CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-16634 - TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The
CVE-2026-15663 - The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to
CVE-2026-15401 - The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-10033 - The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions u
CVE-2026-63317 - Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP
CVE-2026-56392 - GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow duri
CVE-2026-56391 - GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte inp
CVE-2026-49745 - Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmwa
CVE-2026-49744 - Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmwa
CVE-2026-49743 - Software installed and run as a non-privileged user may conduct improper GPU system calls to manipul
CVE-2026-24727 - An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload functio
CVE-2026-15821 - The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cr
CVE-2026-15739 - The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripti
CVE-2026-15704 - In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vuln
CVE-2026-15346 - The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site
CVE-2026-12702 - In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an
CVE-2026-16910 - A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notif
CVE-2026-16519 - A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The
CVE-2026-15755 - The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-15665 - The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to
CVE-2026-15653 - The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerab
CVE-2026-15648 - The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wi
CVE-2026-15464 - The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_s
CVE-2026-15334 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
CVE-2026-15333 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
CVE-2026-12654 - The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypas
CVE-2026-14603 - The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorizatio
CVE-2026-14172 - Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated
CVE-2026-12981 - The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation wh
CVE-2026-12877 - The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not saniti
CVE-2026-12690 - The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license
CVE-2026-12689 - The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership che
CVE-2026-12688 - The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before gra
CVE-2026-12497 - The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C
CVE-2026-16870 - Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allo
CVE-2026-66141 - Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport i
CVE-2026-66140 - Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequ
CVE-2026-66139 - OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is
CVE-2026-66138 - In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can ach
CVE-2026-54422 - In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ir
CVE-2026-6454 - The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in vers
CVE-2026-15420 - The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vuln
CVE-2026-15100 - The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scrip
CVE-2026-13464 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-12736 - The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl
CVE-2026-11922 - A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-l
CVE-2026-11354 - The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in al
CVE-2025-9205 - The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to,
CVE-2026-62825 - Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges ove
CVE-2026-58275 - Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a netw
CVE-2026-56191 - Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp
CVE-2026-56167 - Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privi
CVE-2026-56165 - Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over
CVE-2026-56160 - Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate pri
CVE-2026-54120 - Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a
CVE-2026-50517 - Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over
CVE-2026-49159 - Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized a
CVE-2026-35425 - Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code
CVE-2026-50044 - Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability
CVE-2026-44955 - Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to a
CVE-2026-42933 - Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerabilit
CVE-2026-40430 - Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability
CVE-2026-28698 - Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to a
CVE-2026-16767 - A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extr
CVE-2026-65694 - Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller
CVE-2026-65604 - Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open
CVE-2026-63732 - 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (
CVE-2026-63313 - 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fet
CVE-2026-16807 - Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to
CVE-2026-16806 - Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execu
CVE-2026-16805 - Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execut
CVE-2026-16804 - Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had c
CVE-2026-16765 - A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unk
CVE-2026-16764 - A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSeria
CVE-2026-16763 - A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element
CVE-2025-71389 - Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because
CVE-2024-58355 - Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability
CVE-2024-58354 - cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerabilit
CVE-2024-58353 - Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS
CVE-2026-6924 - A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such,
CVE-2026-52439 - An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.ne
CVE-2026-50103 - A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adja
CVE-2026-50039 - The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to
CVE-2026-50032 - A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network a
CVE-2026-49035 - The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate reques
CVE-2026-47724 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-47723 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-39155 - Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the n
CVE-2026-38764 - An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate priv
CVE-2026-34496 - Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affect
CVE-2026-21655 - Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Contro
CVE-2026-21653 - Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server
CVE-2026-16796 - Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock Agent
CVE-2026-16002 - The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash th
CVE-2026-15981 - The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in a
CVE-2026-15968 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-15967 - Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEi
CVE-2026-15966 - Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Tran
CVE-2026-15630 - A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or mod
CVE-2026-10697 - Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transf
CVE-2026-65706 - FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect vi
CVE-2026-65705 - FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill v
CVE-2026-65704 - FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause he
CVE-2026-65703 - FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video dec
CVE-2026-64785 - SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other
CVE-2026-63359 - The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an
CVE-2026-60122 - gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the
CVE-2026-48013 - Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/exte
CVE-2026-48012 - Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Sh
CVE-2026-47722 - nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v
CVE-2026-47670 - DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated
CVE-2026-47669 - DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` funct
CVE-2026-25800 - Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting
CVE-2026-15212 - The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t
CVE-2026-12353 - An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for R
CVE-2026-65010 - Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extrac
CVE-2026-63765 - Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads control
CVE-2026-16756 - Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the de
CVE-2026-15687 - A security issue was discovered in the Kubernetes Java client library where a compromised pod may be
CVE-2026-6516 - Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code
CVE-2026-65920 - Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _g
CVE-2026-65919 - Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/syst
CVE-2026-65918 - PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vul
CVE-2026-65763 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper valid
CVE-2026-65762 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper
CVE-2026-65702 - Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persi
CVE-2026-65701 - SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability
CVE-2026-65700 - h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that
CVE-2026-65699 - AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability th
CVE-2026-47769 - APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP
CVE-2026-47755 - ITFlow provides an IT documentation, ticketing and accounting system for small managed service provi
CVE-2026-47752 - Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2
CVE-2026-47743 - Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewir
CVE-2026-47668 - DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner
CVE-2026-44210 - Kata Containers is an open source project focusing on a standard implementation of lightweight Virtu
CVE-2026-65761 - Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.
CVE-2026-65760 - Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy
CVE-2026-65759 - Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.
CVE-2026-65698 - Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that a
CVE-2026-65697 - Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics coll
CVE-2026-65696 - Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability
CVE-2026-65695 - Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools
CVE-2026-44909 - Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A re
CVE-2026-16768 - A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exc
CVE-2026-65917 - CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDO
CVE-2026-65916 - CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in
CVE-2026-48539 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights s
CVE-2026-48538 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import
CVE-2026-48537 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive A
CVE-2026-48536 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settin
CVE-2026-48535 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home prox
CVE-2026-48534 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server co
CVE-2026-48533 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-48532 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History R
CVE-2026-48531 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Poli
CVE-2026-48530 - GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification
CVE-2026-16584 - Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 migh
CVE-2026-15617 - Logto performs principal lookup without normalizing email and identifier strings, enabling principal
CVE-2026-15616 - Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass se
CVE-2026-15615 - Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audien
CVE-2026-15614 - Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within
CVE-2026-15612 - Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling repl
CVE-2026-15611 - Logto allows unverified email-based SSO account linking, enabling an attacker to register an identit
CVE-2026-11804 - Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framewo
CVE-2026-43823 - When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-f
CVE-2026-43820 - NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSS
CVE-2026-8287 - Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems
CVE-2026-65914 - DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into
CVE-2026-65913 - DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows
CVE-2026-65912 - DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a
CVE-2026-65911 - In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanit
CVE-2026-65904 - DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element ori
CVE-2026-65903 - DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluatio
CVE-2026-65902 - DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEF
CVE-2026-65901 - DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts a
CVE-2026-65900 - DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a
CVE-2026-65899 - DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is
CVE-2026-65898 - DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an u
CVE-2026-65690 - Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner
CVE-2026-65689 - Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner
CVE-2026-65688 - Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner
CVE-2026-65687 - Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner
CVE-2026-16735 - A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This a
CVE-2026-16733 - A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is
CVE-2026-14257 - brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand()
CVE-2026-65908 - In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executabl
CVE-2026-65907 - In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
CVE-2026-65906 - In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was po
CVE-2026-15037 - Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction se
CVE-2026-65897 - Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::c
CVE-2026-65896 - Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate
CVE-2026-65895 - Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin con
CVE-2026-65608 - Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory
CVE-2026-65607 - SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit bran
CVE-2026-65606 - SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler
CVE-2026-65605 - SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (databas
CVE-2026-65550 - Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65540 - Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 version
CVE-2026-65539 - Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538 - Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537 - Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <=
CVE-2026-65536 - Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی،
CVE-2026-65535 - Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65534 - Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65533 - Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65532 - Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65531 - Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65530 - Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-65529 - Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
CVE-2026-65528 - Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
CVE-2026-65527 - Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65526 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-65525 - Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65524 - Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65522 - Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPre
CVE-2026-65521 - Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-65519 - Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-65518 - Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-65516 - Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65514 - Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65512 - Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activi
CVE-2026-65511 - Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education Wor
CVE-2026-65510 - Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65506 - Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.
CVE-2026-65505 - Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65503 - Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65501 - Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 vers
CVE-2026-65500 - Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPres
CVE-2026-65499 - Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65498 - Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
CVE-2026-65497 - Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
CVE-2026-65496 - Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.
CVE-2026-65495 - Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
CVE-2026-65494 - Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-65493 - Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
CVE-2026-65492 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-65491 - Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65490 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Mic
CVE-2026-65489 - Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-elemen
CVE-2026-65488 - Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor las
CVE-2026-65487 - Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
CVE-2026-65486 - Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65485 - Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65484 - Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
CVE-2026-65483 - Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
CVE-2026-65482 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-65481 - Contributor Local File Inclusion in Vino <= 1.9 versions.
CVE-2026-65480 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-65479 - Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-65478 - Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware