CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
18111 CVEs gefunden (Seite 53/73)

CVE-2026-46328 - In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-46327 - In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_su

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46326 - In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix

🏢 Linux 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-46325 - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conver

🏢 Linux 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-11793 - A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c c

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-11792 - A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the cr

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.3
3.3

CVE-2026-11790 - A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-11789 - A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-11788 - A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocati

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-11787 - A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.0
5.0

CVE-2026-11786 - A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when p

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 1.9
1.9

CVE-2026-11785 - A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handl

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46324 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46323 - In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skb

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46322 - In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb fai

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-46321 - In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame r

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-46320 - In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths i

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-46319 - In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46318 - In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hu

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-46317 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmu

🏢 Linux 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-46316 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the

🏢 Linux 📅 9.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-2638 - A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 thro

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-11764 - When creating an export of all reusable media, the secrets of connected gift cards were included in

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2017-20251 - WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that al

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2017-20250 - Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2017-20249 - Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attack

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20248 - Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attack

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2017-20247 - WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthen

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20246 - KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenti

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20245 - Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthent

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20244 - Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthent

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20243 - WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerab

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2016-20065 - Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unaut

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2016-20064 - WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.2
6.2

CVE-2016-20063 - Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated user

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2016-20062 - Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthent

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-49742 - Backend users with file download permissions were able to download files from the fallback storage o

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-49741 - Backend users with write access to the form_definition database table were able to directly create,

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-49740 - TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-49738 - The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix compa

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47352 - Authenticated backend users were able to retrieve file metadata via several Backend API routes witho

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47351 - Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without prope

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47350 - Backend users were able to move records to a different page without having edit permissions on the s

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47349 - Backend users with access to the Recycler module were able to restore soft-deleted records on pages

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47348 - Editors with access to create or modify page content were able to include HTML markup in page titles

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47347 - Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to op

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47346 - Backend users with file write permissions were able to upload form definition files with mixed-case

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47343 - Non-privileged backend users with file mount access were able to perform write operations (move, del

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-11607 - Backend users with access to the Form Framework were able to use files not ending in .form.yaml as f

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-52902 - A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directiv

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.7
4.7

CVE-2026-4058 - The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registrat

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46749 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected ap

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-46748 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected sy

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-46747 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected ap

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46746 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-41031 - A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Bui

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.7
8.7

CVE-2026-24349 - A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-10731 - SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ fun

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2025-40808 - A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2025-10263 - Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Co

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-8677 - The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8599 - The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for Word

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8365 - The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Executi

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-7542 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in vers

🏢 Aws 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-6899 - Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.6
5.6

CVE-2026-49818 - The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destinat

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-46315 - In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid i

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-34905 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This iss

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-34033 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach

🏢 Apache 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-34031 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-33582 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-28262 - Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Acces

🏢 Dell 📅 9.6.2026 📊 CVSS: 6.0
6.0

CVE-2026-25699 - Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. T

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-25688 - Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-11616 - The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in v

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2009-10007 - Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixatio

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-9698 - DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-5068 - A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host du

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.6
7.6

CVE-2026-44083 - An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagi

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-41986 - Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 2.4
2.4

CVE-2026-41985 - UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.1
5.1

CVE-2026-41984 - UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.2
5.2

CVE-2026-41983 - DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-41982 - Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerabilit

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-41981 - Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnera

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-41977 - DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affe

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.0
5.0

CVE-2026-41976 - Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vul

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.6
6.6

CVE-2026-41974 - Permission control vulnerability in service notifications. Impact: Successful exploitation of this v

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.6
3.6

CVE-2026-41973 - Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41972 - Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability m

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2025-62858 - A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-8981 - The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_h

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 3.5
3.5

CVE-2026-5067 - A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket u

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-4986 - The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal we

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-41539 - A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-11572 - Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command In

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-9662 - The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all v

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-9185 - The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Control

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-8977 - The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8940 - The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8910 - The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-8909 - The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8907 - The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-8904 - The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8902 - The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8895 - The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8883 - The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Script

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8882 - The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8880 - The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8841 - The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8499 - The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-7662 - The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-41980 - Permission control vulnerability in the file preview module. Impact: Successful exploitation of this

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-41979 - Permission control vulnerability in the print module. Impact: Successful exploitation of this vulner

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-41978 - Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulner

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.4
4.4

CVE-2026-41975 - Permission management vulnerability in the network management module. Impact: Successful exploitatio

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-41855 - In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-41854 - Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.2
4.2

CVE-2026-41853 - Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-41852 - A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argu

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-41851 - Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnera

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-41850 - Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerabl

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-41849 - An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-41848 - Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attack

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-41847 - Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.8
4.8

CVE-2026-41846 - Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyl

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41845 - Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-41844 - A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.2
4.2

CVE-2026-41843 - Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static r

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41842 - Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-41841 - Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41840 - Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multip

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41839 - A WebFlux application with a compromised subdomain (for example, compromised via cross-site scriptin

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.2
4.2

CVE-2026-41838 - IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, w

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.8
4.8

CVE-2026-41720 - Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-41715 - In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Ne

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-41710 - An attacker can craft a large number of unique requests that trigger a failure, exhausting the capac

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41007 - Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-41006 - Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JS

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40984 - In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40983 - In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-26236 - A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11623 - A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free o

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-11603 - The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site S

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-10738 - The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Foo

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-10553 - The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-10024 - The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'b

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-7556 - The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-5714 - The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-11621 - A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpl

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.7
4.7

CVE-2026-11620 - A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-11619 - A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-11618 - A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function pr

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-10862 - The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion b

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8795 - A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velocir

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44757 - SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially craft

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.7
4.7

CVE-2026-44755 - SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending par

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-44754 - The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (OD

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.6
6.6

CVE-2026-44751 - Application server ABAP does not perform necessary authorization checks for an authenticated user al

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-44750 - SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for au

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-44748 - SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-44746 - Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-44744 - SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module com

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-44743 - Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business O

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-40128 - SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.0
9.0

CVE-2026-27671 - Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-24315 - SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls o

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.2
4.2

CVE-2026-11701 - Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote

🏢 Google 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-11700 - Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11699 - Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11698 - Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11697 - Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11696 - Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta

🏢 Google 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-11695 - Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote

🏢 Google 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-11694 - Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker w

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11693 - Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote at

🏢 Google 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-11692 - Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker w

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11691 - Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103

🏢 Google 📅 9.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-11690 - Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remo

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11689 - Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remo

🏢 Google 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-11688 - Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attack

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11687 - Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11686 - Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103

🏢 Google 📅 9.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-11685 - Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed

🏢 Google 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-11684 - Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote

🏢 Google 📅 9.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-11683 - Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to ex

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11682 - Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a re

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11681 - Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11680 - Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11679 - Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attack

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11678 - Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha

🏢 Google 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-11677 - Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had co

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11676 - Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 1

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11675 - Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha

🏢 Google 📅 9.6.2026 📊 CVSS: 3.1
3.1

CVE-2026-11674 - Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to e

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11673 - Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11672 - Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote att

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11671 - Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11670 - Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11669 - Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote at

🏢 Google 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-11668 - Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a re

🏢 Google 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-11667 - Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11666 - Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed

🏢 Google 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-11665 - Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta

🏢 Google 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-11664 - Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to pot

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11663 - Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11662 - Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to exe

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11661 - Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11660 - Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11659 - Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker t

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11658 - Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 al

🏢 Google 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-11657 - Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11656 - Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who con

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11655 - Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11654 - Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote att

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11653 - Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote

🏢 Google 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-11652 - Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11651 - Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to exec

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11650 - Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11649 - Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11648 - Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote at

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11647 - Use after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote atta

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11646 - Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11645 - Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11644 - Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who co

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11643 - Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execut

🏢 Google 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-11642 - Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11641 - Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote att

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11640 - Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11639 - Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attac

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11638 - Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to pot

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11637 - Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11636 - Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11635 - Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11634 - Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attac

🏢 Google 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-11633 - Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11632 - Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who co

🏢 Google 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-11631 - Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker

🏢 Google 📅 9.6.2026 📊 CVSS: 8.3
8.3

CVE-2026-11630 - Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11629 - Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potent

🏢 Google 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-11628 - Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potenti

🏢 Google 📅 9.6.2026 📊 CVSS: 6.8
6.8

CVE-2026-9669 - bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught th

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-44541 - Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5,

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-40215 - A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attacker

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-11585 - A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-49141 - WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-47345 - Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47344 - When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-46484 - Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Head

🏢 Sonstige 📅 8.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-40519 - Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticate

🏢 Nginx 📅 8.6.2026 📊 CVSS: 7.5
7.5
«« « Zurück Seite 53 von 73 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.