CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-77567 - Filament is a collection of full-stack components for accelerated Laravel development. Prior to vers
CVE-2026-75554 - Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows
CVE-2026-75542 - Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key h
CVE-2026-75464 - OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
CVE-2026-5006 - A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authen
CVE-2026-56136 - In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c t
CVE-2026-56135 - In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id
CVE-2026-55468 - Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4,
CVE-2026-52492 - An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buf
CVE-2026-52490 - An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary
CVE-2026-19568 - A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
CVE-2026-16783 - A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri
CVE-2026-16782 - A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Rea
CVE-2026-16781 - A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Re
CVE-2022-30983 - A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2
CVE-2026-78555 - RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administ
CVE-2026-78553 - RansomLook created its Flask session-signing key without explicitly restricting the file permissions
CVE-2026-78551 - RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated
CVE-2026-78430 - A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the funct
CVE-2026-77923 - Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted b
CVE-2026-77310 - jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson
CVE-2026-76816 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Fina
CVE-2026-76098 - Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul
CVE-2026-75509 - joserfc is a Python library that provides an implementation of several JSON Object Signing and Encry
CVE-2026-75369 - An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component o
CVE-2026-75368 - A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows
CVE-2026-72714 - Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module t
CVE-2026-72711 - The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_
CVE-2026-72705 - The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own argum
CVE-2026-72704 - The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive
CVE-2026-72703 - The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without e
CVE-2026-71511 - Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that
CVE-2026-71510 - Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows auth
CVE-2026-63693 - Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerab
CVE-2026-61419 - Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A
CVE-2020-37268 - Print Assumptions does not report that a definition was produced while universe checking was disable
CVE-2026-78541 - A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE
CVE-2026-78417 - Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop M
CVE-2026-75371 - An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90e
CVE-2026-75370 - An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of Space
CVE-2026-71832 - Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, wh
CVE-2026-71509 - Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST A
CVE-2026-71508 - Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update
CVE-2026-71507 - Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API co
CVE-2026-71506 - Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API del
CVE-2026-71505 - Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API th
CVE-2026-71504 - Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that
CVE-2026-71503 - Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields a
CVE-2026-40877 - Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP ob
CVE-2026-39975 - Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could
CVE-2026-30864 - Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflec
CVE-2026-13081 - Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA shou
CVE-2026-13047 - Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA shou
CVE-2025-26238 - In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary
CVE-2025-26237 - D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of m
CVE-2026-9254 - An unauthenticated OS command injection vulnerability exists in the parental control functionality o
CVE-2026-78475 - A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image
CVE-2026-76838 - Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInter
CVE-2026-76837 - Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding.
CVE-2026-76836 - AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not requi
CVE-2026-76835 - OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk
CVE-2026-76073 - Label Studio does not scope the annotation detail endpoint to the requesting user's organization. An
CVE-2026-76072 - The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands wh
CVE-2026-71982 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-71943 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet funct
CVE-2026-71942 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert fu
CVE-2026-71941 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail func
CVE-2026-71940 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup
CVE-2026-71939 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup
CVE-2026-71938 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp f
CVE-2026-71937 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_prof
CVE-2026-71936 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot functio
CVE-2026-71935 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction f
CVE-2026-71934 - Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace functio
CVE-2026-71933 - Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo
CVE-2026-71932 - Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile
CVE-2026-71931 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade fu
CVE-2026-71930 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime functio
CVE-2026-71929 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto fun
CVE-2026-71928 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice func
CVE-2026-71927 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice funct
CVE-2026-71926 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice funct
CVE-2026-71925 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail funct
CVE-2026-71924 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function
CVE-2026-71923 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set functi
CVE-2026-71922 - Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerabil
CVE-2026-71921 - Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in
CVE-2026-71920 - Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogo
CVE-2026-71919 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot funct
CVE-2026-71918 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction
CVE-2026-71917 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace funct
CVE-2026-71916 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable fu
CVE-2026-71915 - Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus func
CVE-2026-71914 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component.
CVE-2026-71913 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi
CVE-2026-71912 - Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function.
CVE-2026-71911 - Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The
CVE-2026-71910 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function
CVE-2026-71909 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime functio
CVE-2026-71908 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_te
CVE-2026-71907 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function.
CVE-2026-71906 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. Th
CVE-2026-71905 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings func
CVE-2026-71904 - Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform fun
CVE-2026-34491 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-16348 - An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with
CVE-2026-13213 - The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-c
CVE-2026-78465 - A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX
CVE-2026-78329 - Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Ap
CVE-2026-77915 - rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthe
CVE-2026-77914 - rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated u
CVE-2026-76831 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76830 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76829 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-75099 - Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apa
CVE-2026-71300 - Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issu
CVE-2026-66908 - Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue af
CVE-2026-66907 - Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affect
CVE-2026-66906 - Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue af
CVE-2026-63621 - Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstrea
CVE-2026-60093 - Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue
CVE-2026-59230 - Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.
CVE-2026-19685 - NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path d
CVE-2026-18349 - Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Har
CVE-2026-15469 - The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality
CVE-2025-36940 - Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privile
CVE-2025-36939 - Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on
CVE-2026-78416 - Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenti
CVE-2026-76071 - Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that al
CVE-2026-76070 - Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that al
CVE-2026-71366 - A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends.
CVE-2026-71364 - A path traversal vulnerability was found in AWX's project archive extraction. The project_archive ac
CVE-2026-67204 - BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated AP
CVE-2026-21752 - HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker una
CVE-2026-13343 - The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-by
CVE-2026-13212 - The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device write
CVE-2026-12556 - Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior t
CVE-2026-12555 - Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior t
CVE-2026-12554 - Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior t
CVE-2025-68825 - HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lat
CVE-2026-9728 - The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nest
CVE-2026-78414 - Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before vers
CVE-2026-78391 - RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet d
CVE-2026-78387 - RansomLook contains an authorization weakness in the web-based configuration editor exposed through
CVE-2026-76055 - Improper Neutralization of Special Elements used in an OS Command in the package manager component o
CVE-2026-76054 - Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 throu
CVE-2026-65053 - Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML statu
CVE-2026-39915 - TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to injec
CVE-2026-39914 - TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticate
CVE-2026-21755 - HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via b
CVE-2026-19874 - A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from
CVE-2026-78386 - RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated A
CVE-2026-78385 - RansomLook contains insufficient resource validation in the analysis PDF generation functionality. A
CVE-2026-78381 - RansomLook contains a path traversal vulnerability in the handling of the screen field associated wi
CVE-2026-78380 - RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing ne
CVE-2026-78378 - Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralizati
CVE-2026-78376 - A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due
CVE-2026-78372 - RansomLook does not consistently enforce authorization checks when accessing groups, markets, and r
CVE-2026-78370 - RansomLook contains an authorization flaw in its legacy database export functionality that can allow
CVE-2026-78369 - RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint.
CVE-2026-78367 - A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source arc
CVE-2026-78250 - A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown funct
CVE-2026-78248 - A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is
CVE-2026-77995 - Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, O
CVE-2026-76848 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76847 - act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actio
CVE-2026-76845 - adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in
CVE-2026-76844 - zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_wri
CVE-2026-76843 - The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose Clus
CVE-2026-76842 - The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without
CVE-2026-76841 - Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before
CVE-2026-76840 - RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buff
CVE-2026-67602 - phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows una
CVE-2026-59568 - Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code executio
CVE-2026-59567 - Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege esca
CVE-2026-59566 - A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected ver
CVE-2026-59565 - A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on
CVE-2026-59564 - An authentication bypass issue exists in communications between affected versions of the Zscaler Cli
CVE-2026-30512 - A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementati
CVE-2026-21751 - HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an a
CVE-2026-17033 - An authenticated attacker with Editor access or alert.instances.external:write can submit an externa
CVE-2025-68833 - HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could
CVE-2026-78365 - Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0
CVE-2026-78247 - A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affec
CVE-2026-21759 - HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found
CVE-2026-21756 - HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unaut
CVE-2026-78323 - A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trus
CVE-2026-78291 - Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
CVE-2026-78290 - Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
CVE-2026-78280 - Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
CVE-2026-78279 - Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
CVE-2026-78278 - Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78277 - Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-78272 - Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
CVE-2026-78270 - Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-78269 - Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
CVE-2026-78258 - Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-78246 - A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerabili
CVE-2026-6017 - Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpo
CVE-2026-66671 - Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
CVE-2026-66670 - Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
CVE-2026-66650 - Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
CVE-2026-66648 - Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVE-2026-66623 - Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
CVE-2026-66610 - Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
CVE-2026-66599 - Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
CVE-2026-66587 - Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-66585 - Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
CVE-2026-66584 - Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
CVE-2026-32558 - Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPres
CVE-2026-32551 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-32478 - Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
CVE-2026-32477 - Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <=
CVE-2026-32476 - Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
CVE-2026-32471 - Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
CVE-2026-28190 - Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
CVE-2026-28171 - Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
CVE-2026-28167 - Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
CVE-2026-28166 - Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
CVE-2026-28165 - Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVE-2026-28162 - Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
CVE-2026-28153 - Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notificatio
CVE-2026-28152 - Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
CVE-2026-28151 - Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
CVE-2025-63080 - Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC re
CVE-2026-78337 - Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow C
CVE-2026-78245 - A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_upl
CVE-2026-78244 - A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this iss
CVE-2026-76172 - fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme
CVE-2026-59295 - It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-o
CVE-2026-10618 - Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info str
CVE-2026-10582 - Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRem
CVE-2026-78317 - SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78316 - SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78315 - SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78314 - SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-75975 - fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validat
CVE-2026-75931 - fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input
CVE-2026-75899 - fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and th
CVE-2026-66897 - A path traversal vulnerability in LXD's instance template processing allows an attacker with contain
CVE-2026-16249 - Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were
CVE-2026-78321 - The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or re
CVE-2026-78306 - DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker w
CVE-2026-78255 - The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoi
CVE-2026-77994 - Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla
CVE-2026-77993 - Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Pag
CVE-2026-8173 - The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC addre
CVE-2026-78202 - A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_setting
CVE-2026-78201 - A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the funct
CVE-2026-78200 - A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unkn
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware