CVE-2026-79655 - A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a
CVE-2026-79623 - A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element
CVE-2026-79622 - A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the
CVE-2026-55525 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function val
CVE-2026-79406 - A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function
CVE-2026-78887 - A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShar
CVE-2026-78886 - A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function
CVE-2026-78885 - A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function f
CVE-2026-78581 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data m
CVE-2026-77998 - Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter
CVE-2026-75803 - Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success
CVE-2026-63076 - Issue summary: OpenSSL CMP password based protection verification only checks whether the protection
CVE-2026-63075 - Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting p
CVE-2026-63074 - Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (ext
CVE-2026-63073 - Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished na
CVE-2026-63072 - Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwra
CVE-2026-57863 - Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that all
CVE-2026-54874 - Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes Op
CVE-2026-18798 - Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation f
CVE-2026-14457 - Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and
CVE-2026-79673 - Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, bu
CVE-2026-79672 - Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints,
CVE-2026-79671 - Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL fun
CVE-2026-79670 - Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint t
CVE-2026-79669 - Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-
CVE-2026-79668 - Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endp
CVE-2026-79667 - Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restr
CVE-2026-79666 - Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing
CVE-2026-79665 - Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope val
CVE-2026-79664 - Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing
CVE-2026-79663 - Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where
CVE-2026-79662 - Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClient
CVE-2026-79661 - Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without
CVE-2026-79660 - Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due t
CVE-2026-79659 - Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo f
CVE-2026-79658 - Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by
CVE-2026-79657 - NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle load
CVE-2026-78864 - A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function j
CVE-2026-78684 - vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enfo
CVE-2026-77997 - Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1
CVE-2026-77996 - Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41
CVE-2026-77824 - The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injectio
CVE-2026-75971 - The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for Word
CVE-2026-75908 - The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, an
CVE-2026-57910 - Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network acce
CVE-2026-57909 - A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an a
CVE-2026-19949 - The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archi
CVE-2026-18547 - The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Mem
CVE-2026-17587 - The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to au
CVE-2026-79652 - A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services c
CVE-2026-78863 - A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the f
CVE-2026-59335 - Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Iden
CVE-2026-55976 - Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allow
CVE-2026-53561 - An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive
CVE-2026-49845 - SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on
CVE-2026-21758 - HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gat
CVE-2026-21754 - HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which cou
CVE-2026-21753 - HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of
CVE-2026-12600 - Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the
CVE-2026-78576 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-78572 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-78570 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-76128 - The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-75038 - UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial
CVE-2026-75037 - Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authenticati
CVE-2026-49050 - General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinSch
CVE-2026-16231 - hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars
CVE-2026-12878 - In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to
CVE-2026-78568 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-78566 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-78563 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-78562 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-77146 - The extension's invitation controller fails to stop processing after redirecting on invalid input (m
CVE-2026-77145 - The permission check for the frontend management update flow verified a different event than the one
CVE-2026-77144 - The frontend management plugin attributed a newly created event to the submitting user's organizer r
CVE-2026-77143 - The frontend topic editing flow does not verify on the server side that the requesting visitor owns
CVE-2026-77142 - The frontend company self-service editing feature relies on a template-level visibility flag to hide
CVE-2026-77141 - The extension resolves the targeted club record from a user-supplied request argument in its fronten
CVE-2026-77140 - The extension validates the HMAC of a frontend employee edit link only in the action that renders th
CVE-2026-77139 - The extension fails to validate a client-supplied template element key before using it to build file
CVE-2026-77138 - The extension fails to safely process untrusted client input of an attacker-controlled cookie direct
CVE-2026-77137 - The extension fails to properly sanitize user input before using it in a database query. As a result
CVE-2026-77136 - The extension passes the raw value of a form field configured as "This field contains the name of th
CVE-2026-77135 - The extension's user detail view fails to verify that a requested user record matches the configured
CVE-2026-77134 - The extension fails to require the dedicated admin confirmation token when processing an admin-appro
CVE-2026-77133 - The extension fails to restrict which frontend usergroups a logged-in user may assign to their own a
CVE-2026-77131 - When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in clear
CVE-2026-77130 - The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an
CVE-2026-77129 - The extension passes an editor-configurable email subject string directly into a Fluid template sour
CVE-2026-77128 - The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthe
CVE-2026-77127 - The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current use
CVE-2026-63587 - The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the
CVE-2026-63586 - The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Ba
CVE-2026-56096 - The extension passes the user-supplied search query parameter to Apache Solr without restricting adv
CVE-2026-56095 - The extension's indexer passed every field value returned by content object rendering through PHP's
CVE-2026-56094 - The extension allows a request-provided additionalFilters parameter to register a named siteHash fil
CVE-2026-56093 - The extension's frontend detail-view document lookup does not apply the current site's siteHash filt
CVE-2026-56092 - The extension forces empty frontend-group and subpage-inheritance restrictions onto page records dur
CVE-2026-17548 - Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an au
CVE-2026-78701 - A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in t
CVE-2026-78322 - A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing
CVE-2026-67578 - FA-50 all versions miss authentication for some configuration. An attacker with access to the vesse
CVE-2026-66882 - Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshA
CVE-2026-65633 - Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs
CVE-2026-59769 - FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has a
CVE-2026-19851 - A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 c
CVE-2026-18512 - The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner
CVE-2026-18328 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-18323 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-18100 - The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress i
CVE-2026-16601 - The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vu
CVE-2026-78656 - A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown fun
CVE-2026-69665 - SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If thi
CVE-2026-68960 - A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If t
CVE-2026-68959 - SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili
CVE-2026-68062 - SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili
CVE-2026-66109 - A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vu
CVE-2026-78654 - A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the funct
CVE-2026-78638 - A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function u
CVE-2026-78478 - The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ
CVE-2026-78477 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-78470 - The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to
CVE-2026-78467 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78272. Reason:
CVE-2026-78466 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78278. Reason:
CVE-2025-41741 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-78637 - A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the
CVE-2026-13215 - The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superb
CVE-2026-13214 - The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getcon
CVE-2026-12561 - The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw
CVE-2026-76063 - The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cro
CVE-2026-75930 - The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorizat
CVE-2026-19943 - The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to
CVE-2026-19892 - The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover i
CVE-2026-17089 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Re
CVE-2026-14280 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Lo
CVE-2026-78685 - Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Un
CVE-2026-75982 - The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPres
CVE-2026-75019 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
CVE-2026-10627 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to au
CVE-2025-9878 - The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul
CVE-2026-78683 - NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerabili
CVE-2026-78682 - NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and
CVE-2026-78681 - NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors
CVE-2026-78680 - NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot bina
CVE-2026-78679 - GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where
CVE-2026-78678 - GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options g
CVE-2026-78677 - GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers t
CVE-2026-78676 - GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write opera
CVE-2026-78675 - GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers
CVE-2026-76846 - Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fa
CVE-2026-76839 - Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-lis
CVE-2026-75575 - Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauth
CVE-2026-75574 - The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email
CVE-2026-72702 - Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referr
CVE-2026-72701 - Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constan
CVE-2026-72700 - The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset an
CVE-2026-72699 - The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumer
CVE-2026-72698 - Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twi
CVE-2026-72697 - Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig functio
CVE-2026-72696 - Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile()
CVE-2026-72695 - Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that al
CVE-2026-56710 - Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in th
CVE-2026-56709 - Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function whe
CVE-2026-56708 - Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delive
CVE-2026-56707 - Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability
CVE-2026-56706 - Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value
CVE-2026-56705 - Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowi
CVE-2026-56704 - Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid
CVE-2026-56703 - Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where V
CVE-2026-56702 - Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUp
CVE-2026-34968 - Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the data
CVE-2026-34967 - Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write
CVE-2026-34964 - Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server
CVE-2026-34959 - Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUE
CVE-2026-19801 - The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for
CVE-2026-16434 - Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Pref
CVE-2026-15023 - The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to ge
CVE-2026-10630 - The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses
CVE-2026-66766 - SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial o
CVE-2026-59183 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55373 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55371 - OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file
CVE-2026-55059 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-54920 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-53532 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-78435 - A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the
CVE-2026-78434 - A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_
CVE-2026-78284 - Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
CVE-2026-78282 - Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
CVE-2026-78268 - Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat But
CVE-2026-78267 - Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78266 - Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
CVE-2026-78265 - Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78264 - Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
CVE-2026-78263 - Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
CVE-2026-78262 - Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-78259 - Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
CVE-2026-77384 - libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the re
CVE-2026-77337 - CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based
CVE-2026-68516 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-45404 - OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the
CVE-2026-32563 - Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 ver
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware