CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-64579 - In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: preallocate inexa
CVE-2026-64578 - In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound reques
CVE-2026-64577 - In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() retu
CVE-2026-64576 - In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in n
CVE-2026-64575 - In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock relea
CVE-2026-64574 - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new l
CVE-2026-64573 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag len
CVE-2026-64572 - In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with
CVE-2026-64571 - In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame le
CVE-2026-64570 - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discov
CVE-2026-64569 - In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_va
CVE-2026-64568 - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast
CVE-2026-64567 - In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache
CVE-2026-64566 - In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SH
CVE-2026-61486 - ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This is
CVE-2026-61485 - Rejected reason: this attack requires control over the search index, which is considered fully trust
CVE-2026-61484 - ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. T
CVE-2026-61483 - ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue a
CVE-2026-5651 - The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in mult
CVE-2026-5581 - The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary me
CVE-2026-5116 - The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-5108 - The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-59675 - When API audit logging is enabled, the middleware reads the entire HTTP request body into memory wit
CVE-2026-55998 - The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the
CVE-2026-55997 - Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream
CVE-2026-55996 - A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the catt
CVE-2026-55747 - The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin
CVE-2026-55739 - Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both
CVE-2026-54418 - Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecre
CVE-2026-54416 - Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using
CVE-2026-4431 - The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due
CVE-2026-18881 - The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injec
CVE-2026-17532 - The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via
CVE-2026-17505 - The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cr
CVE-2026-15281 - The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id
CVE-2026-12000 - The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure i
CVE-2026-11977 - The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPre
CVE-2026-11969 - The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'cu
CVE-2026-11920 - The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerabl
CVE-2026-11454 - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to In
CVE-2026-71201 - In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can retu
CVE-2026-70375 - HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deplo
CVE-2026-70374 - HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upl
CVE-2026-68080 - It was not possible to govern the rate at which the broker would respond to an echo flow, enabling a
CVE-2026-68078 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-68077 - An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi
CVE-2026-68075 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-68073 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-67592 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-67591 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-67590 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-67555 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-67554 - An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi
CVE-2026-67553 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-67552 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-66277 - It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling
CVE-2026-66276 - An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi
CVE-2026-66275 - An authenticated attacker could exceed the session flow control incoming window potentially leading
CVE-2026-66274 - A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially
CVE-2026-49004 - The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command
CVE-2026-17515 - The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does n
CVE-2026-16993 - The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping
CVE-2026-16981 - The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authoriz
CVE-2026-16968 - The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users a
CVE-2026-16942 - The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of
CVE-2026-16940 - The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before d
CVE-2026-16746 - The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to
CVE-2026-16736 - The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's regist
CVE-2026-16613 - The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an acti
CVE-2026-16605 - The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its
CVE-2026-16604 - The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public p
CVE-2026-16603 - The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection o
CVE-2026-16602 - The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning po
CVE-2026-16583 - The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress
CVE-2026-16573 - The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before sto
CVE-2026-16561 - The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in on
CVE-2026-16055 - The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the s
CVE-2026-16036 - The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured d
CVE-2026-15372 - The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when on
CVE-2026-15360 - The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter
CVE-2026-15230 - The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its R
CVE-2026-15210 - The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the
CVE-2026-14553 - The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the c
CVE-2025-15677 - The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category sett
CVE-2026-9273 - The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vuln
CVE-2026-8790 - The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shou
CVE-2026-8761 - The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl
CVE-2026-7753 - The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive d
CVE-2026-71192 - In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control heade
CVE-2026-71191 - In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers a
CVE-2026-71190 - In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expressi
CVE-2026-68074 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-68060 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation
CVE-2026-67589 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation
CVE-2026-67588 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-67551 - pre-authentication attacker could leverage type size/count handling to cause excessive allocation le
CVE-2026-67465 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-66839 - NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path o
CVE-2026-66344 - NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Pa
CVE-2026-66273 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation
CVE-2026-66257 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus
CVE-2026-5062 - The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugi
CVE-2026-55707 - In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the t
CVE-2026-18903 - A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. T
CVE-2026-18902 - A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function es
CVE-2026-18322 - The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versi
CVE-2026-16143 - The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cr
CVE-2026-15941 - The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run R
CVE-2026-15918 - VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injec
CVE-2026-11421 - The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vu
CVE-2026-18901 - A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.ad
CVE-2026-18900 - A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file
CVE-2026-18898 - A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the functi
CVE-2026-18907 - Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary
CVE-2026-18897 - A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element
CVE-2026-18896 - A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected eleme
CVE-2026-18895 - A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function st
CVE-2026-18859 - A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of th
CVE-2026-18856 - A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImpo
CVE-2026-46334 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4
CVE-2026-45809 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4
CVE-2026-45705 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 an
CVE-2026-18854 - A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. T
CVE-2026-18853 - A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This
CVE-2026-18852 - A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79de
CVE-2026-18103 - A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management
CVE-2026-45537 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 an
CVE-2026-18819 - A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d97
CVE-2026-18818 - A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the functio
CVE-2026-70620 - Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admi
CVE-2026-70619 - Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authentica
CVE-2026-70594 - Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidat
CVE-2026-70593 - Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom th
CVE-2026-70592 - Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user
CVE-2026-70591 - Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forger
CVE-2026-70590 - Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak
CVE-2026-70589 - Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check a
CVE-2026-67862 - open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/u
CVE-2026-67861 - An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via t
CVE-2026-67860 - open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the defau
CVE-2026-67859 - Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of serv
CVE-2026-67858 - Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is bui
CVE-2026-67857 - open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArr
CVE-2026-67856 - An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via c
CVE-2026-67855 - open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when
CVE-2026-52370 - A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allow
CVE-2026-51144 - Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allow
CVE-2026-45103 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 an
CVE-2026-45100 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3
CVE-2026-45084 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5
CVE-2026-18817 - A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function B
CVE-2026-18816 - A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the functio
CVE-2026-18814 - A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of th
CVE-2026-70588 - Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature
CVE-2026-70554 - MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to e
CVE-2026-70494 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 un
CVE-2026-70493 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt
CVE-2026-70492 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 un
CVE-2026-70491 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and
CVE-2026-70490 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 unt
CVE-2026-70489 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 unt
CVE-2026-70488 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt
CVE-2026-70487 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 unt
CVE-2026-67979 - Incorrect access control in the Executive Services dynamic application start path component of NASA
CVE-2026-66902 - Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JS
CVE-2026-66901 - Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltra
CVE-2026-65986 - CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5
CVE-2026-54020 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.
CVE-2026-51401 - An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via
CVE-2026-51400 - An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via
CVE-2026-45538 - OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior,
CVE-2026-18813 - A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /a
CVE-2026-18812 - A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of th
CVE-2026-18811 - A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the f
CVE-2026-13227 - An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to in
CVE-2026-70553 - MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to
CVE-2026-70552 - MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher
CVE-2026-70486 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 unt
CVE-2026-70485 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 unt
CVE-2026-70484 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 unt
CVE-2026-70483 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt
CVE-2026-70482 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 unt
CVE-2026-70481 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 unt
CVE-2026-70480 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 un
CVE-2026-70479 - Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt
CVE-2026-70478 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-70477 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-70476 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-70475 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-48154 - GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful A
CVE-2026-47682 - CVAT is an open source interactive video and image annotation tool for computer vision. In versions
CVE-2026-18810 - A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of
CVE-2026-18657 - An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remot
CVE-2026-18656 - An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remo
CVE-2026-16793 - An improper neutralization of special elements used in an operating system command vulnerability was
CVE-2026-16792 - An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrat
CVE-2026-16791 - A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.
CVE-2026-70474 - Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows.
CVE-2026-70473 - Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows.
CVE-2026-70472 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-70471 - Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows.
CVE-2026-69704 - Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database quer
CVE-2026-69703 - Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_
CVE-2026-69702 - SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that al
CVE-2026-68743 - A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate t
CVE-2026-66300 - SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirec
CVE-2026-49435 - Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauth
CVE-2026-47781 - PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automati
CVE-2026-47764 - pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior t
CVE-2026-13229 - Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article at
CVE-2026-0163 - In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. Th
CVE-2017-20242 - Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticate
CVE-2017-20241 - Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated
CVE-2026-70470 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69264 - Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI
CVE-2026-47763 - pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prio
CVE-2026-47623 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of un
CVE-2026-47622 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of err
CVE-2026-47621 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in t
CVE-2026-47620 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in t
CVE-2026-47619 - NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a
CVE-2026-47618 - NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attac
CVE-2026-47617 - NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker m
CVE-2026-47616 - NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker m
CVE-2026-47615 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request for
CVE-2026-47614 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request for
CVE-2026-47613 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of
CVE-2026-47612 - NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker ma
CVE-2026-47487 - NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files out
CVE-2026-24255 - NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacke
CVE-2026-24254 - NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attack
CVE-2026-24253 - NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds writ
CVE-2026-18830 - Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remot
CVE-2026-18790 - A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac
CVE-2026-18788 - A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted eleme
CVE-2026-69263 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69262 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69259 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69258 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69257 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69256 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-69255 - Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.
CVE-2026-64634 - A vulnerability allowing local privilege escalation to the Reporter service context.
CVE-2026-64633 - A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-64631 - A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-64630 - A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared
CVE-2026-63456 - Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow
CVE-2026-63455 - Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow
CVE-2026-58075 - A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which ca
CVE-2026-58074 - A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware