CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
18102 CVEs gefunden (Seite 34/73)

CVE-2026-57649 - Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57648 - Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57647 - Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versi

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57646 - Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-57645 - newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-57644 - Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-57643 - Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-57642 - Contributor SQL Injection in Gallery <= 4.7.8 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-57641 - Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57640 - Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57638 - Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57637 - Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 ve

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57636 - Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-57635 - Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerc

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57634 - Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57633 - Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-57632 - Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-57631 - Administrator SQL Injection in Popup box <= 6.0.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.6
7.6

CVE-2026-57630 - Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-57629 - Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57628 - Administrator SQL Injection in WP All Import <= 4.0.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.6
7.6

CVE-2026-57627 - Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-57622 - Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57618 - Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57617 - Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57527 - Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulner

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-57431 - Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57430 - Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57325 - Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57324 - Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57323 - Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.8
5.8

CVE-2026-57322 - Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57321 - Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57319 - Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57318 - Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57317 - Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57316 - Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57315 - Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-57314 - Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57313 - Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57312 - Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56773 - Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenti

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-56072 - Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56070 - Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-56069 - Unauthenticated Insecure Direct Object References (IDOR) in Toolset Forms <= 2.6.24 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-56068 - Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-56067 - Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-56066 - Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.8
5.8

CVE-2026-56064 - Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-56063 - Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-56062 - Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-56061 - Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-56060 - Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 v

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-56059 - Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-56058 - Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-56057 - Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-56055 - Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-56048 - Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-56047 - Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56046 - Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-56045 - Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56044 - Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56043 - Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56041 - Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56040 - Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56039 - Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56038 - Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-56036 - Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-56035 - Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.6
8.6

CVE-2026-56034 - Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-56033 - Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-56032 - Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-56031 - Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-56030 - Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-56029 - Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-56028 - Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Tem

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-56027 - Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-56026 - Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-56025 - Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-56011 - Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-56010 - Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-56008 - Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-54847 - Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54846 - Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versi

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54840 - Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-54839 - Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &a

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54837 - Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <=

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54835 - Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54834 - Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54833 - Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-54832 - Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54831 - Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-54827 - Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-54826 - Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.6
7.6

CVE-2026-54825 - Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-54824 - Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-54820 - Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-52701 - Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-4339 - Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachm

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-45257 - The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45256 - When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine w

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-3472 - Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply m

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 3.5
3.5

CVE-2026-30041 - An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to ex

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-30040 - A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-24547 - Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2025-68075 - Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2025-68074 - Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2025-68064 - Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2025-68063 - Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Ho

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2025-68052 - Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.8
8.8

CVE-2025-66123 - Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2025-64637 - Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2025-64636 - Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2025-63079 - Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2025-63078 - Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2025-63041 - Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-57940 - HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import funct

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-57926 - In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollut

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 2.6
2.6

CVE-2026-57925 - In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57924 - In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57923 - In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-57922 - In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-57921 - In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private dat

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-53914 - In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the buil

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.7
6.7

CVE-2026-13426 - The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to v

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-57920 - Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-cont

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.7
7.7

CVE-2026-57915 - It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA

🏢 Apache 📅 26.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-40711 - Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-power

🏢 Dell 📅 26.6.2026 📊 CVSS: 8.0
8.0

CVE-2025-64152 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 26.6.2026 📊 CVSS: 9.1
9.1

CVE-2025-55017 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac

🏢 Apache 📅 26.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-57914 - By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trig

🏢 Apache 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57620 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-57918 - libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_sock

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-57913 - Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meetin

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57912 - Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited s

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57473 - A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-13325 - Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2025-7958 - A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticate

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-6658 - A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via un

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-1869 - The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, Us

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-11702 - Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked proce

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11625 - Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57881 - An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-57880 - An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-57879 - An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-57878 - An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC201

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-57877 - An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC221

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.6
8.6

CVE-2026-57876 - An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57875 - An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic o

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57874 - An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57873 - An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVisio

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-57872 - An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49486 - The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but n

🏢 Apache 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-2053 - The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not suffi

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-8380 - The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-10835 - The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a para

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 7.7
7.7

CVE-2026-10823 - The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2025-10268 - The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulner

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-8797 - An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-8661 - Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin o

🏢 Linux 📅 26.6.2026 📊 CVSS: 4.8
4.8

CVE-2026-50745 - A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way U

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-50744 - A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-50742 - A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-chec

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-50741 - Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio an

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-50740 - A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive A

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-50739 - A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48936 - A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket),

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48935 - A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was se

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48934 - A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48933 - A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()`

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48930 - A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authorit

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-48928 - A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS s

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-48619 - A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48618 - A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48615 - A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` e

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-13226 - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge

🏢 Wordpress 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-9222 - Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the pass

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-9221 - The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to g

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-9220 - Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests bet

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-9219 - Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable re

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-43920 - FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-13322 - A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest request

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 3.8
3.8

CVE-2026-13318 - A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. Whe

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-13218 - A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function w

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 4.2
4.2

CVE-2026-13083 - A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML repor

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.9
6.9

CVE-2026-12993 - A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and

🏢 Sonstige 📅 26.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40941 - Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40084 - Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vu

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40083 - Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have S

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-40082 - Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have m

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-40080 - Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vu

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-8720 - wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the bloc

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-7532 - iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constrain

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-7511 - PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-6331 - HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-6330 - The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-O

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-6329 - PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity chec

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-6325 - Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list,

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-6092 - When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rat

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-55962 - TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished me

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-54479 - The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows mu

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-50176 - The WebSocket Application Programming Interface lacks restrictions on the number of authentication r

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-44622 - Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40702 - WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate chargin

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.4
9.4

CVE-2026-22879 - vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-13283 - Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote atta

🏢 Google 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-13282 - Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attac

🏢 Google 📅 25.6.2026 📊 CVSS: 6.8
6.8

CVE-2026-13281 - Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had

🏢 Google 📅 25.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-12992 - A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without di

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-12975 - A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParse

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-11800 - A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Gr

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-11703 - Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding c

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-10098 - OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer Sin

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.3
5.3

CVE-2025-71340 - picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.Modifie

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.1
8.1

CVE-2025-71338 - Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoin

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 10.0
10.0

CVE-2025-71336 - Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote co

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.8
9.8

CVE-2025-71335 - Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions an

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.1
8.1

CVE-2025-71334 - Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnera

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.8
9.8

CVE-2025-71333 - Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.8
9.8

CVE-2025-71328 - Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user ca

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.3
8.3

CVE-2025-71327 - Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.1
9.1

CVE-2025-71324 - Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /a

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2021-47987 - Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags w

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2021-47986 - Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were p

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2020-37256 - Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor def

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-6731 - X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certific

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-6681 - The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded c

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-6679 - A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-6678 - Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to inco

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-6450 - A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not prop

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-6412 - Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-56445 - The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datase

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-38640 - A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows att

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-38637 - An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-37452 - Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attac

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-12473 - Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitra

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-7531 - Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-546

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-57522 - Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProce

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 3.5
3.5

CVE-2026-57521 - Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any auth

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-57520 - Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authentic

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-55964 - Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificate

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-55960 - Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain v

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-55958 - Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capaci

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-46602 - The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious o

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-46601 - The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-37454 - Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attac

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-37453 - Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attac

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-37149 - GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL

🏢 Mysql 📅 25.6.2026 📊 CVSS: 7.7
7.7

CVE-2026-2299 - The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the

🏢 Google 📅 25.6.2026 📊 CVSS: 4.2
4.2

CVE-2026-12340 - Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificat

🏢 Sonstige 📅 25.6.2026 📊 CVSS: 7.5
7.5
«« « Zurück Seite 34 von 73 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.