CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-17710 - Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot
CVE-2026-17709 - Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had c
CVE-2026-17708 - Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
CVE-2026-17707 - Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attac
CVE-2026-17706 - Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.
CVE-2026-17705 - Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exec
CVE-2026-17704 - Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
CVE-2026-17703 - Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all
CVE-2026-17702 - Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attack
CVE-2026-17701 - Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 a
CVE-2026-17700 - Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed
CVE-2026-17699 - Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentia
CVE-2026-17698 - Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72
CVE-2026-17697 - Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti
CVE-2026-17696 - Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote a
CVE-2026-17695 - Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot
CVE-2026-17694 - Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a
CVE-2026-17693 - Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remo
CVE-2026-17692 - Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote a
CVE-2026-17691 - Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote att
CVE-2026-17690 - Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72
CVE-2026-17689 - Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
CVE-2026-17688 - Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
CVE-2026-17687 - Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
CVE-2026-17686 - Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allo
CVE-2026-17685 - Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exec
CVE-2026-17684 - Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.
CVE-2026-17683 - Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac
CVE-2026-17682 - Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had
CVE-2026-17681 - Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior t
CVE-2026-17680 - Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote a
CVE-2026-17679 - Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72
CVE-2026-17678 - Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who ha
CVE-2026-17677 - Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r
CVE-2026-17676 - Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r
CVE-2026-17675 - Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h
CVE-2026-17674 - Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attack
CVE-2026-17673 - Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had c
CVE-2026-17672 - Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 all
CVE-2026-17671 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed
CVE-2026-17670 - Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
CVE-2026-17669 - Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
CVE-2026-17668 - Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
CVE-2026-17667 - Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
CVE-2026-17666 - Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a pr
CVE-2026-17665 - Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar
CVE-2026-17664 - Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed
CVE-2026-17663 - Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72
CVE-2026-17662 - Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote
CVE-2026-17661 - Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execut
CVE-2026-17660 - Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowe
CVE-2026-17659 - Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remo
CVE-2026-17658 - Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar
CVE-2026-17657 - Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h
CVE-2026-17656 - Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti
CVE-2026-17655 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed
CVE-2026-17654 - Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform O
CVE-2026-17653 - Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had com
CVE-2026-17652 - Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
CVE-2026-17651 - Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.7
CVE-2026-17650 - Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who
CVE-2026-64685 - ImageMagick is free and open-source software used for editing and manipulating digital images. In ve
CVE-2026-62946 - ImageMagick is free and open-source software used for editing and manipulating digital images. In ve
CVE-2026-62363 - ImageMagick is free and open-source software used for editing and manipulating digital images. In ve
CVE-2026-62343 - ImageMagick is free and open-source software used for editing and manipulating digital images. In ve
CVE-2026-16339 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-67595 - VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in t
CVE-2026-18060 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-15157 - undici does not validate the type property of a duck-typed blob-like request body before using it as
CVE-2026-14643 - undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualifi
CVE-2025-69949 - kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php v
CVE-2025-69945 - kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php
CVE-2025-69944 - kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php
CVE-2025-69943 - kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the pa
CVE-2025-69942 - kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient
CVE-2025-67408 - Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.ph
CVE-2025-67407 - Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_studen
CVE-2025-67406 - https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection.
CVE-2025-67405 - Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_passwo
CVE-2025-67404 - Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php
CVE-2025-67403 - Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.
CVE-2026-67439 - OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 30
CVE-2026-67438 - OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17
CVE-2026-67437 - OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17
CVE-2026-65975 - Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
CVE-2026-54249 - Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0
CVE-2026-50782 - Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.Hrm
CVE-2026-46678 - Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0
CVE-2026-16728 - undici's retry interceptor can deliver a response whose body length does not match the Content-Lengt
CVE-2026-13309 - Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerabili
CVE-2026-13308 - Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. Th
CVE-2026-13307 - Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerabilit
CVE-2026-13306 - Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows p
CVE-2026-13305 - Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arb
CVE-2025-65340 - kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsrep
CVE-2025-65337 - Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.
CVE-2026-6336 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1
CVE-2026-6267 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.
CVE-2026-6102 - MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulner
CVE-2026-67436 - Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related mo
CVE-2026-67435 - linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integ
CVE-2026-67433 - Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related mo
CVE-2026-67432 - MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.
CVE-2026-67431 - MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.
CVE-2026-67430 - MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.
CVE-2026-63119 - MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.
CVE-2026-63118 - MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.
CVE-2026-5492 - DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote
CVE-2026-5491 - DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote
CVE-2026-5490 - DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attacke
CVE-2026-5489 - DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote
CVE-2026-5487 - DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote
CVE-2026-5057 - ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability a
CVE-2026-5056 - GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit
CVE-2026-4672 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1
CVE-2026-3093 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1
CVE-2026-18266 - Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote at
CVE-2026-18022 - Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write d
CVE-2026-16553 - GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 bef
CVE-2026-15975 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1
CVE-2026-15831 - GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2
CVE-2026-15077 - GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2
CVE-2026-14351 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 b
CVE-2026-14341 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1
CVE-2026-13268 - G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This v
CVE-2026-13113 - GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 bef
CVE-2026-12436 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1
CVE-2026-12357 - Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability.
CVE-2025-14562 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1
CVE-2026-67429 - Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.dow
CVE-2026-67428 - Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emit
CVE-2026-67427 - Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workf
CVE-2026-67426 - Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the stand
CVE-2026-67425 - Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat
CVE-2026-67424 - Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP
CVE-2026-67201 - V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulne
CVE-2026-66737 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62995 - joserfc is a Python library that provides an implementation of several JSON Object Signing and Encry
CVE-2026-59898 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fin
CVE-2026-2482 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site req
CVE-2026-16328 - In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was
CVE-2026-16326 - In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless
CVE-2026-14529 - IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.
CVE-2026-13346 - pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be insta
CVE-2026-12935 - The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lea
CVE-2026-10684 - In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a
CVE-2026-8497 - Improper certificate validation in the Devolutions Server connection handling in Devolutions Passwor
CVE-2026-59920 - Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.F
CVE-2026-59919 - Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.F
CVE-2026-59901 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fina
CVE-2026-59900 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fina
CVE-2026-59899 - Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Fina
CVE-2026-54705 - MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to esc
CVE-2026-41939 - Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildF
CVE-2026-40272 - Improper Input Validation in the decode() function of the traceparser library could allow an attacke
CVE-2026-18236 - A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmat
CVE-2026-14266 - 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerab
CVE-2026-13723 - A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker t
CVE-2026-8339 - A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0
CVE-2026-8338 - A Spring Security authentication and authorization bypass exists in Coverity Connect versions betwee
CVE-2026-67194 - Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to cra
CVE-2026-64560 - In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF c
CVE-2026-64559 - In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY
CVE-2026-64558 - In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey
CVE-2026-54727 - proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restor
CVE-2026-54693 - ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 unti
CVE-2026-54680 - Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior t
CVE-2026-54574 - proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro instal
CVE-2026-52791 - fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the
CVE-2026-51992 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHou
CVE-2026-20316 - A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could
CVE-2026-18257 - Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of
CVE-2026-18255 - A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot acc
CVE-2026-16729 - undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from
CVE-2026-15144 - @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned
CVE-2026-13697 - undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up
CVE-2025-60931 - An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Globa
CVE-2026-67193 - Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthen
CVE-2026-67192 - Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability tha
CVE-2026-67191 - Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that
CVE-2026-67188 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-66051 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60113 - AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing au
CVE-2026-60112 - AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that
CVE-2026-54735 - Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Pr
CVE-2026-54082 - veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.
CVE-2026-54081 - veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains
CVE-2026-54080 - veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains
CVE-2026-54079 - veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. Fro
CVE-2026-54078 - veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.
CVE-2026-50558 - Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior t
CVE-2026-17550 - A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bou
CVE-2026-16543 - Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scope
CVE-2026-16465 - A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bou
CVE-2026-16463 - A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflo
CVE-2026-15228 - Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privile
CVE-2026-66724 - MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecat
CVE-2026-66723 - MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote I
CVE-2026-65947 - Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65888 - Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogi
CVE-2026-65887 - Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The
CVE-2026-65886 - Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo
CVE-2026-59247 - Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the mid
CVE-2026-54666 - swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior
CVE-2026-54664 - swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior
CVE-2026-54663 - swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior t
CVE-2026-54662 - swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior t
CVE-2026-54661 - swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior
CVE-2026-54660 - swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior t
CVE-2026-12703 - TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that c
CVE-2026-9177 - A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functiona
CVE-2026-67217 - cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON
CVE-2026-67216 - cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When co
CVE-2026-67215 - cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an unt
CVE-2026-67214 - nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid
CVE-2026-67213 - nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom funct
CVE-2026-66490 - Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.
CVE-2026-66489 - Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-66488 - Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-66400 - Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in
CVE-2026-65890 - Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi v
CVE-2026-65889 - Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generat
CVE-2026-55995 - A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
CVE-2026-18174 - @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0
CVE-2026-16751 - Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum S
CVE-2026-65946 - Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVE-2026-65944 - Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
CVE-2026-65943 - Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
CVE-2026-65891 - Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite
CVE-2026-65885 - Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File uplo
CVE-2026-65884 - Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method
CVE-2026-50641 - Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database Thi
CVE-2026-44944 - An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the i
CVE-2026-44943 - An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in o
CVE-2026-33385 - A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of inp
CVE-2026-14354 - CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication by
CVE-2026-12927 - CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk a
CVE-2026-0667 - CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitra
CVE-2026-14270 - The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for Wo
CVE-2026-8791 - The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-7436 - The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr
CVE-2026-6089 - The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media
CVE-2026-65883 - Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guar
CVE-2026-5060 - The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vuln
CVE-2026-56390 - GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %h
CVE-2026-56389 - GNU Bison allows for an execution of an arbitrary program during HTML report generation due to impro
CVE-2026-50642 - diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff d
CVE-2026-4604 - The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of d
CVE-2026-18220 - An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c
CVE-2026-16655 - The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware