CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-50642 - diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff d
CVE-2026-4604 - The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of d
CVE-2026-18220 - An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c
CVE-2026-16655 - The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo
CVE-2026-16597 - The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to S
CVE-2026-14900 - The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all v
CVE-2026-14488 - The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redire
CVE-2026-12895 - SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application co
CVE-2026-65100 - Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block enco
CVE-2026-59243 - The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID
CVE-2026-58189 - Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SS
CVE-2026-58188 - Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. Th
CVE-2026-58187 - The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, ena
CVE-2026-58186 - The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable
CVE-2026-58185 - The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffi
CVE-2026-58184 - The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations
CVE-2026-58183 - The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. Th
CVE-2026-58182 - The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instan
CVE-2026-58181 - The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker
CVE-2026-58180 - The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This
CVE-2026-58179 - The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution inpu
CVE-2026-58178 - The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
CVE-2026-58177 - The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-f
CVE-2026-58175 - Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Tr
CVE-2026-58164 - Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration
CVE-2026-58163 - Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras
CVE-2026-58162 - The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien
CVE-2026-58161 - Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli
CVE-2026-58160 - Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Tr
CVE-2026-58159 - Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors
CVE-2026-58158 - Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
CVE-2026-58157 - Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client
CVE-2026-50622 - Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache
CVE-2026-23904 - Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to th
CVE-2026-18207 - A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the s
CVE-2026-18201 - Keycloak provides a way to manage identity providers and organizations through its administrative AP
CVE-2025-10656 - The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vuln
CVE-2026-9720 - The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forg
CVE-2026-65325 - Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server cert
CVE-2026-65324 - Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, le
CVE-2026-64557 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after
CVE-2026-64556 - In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups
CVE-2026-58156 - Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypa
CVE-2026-58155 - Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,
CVE-2026-58154 - Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP heade
CVE-2026-58153 - Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked frami
CVE-2026-58152 - Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory.
CVE-2026-58151 - Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and
CVE-2026-13425 - The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array For
CVE-2026-11973 - The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'ord
CVE-2026-58150 - Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade reque
CVE-2026-57834 - Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affe
CVE-2026-41920 - Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S
CVE-2026-35226 - An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated at
CVE-2026-33930 - Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound d
CVE-2026-33267 - Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic
CVE-2026-24033 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap
CVE-2026-22068 - Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apach
CVE-2026-18197 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-18192 - VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated r
CVE-2026-18191 - VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated
CVE-2026-63242 - A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson c
CVE-2026-63241 - An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to qu
CVE-2026-63240 - An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain co
CVE-2026-63239 - A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared m
CVE-2026-63238 - An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take ov
CVE-2026-63237 - A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a
CVE-2026-63236 - An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read
CVE-2026-63235 - An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forci
CVE-2026-63234 - A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated att
CVE-2026-63233 - A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated att
CVE-2026-63232 - A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated att
CVE-2026-63231 - A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker t
CVE-2026-63230 - A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticat
CVE-2026-63229 - A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated att
CVE-2026-63228 - An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to uploa
CVE-2026-63227 - An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module desig
CVE-2026-14300 - The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin befor
CVE-2026-14234 - The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its A
CVE-2026-14224 - The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted
CVE-2026-13692 - The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signat
CVE-2026-13690 - The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider i
CVE-2026-13605 - The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link mar
CVE-2026-13423 - The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification
CVE-2026-11974 - The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter
CVE-2026-11351 - The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on o
CVE-2026-18072 - The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPre
CVE-2026-5626 - The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a mis
CVE-2026-15344 - The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table'
CVE-2026-12476 - The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions u
CVE-2026-17166 - The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar
CVE-2026-17162 - The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to
CVE-2026-17161 - The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to
CVE-2026-15735 - The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'c
CVE-2026-12939 - The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link
CVE-2026-12938 - The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'targ
CVE-2026-12144 - The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all vers
CVE-2026-56822 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fina
CVE-2026-56821 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fina
CVE-2026-66064 - goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, th
CVE-2026-66063 - goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, th
CVE-2026-64863 - goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, th
CVE-2026-62325 - goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2
CVE-2026-59921 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fina
CVE-2026-54719 - goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, th
CVE-2026-54659 - Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/p
CVE-2026-54658 - Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/c
CVE-2026-54650 - openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in
CVE-2026-54638 - gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode
CVE-2026-47219 - find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports ro
CVE-2026-55415 - datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct fr
CVE-2026-55403 - datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/
CVE-2026-55391 - datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct fr
CVE-2026-55390 - datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.6
CVE-2026-55389 - datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct fr
CVE-2026-54691 - datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61
CVE-2026-54690 - datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct fr
CVE-2026-54656 - datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct fr
CVE-2026-54655 - datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.6
CVE-2026-54654 - datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.6
CVE-2026-54653 - datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct fr
CVE-2026-54621 - datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, Grap
CVE-2026-6881 - A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allow
CVE-2026-59943 - Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can sup
CVE-2026-59942 - Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Se
CVE-2026-59941 - Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates
CVE-2026-56722 - Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls th
CVE-2026-49447 - Cosmos provides users the ability self-host a home server by acting as a secure gateway to your appl
CVE-2026-16581 - In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information i
CVE-2026-15328 - IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
CVE-2026-15325 - IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
CVE-2026-15280 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is aff
CVE-2026-15064 - IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTT
CVE-2026-15057 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se
CVE-2026-14996 - IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session manageme
CVE-2026-14981 - IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty are affected by a de
CVE-2026-14976 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code exec
CVE-2026-14974 - IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute a
CVE-2026-14973 - IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written out
CVE-2026-14959 - IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute ar
CVE-2026-14958 - IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute ar
CVE-2026-14893 - IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer comp
CVE-2026-14528 - IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain se
CVE-2026-14515 - IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a
CVE-2026-14512 - IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe
CVE-2026-14446 - IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escal
CVE-2026-13463 - IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the
CVE-2026-13442 - IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace
CVE-2026-57511 - SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated
CVE-2026-57510 - SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasSer
CVE-2026-55555 - Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existen
CVE-2026-55554 - Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() metho
CVE-2026-48060 - Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Lite
CVE-2026-3158 - IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
CVE-2026-3157 - IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
CVE-2026-1918 - IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
CVE-2026-16347 - MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safegu
CVE-2026-16192 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of serv
CVE-2026-16184 - IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication
CVE-2026-16107 - IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS
CVE-2026-11391 - Tanium addressed a SQL injection vulnerability in Patch.
CVE-2026-7769 - IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 throug
CVE-2026-7362 - IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterlin
CVE-2026-66745 - Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixa
CVE-2026-5114 - The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all
CVE-2026-59932 - PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 th
CVE-2026-50738 - A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can
CVE-2026-50737 - When applying replicated changes for a row that is missing one or more columns, pglogical evaluates
CVE-2026-50736 - The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a pub
CVE-2026-50735 - pglogical's apply worker does not sufficiently validate the length of certain fields in incoming rep
CVE-2026-4932 - IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an a
CVE-2026-4912 - The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request F
CVE-2026-49258 - Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and belo
CVE-2026-48396 - Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code e
CVE-2026-48395 - Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code exe
CVE-2026-48394 - Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execu
CVE-2026-48393 - Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execu
CVE-2026-48392 - Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execu
CVE-2026-48391 - Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code exe
CVE-2026-48390 - Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escala
CVE-2026-48374 - Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversa
CVE-2026-48058 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-47768 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-47726 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-47725 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-18107 - A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A mal
CVE-2026-16771 - In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑sid
CVE-2026-16498 - The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue
CVE-2026-16496 - The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the stream
CVE-2026-15992 - The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up
CVE-2026-15304 - The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' pa
CVE-2026-14869 - The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue i
CVE-2026-59933 - PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 th
CVE-2026-59931 - PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 th
CVE-2026-54635 - pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON
CVE-2026-48388 - Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that cou
CVE-2026-48372 - Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitr
CVE-2026-48025 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-67185 - TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers
CVE-2026-67184 - TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated
CVE-2026-67183 - TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to
CVE-2026-67182 - Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote atta
CVE-2026-54620 - sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks
CVE-2026-54619 - sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, rede
CVE-2026-54609 - QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0
CVE-2026-54605 - OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.
CVE-2026-54603 - OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connec
CVE-2026-54345 - gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter
CVE-2026-54332 - gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow Ext
CVE-2026-51275 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51274 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51273 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-18085 - An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8
CVE-2026-18084 - Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Manageme
CVE-2026-16313 - A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs de
CVE-2026-8058 - IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a p
CVE-2026-7868 - IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to es
CVE-2026-7775 - IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through
CVE-2026-67181 - Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote atta
CVE-2026-66754 - Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_pref
CVE-2026-66753 - tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to in
CVE-2026-66752 - tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attacke
CVE-2026-66751 - Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any auth
CVE-2026-66750 - Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authentica
CVE-2026-66749 - Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated a
CVE-2026-66748 - Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerabil
CVE-2026-66746 - Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote att
CVE-2026-62828 - Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform t
CVE-2026-61609 - Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authen
CVE-2026-54593 - Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and W
CVE-2026-54545 - wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli saniti
CVE-2026-51271 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51270 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51269 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51268 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51267 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51266 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51263 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-47483 - NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where
CVE-2026-47427 - GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function i
CVE-2026-45293 - WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding
CVE-2026-43910 - Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C Web
CVE-2026-8164 - Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade
CVE-2026-7521 - Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail t
CVE-2026-6879 - `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when us
CVE-2026-67178 - MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrec
CVE-2026-67174 - Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolutio
CVE-2026-66713 - Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache So
CVE-2026-66299 - Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This iss
CVE-2026-63727 - Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware