CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-47641 - Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform sp
CVE-2026-47640 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-47639 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-47638 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-47637 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-47636 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-47635 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
CVE-2026-47634 - Improper neutralization of special elements in output used by a downstream component ('injection') i
CVE-2026-47631 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex
CVE-2026-47298 - Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code
CVE-2026-47293 - Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges
CVE-2026-47292 - Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorize
CVE-2026-47291 - Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code o
CVE-2026-47289 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
CVE-2026-47288 - Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code ove
CVE-2026-47287 - Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering o
CVE-2026-47284 - Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthori
CVE-2026-47281 - Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges ov
CVE-2026-46492 - md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cr
CVE-2026-45771 - FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary
CVE-2026-45658 - Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat
CVE-2026-45657 - Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
CVE-2026-45656 - Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feat
CVE-2026-45655 - Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
CVE-2026-45654 - Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security fe
CVE-2026-45653 - Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
CVE-2026-45650 - User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthoriz
CVE-2026-45649 - Improper access control in Office for Android allows an unauthorized attacker to perform spoofing lo
CVE-2026-45648 - Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exe
CVE-2026-45647 - Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an autho
CVE-2026-45645 - Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo
CVE-2026-45644 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Li
CVE-2026-45643 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co
CVE-2026-45642 - Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Servi
CVE-2026-45641 - Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthori
CVE-2026-45640 - Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges
CVE-2026-45639 - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
CVE-2026-45638 - Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
CVE-2026-45637 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-45636 - Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-45635 - Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll)
CVE-2026-45634 - Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information loca
CVE-2026-45608 - Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo
CVE-2026-45607 - Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
CVE-2026-45606 - Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny
CVE-2026-45605 - Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges loca
CVE-2026-45604 - Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker t
CVE-2026-45603 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-45602 - No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering ov
CVE-2026-45601 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-45600 - Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows
CVE-2026-45599 - Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code
CVE-2026-45598 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-45597 - Concurrent execution using shared resource with improper synchronization ('race condition') in UI Au
CVE-2026-45596 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-45595 - Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to by
CVE-2026-45594 - Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) S
CVE-2026-45593 - Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
CVE-2026-45592 - Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to el
CVE-2026-45591 - Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service ov
CVE-2026-45588 - Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi
CVE-2026-45586 - Improper link resolution before file access ('link following') in Windows Collaborative Translation
CVE-2026-45583 - Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an una
CVE-2026-45504 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to ele
CVE-2026-45503 - Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose inform
CVE-2026-45502 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to dis
CVE-2026-45501 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to per
CVE-2026-45500 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex
CVE-2026-45491 - Improper link resolution before file access ('link following') in .NET allows an unauthorized attack
CVE-2026-45490 - Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-45487 - Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows
CVE-2026-45486 - Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45485 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
CVE-2026-45484 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to el
CVE-2026-45483 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45482 - Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and
CVE-2026-45481 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45479 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45476 - Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-45475 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
CVE-2026-45474 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45471 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co
CVE-2026-45469 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to
CVE-2026-45468 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45467 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45466 - Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose info
CVE-2026-45465 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45464 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45463 - Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execut
CVE-2026-45462 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45461 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45460 - Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally
CVE-2026-45459 - Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a s
CVE-2026-45458 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45457 - Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45456 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor
CVE-2026-45455 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
CVE-2026-45454 - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office S
CVE-2026-45453 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-45447 - Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free du
CVE-2026-45446 - Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the au
CVE-2026-45445 - Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-sho
CVE-2026-44824 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
CVE-2026-44823 - Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code l
CVE-2026-44822 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
CVE-2026-44821 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
CVE-2026-44820 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
CVE-2026-44819 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local
CVE-2026-44818 - Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
CVE-2026-44817 - Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un
CVE-2026-44815 - Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code o
CVE-2026-44814 - Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
CVE-2026-44813 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-44812 - Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c
CVE-2026-44811 - Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv
CVE-2026-44810 - Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate
CVE-2026-44809 - Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate pri
CVE-2026-44808 - Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv
CVE-2026-44807 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-44805 - Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny s
CVE-2026-44804 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-44803 - Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c
CVE-2026-44802 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-44801 - Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
CVE-2026-44799 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
CVE-2026-42993 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
CVE-2026-42992 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
CVE-2026-42991 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-42989 - Improper link resolution before file access ('link following') in Winlogon allows an authorized atta
CVE-2026-42987 - Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a
CVE-2026-42986 - Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
CVE-2026-42985 - Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
CVE-2026-42984 - Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-42983 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-42981 - Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacke
CVE-2026-42980 - Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elev
CVE-2026-42979 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-42978 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-42977 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-42974 - Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to exe
CVE-2026-42973 - Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
CVE-2026-42972 - Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized a
CVE-2026-42971 - Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
CVE-2026-42970 - Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
CVE-2026-42969 - Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclos
CVE-2026-42968 - Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio
CVE-2026-42916 - Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate priv
CVE-2026-42915 - Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi
CVE-2026-42914 - Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
CVE-2026-42913 - Concurrent execution using shared resource with improper synchronization ('race condition') in Remot
CVE-2026-42912 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-42911 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-42910 - Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate
CVE-2026-42909 - Concurrent execution using shared resource with improper synchronization ('race condition') in Remot
CVE-2026-42908 - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
CVE-2026-42907 - Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
CVE-2026-42906 - Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
CVE-2026-42905 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local
CVE-2026-42904 - Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges o
CVE-2026-42903 - Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne
CVE-2026-42902 - Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges lo
CVE-2026-42837 - Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to e
CVE-2026-42836 - Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
CVE-2026-42835 - Improper neutralization of special elements in output used by a downstream component ('injection') i
CVE-2026-42829 - Improper access control in Windows Administrator Protection allows an authorized attacker to bypass
CVE-2026-42828 - Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to ele
CVE-2026-42771 - Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a craft
CVE-2026-42770 - Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key i
CVE-2026-42769 - Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key upd
CVE-2026-42768 - Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style at
CVE-2026-42767 - Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a N
CVE-2026-42766 - Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer derefer
CVE-2026-42765 - Issue summary: When a partial-chain certificate verification is enabled together with OCSP response
CVE-2026-42764 - Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dere
CVE-2026-42599 - Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to
CVE-2026-42573 - Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DO
CVE-2026-42570 - Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't
CVE-2026-42567 - Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an int
CVE-2026-41108 - Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile
CVE-2026-41098 - Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack
CVE-2026-41092 - Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges loca
CVE-2026-40409 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40404 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40376 - Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privilege
CVE-2026-40371 - Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises)
CVE-2026-3088 - Unauthenticated users on the local network can cause the router to become unavailable by sending spe
CVE-2026-38615 - DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-35188 - Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response thr
CVE-2026-34692 - Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C
CVE-2026-34335 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-34183 - Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with
CVE-2026-34182 - Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input val
CVE-2026-34181 - Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files th
CVE-2026-34180 - Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content
CVE-2026-33828 - Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges
CVE-2026-33113 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-32193 - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku
CVE-2026-28301 - A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to
CVE-2026-26142 - Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute c
CVE-2026-24181 - NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index
CVE-2026-24180 - NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffe
CVE-2026-22926 - Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
CVE-2026-0420 - An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud
CVE-2026-0419 - Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit releas
CVE-2026-0418 - Insufficient configuration management in the listed devices allows authenticated administrators conn
CVE-2026-0417 - Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin
CVE-2026-0416 - An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an
CVE-2026-0415 - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
CVE-2026-0414 - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
CVE-2026-0413 - A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models al
CVE-2026-0412 - Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band
CVE-2026-0411 - An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could al
CVE-2026-0410 - Authenticated administrators connected to the local network can gain elevated access to the router
CVE-2026-0409 - A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traf
CVE-2026-8045 - CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause
CVE-2026-8025 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-49948 - Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability
CVE-2026-49938 - A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2
CVE-2026-25089 - A improper neutralization of special elements used in an os command ('os command injection') vulnera
CVE-2026-24065 - Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerab
CVE-2026-24064 - Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerab
CVE-2026-10727 - An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions
CVE-2026-10523 - An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R1
CVE-2026-10520 - An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versi
CVE-2025-67862 - An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerabili
CVE-2026-9279 - Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an a
CVE-2026-7486 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-52907 - In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off
CVE-2026-52906 - In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being
CVE-2026-52905 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-pow
CVE-2026-52904 - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device le
CVE-2026-49762 - Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allo
CVE-2026-47901 - Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject
CVE-2026-47900 - Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaSc
CVE-2026-47899 - The Electron preload script in Logseq exposes an API method that allows the renderer process to invo
CVE-2026-46332 - In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound b
CVE-2026-46330 - In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP
CVE-2026-46329 - In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem
CVE-2026-46328 - In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix
CVE-2026-46327 - In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_su
CVE-2026-46326 - In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix
CVE-2026-46325 - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conver
CVE-2026-11793 - A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c c
CVE-2026-11792 - A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the cr
CVE-2026-11790 - A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce
CVE-2026-11789 - A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer
CVE-2026-11788 - A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocati
CVE-2026-11787 - A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start
CVE-2026-11786 - A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when p
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.