CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-15969 - SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickle
CVE-2026-14227 - An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to
CVE-2026-13444 - IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector
CVE-2026-13435 - IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the Pyt
CVE-2026-12943 - IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management sys
CVE-2026-12942 - IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the s
CVE-2026-12733 - IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper res
CVE-2026-12118 - IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to
CVE-2026-11904 - IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1
CVE-2026-10700 - IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its
CVE-2026-10695 - IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non
CVE-2026-10545 - IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an a
CVE-2026-10535 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid
CVE-2025-36374 - IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing
CVE-2025-0152 - IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6
CVE-2024-40683 - IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.
CVE-2024-25039 - IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6
CVE-2026-9322 - IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
CVE-2026-66414 - Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthent
CVE-2026-62663 - Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4,
CVE-2026-54722 - DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks.
CVE-2026-54522 - MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1
CVE-2026-51295 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51294 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51293 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51292 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51291 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51290 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-13379 - The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause
CVE-2026-13117 - An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authe
CVE-2026-12996 - A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenti
CVE-2026-12945 - IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other user
CVE-2026-12940 - IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via e
CVE-2026-12932 - A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alph
CVE-2026-11885 - IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 throug
CVE-2026-11771 - OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one
CVE-2026-67596 - CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that a
CVE-2026-58222 - A security flaw combining LDAP filter injection and improper authorization checks was found in Samba
CVE-2026-58216 - An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password ch
CVE-2026-57862 - Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authentic
CVE-2026-52680 - Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when
CVE-2026-4978 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-48910 - A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsi
CVE-2026-44617 - LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name e
CVE-2026-44616 - LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search f
CVE-2026-44613 - Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration a
CVE-2026-28814 - Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows
CVE-2026-28813 - Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.
CVE-2026-28812 - UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attac
CVE-2026-28811 - Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommend
CVE-2026-28323 - SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This
CVE-2026-23985 - A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.
CVE-2026-23981 - An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user wit
CVE-2026-15658 - A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to
CVE-2026-15657 - A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext paym
CVE-2026-10842 - IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.
CVE-2026-6540 - Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes,
CVE-2026-67349 - OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded
CVE-2026-67348 - Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoi
CVE-2026-67347 - Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulner
CVE-2026-67346 - Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability
CVE-2026-67345 - MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vul
CVE-2026-65635 - Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid m
CVE-2026-54885 - Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attac
CVE-2026-53431 - Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has
CVE-2026-41187 - Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOpe
CVE-2026-41186 - When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and
CVE-2026-16308 - IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus RES
CVE-2026-15435 - IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a
CVE-2026-14980 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site req
CVE-2026-14522 - IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a
CVE-2026-14519 - IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a
CVE-2026-12947 - IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potenti
CVE-2026-11980 - IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files
CVE-2026-11897 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of se
CVE-2026-11707 - IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affecte
CVE-2026-11383 - IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affecte
CVE-2025-36431 - IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through
CVE-2025-36298 - IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.
CVE-2026-67351 - Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password v
CVE-2026-60075 - Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the un
CVE-2026-60074 - Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that
CVE-2026-5219 - Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Co
CVE-2026-58218 - A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests wer
CVE-2026-57859 - e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization h
CVE-2026-56428 - The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability
CVE-2026-41709 - VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit t
CVE-2026-12722 - Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerc
CVE-2026-59310 - VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor
CVE-2026-59309 - VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A ma
CVE-2026-54368 - CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchE
CVE-2026-54367 - CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated
CVE-2026-54366 - CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows un
CVE-2026-54365 - CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll
CVE-2026-54364 - CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthentica
CVE-2026-54363 - CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthentic
CVE-2026-47876 - VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A m
CVE-2026-41703 - VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor w
CVE-2026-7260 - Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack a
CVE-2026-5582 - The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
CVE-2026-18382 - A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resourc
CVE-2026-18381 - A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMe
CVE-2026-18378 - A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resourc
CVE-2026-17544 - Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corrup
CVE-2026-17543 - Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injecti
CVE-2026-15397 - The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all
CVE-2026-22622 - Improper input validation in one of the session management interface of Eaton's Tripp Lite series PA
CVE-2026-22621 - Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PA
CVE-2026-22620 - Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware
CVE-2026-18369 - A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP add
CVE-2026-18363 - A logic vulnerability in the password reset token validation routine implemented by osTicket in vers
CVE-2026-18362 - The IRIS web application in version 2.4.26 and possibly others does not protect its user authenticat
CVE-2026-18361 - The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc
CVE-2026-18360 - The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc
CVE-2026-16971 - The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation a
CVE-2026-16970 - The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which
CVE-2026-16969 - The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc
CVE-2022-4994 - In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emu
CVE-2026-18353 - PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT and checks its **unverified** `iss` claim
CVE-2026-7849 - Due to improper neutralization of special elements, an unauthenticated remote attacker is able to in
CVE-2026-44108 - Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematur
CVE-2026-44107 - A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefor
CVE-2026-44106 - A privilege escalation vulnerability in the init-script for user-applications allows a low-privilege
CVE-2026-44105 - The credentials for the local user "user-app" may be exposed in log files, potentially enabling a lo
CVE-2026-44104 - The firmware update process for the basemodule of the charging controller only validates the CRC32 c
CVE-2026-44103 - An unauthenticated remote attacker can inject malicious firmware into the internal charging module b
CVE-2026-44102 - An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by su
CVE-2026-44101 - Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker
CVE-2026-44100 - The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points.
CVE-2026-44099 - A privilege escalation vulnerability in the system configuration allows a low-privileged local user
CVE-2026-44098 - This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via
CVE-2026-44097 - A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endp
CVE-2026-44096 - A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary
CVE-2026-44095 - A privilege escalation vulnerability in a script used for network configuration allows a low-privile
CVE-2026-44094 - An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with
CVE-2026-44093 - A local privilege escalation vulnerability in the init-script for user-applications allows a low-pri
CVE-2026-44092 - An unauthenticated remote attacker can inject malicious input into the ModbusServer application beca
CVE-2026-44091 - An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creatio
CVE-2026-44090 - Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which
CVE-2026-13584 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerabili
CVE-2026-64635 - Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provid
CVE-2026-59328 - Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded
CVE-2026-59327 - Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secre
CVE-2026-59326 - The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PR
CVE-2026-58066 - Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7
CVE-2026-58046 - Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user t
CVE-2026-58043 - A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree pr
CVE-2026-58040 - An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verif
CVE-2026-56850 - A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing m
CVE-2026-56847 - A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes
CVE-2026-47882 - When enabling Spring Boot DevTools support for a remote application target (for example a Docker con
CVE-2026-47873 - The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of th
CVE-2026-47858 - Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes t
CVE-2026-16531 - An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy log
CVE-2026-16530 - A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit
CVE-2026-16529 - A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network pack
CVE-2026-16527 - An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP
CVE-2026-16526 - A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with in
CVE-2026-16524 - A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the n
CVE-2026-15382 - The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capa
CVE-2026-15257 - The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or
CVE-2026-15255 - The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time pa
CVE-2026-15252 - The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in
CVE-2026-15250 - The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields
CVE-2026-15240 - The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching
CVE-2026-15235 - The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before
CVE-2026-15153 - The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter o
CVE-2026-15054 - The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its
CVE-2026-14923 - The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-edit
CVE-2026-14602 - The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing use
CVE-2026-14592 - The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability o
CVE-2026-14318 - The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before o
CVE-2026-14310 - The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the
CVE-2026-14305 - The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of i
CVE-2026-14239 - The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-fi
CVE-2026-14231 - The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its sel
CVE-2026-14226 - The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on on
CVE-2026-14223 - The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when r
CVE-2026-14222 - The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check
CVE-2026-14221 - The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of
CVE-2026-14207 - The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course
CVE-2026-14188 - The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or n
CVE-2026-13395 - The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize
CVE-2026-13345 - The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, s
CVE-2026-13344 - The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag na
CVE-2026-13330 - The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVG
CVE-2026-13178 - The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts a
CVE-2026-13145 - The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its cust
CVE-2026-13143 - The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications t
CVE-2026-12687 - The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor
CVE-2026-12500 - The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX a
CVE-2026-11881 - The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field c
CVE-2026-11870 - The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP infor
CVE-2026-11867 - The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks o
CVE-2026-11782 - The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation ch
CVE-2026-67248 - A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerabi
CVE-2026-67247 - A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs be
CVE-2026-67246 - A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs
CVE-2026-67245 - A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs bec
CVE-2026-1360 - The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versio
CVE-2026-16610 - The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Executio
CVE-2026-14356 - The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, a
CVE-2026-67244 - A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability
CVE-2026-48449 - Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu
CVE-2026-48448 - Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a
CVE-2026-1982 - The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in al
CVE-2026-18188 - A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs bec
CVE-2026-18187 - A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs
CVE-2026-18186 - A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occur
CVE-2026-16092 - The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_
CVE-2026-16727 - Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS
CVE-2026-15929 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-59952 - Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its
CVE-2026-18019 - Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote a
CVE-2026-18018 - Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a
CVE-2026-18017 - Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute
CVE-2026-18016 - Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all
CVE-2026-18015 - Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote
CVE-2026-18014 - Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow
CVE-2026-18013 - Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
CVE-2026-18012 - Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execut
CVE-2026-18011 - Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
CVE-2026-18010 - Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a
CVE-2026-18009 - Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allo
CVE-2026-18008 - Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote at
CVE-2026-18007 - Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a r
CVE-2026-18006 - Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote
CVE-2026-18005 - Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attac
CVE-2026-18004 - Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote a
CVE-2026-18003 - Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
CVE-2026-18002 - Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 al
CVE-2026-18001 - Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attac
CVE-2026-18000 - Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a
CVE-2026-17999 - Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacke
CVE-2026-17998 - Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who
CVE-2026-17997 - Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a
CVE-2026-17996 - Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a loc
CVE-2026-17995 - Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perf
CVE-2026-17994 - Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a r
CVE-2026-17993 - Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perfo
CVE-2026-17992 - Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attack
CVE-2026-17991 - Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a r
CVE-2026-17990 - Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allow
CVE-2026-17989 - Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar
CVE-2026-17988 - Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 all
CVE-2026-17987 - Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72
CVE-2026-17986 - Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remot
CVE-2026-17985 - Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote a
CVE-2026-17984 - Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a
CVE-2026-17983 - Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowe
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware