CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-65477 - Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-65476 - Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
CVE-2026-65475 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-65474 - Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
CVE-2026-65473 - Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
CVE-2026-65472 - Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
CVE-2026-65471 - Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
CVE-2026-65470 - Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
CVE-2026-65469 - Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
CVE-2026-65468 - Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
CVE-2026-65467 - Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
CVE-2026-65466 - Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
CVE-2026-65465 - Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
CVE-2026-65464 - Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
CVE-2026-65463 - Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
CVE-2026-65462 - Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
CVE-2026-65461 - Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
CVE-2026-65460 - Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
CVE-2026-65458 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby P
CVE-2026-65457 - Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
CVE-2026-65456 - Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 ve
CVE-2026-65455 - Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-65454 - Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
CVE-2026-65453 - Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65452 - Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65451 - Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65450 - Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-65449 - Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
CVE-2026-64815 - In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form
CVE-2026-64814 - In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Developme
CVE-2026-64813 - In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote
CVE-2026-64812 - In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Devel
CVE-2026-64811 - In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting proje
CVE-2026-64810 - In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowin
CVE-2026-64809 - In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project tr
CVE-2026-64808 - In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project tr
CVE-2026-64807 - In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied lin
CVE-2026-64806 - In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project tr
CVE-2026-64805 - In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project tr
CVE-2026-64804 - In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project tr
CVE-2026-64803 - In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trus
CVE-2026-64802 - In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trus
CVE-2026-64800 - In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
CVE-2026-61981 - Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
CVE-2026-61973 - Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61972 - Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
CVE-2026-61954 - Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVE-2026-61951 - Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-61950 - Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
CVE-2026-61949 - Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61948 - Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-61947 - Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versi
CVE-2026-61946 - Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
CVE-2026-61945 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVen
CVE-2026-61944 - Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
CVE-2026-61943 - Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-59555 - Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVE-2026-59554 - Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-59547 - Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions
CVE-2026-59545 - Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-59544 - Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVE-2026-59543 - Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVE-2026-59542 - Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVE-2026-59541 - Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVE-2026-59540 - Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVE-2026-59526 - Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59525 - Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-59524 - Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
CVE-2026-59522 - Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-59517 - Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-59514 - Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-59513 - Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
CVE-2026-59512 - Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
CVE-2026-57809 - Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
CVE-2026-57808 - Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
CVE-2026-57785 - Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
CVE-2026-57784 - Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 v
CVE-2026-57769 - Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
CVE-2026-57767 - Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CVE-2026-57735 - Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
CVE-2026-57717 - Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
CVE-2026-57716 - Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
CVE-2026-57704 - Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
CVE-2026-57703 - Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
CVE-2026-57701 - Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
CVE-2026-57699 - Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
CVE-2026-57696 - Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
CVE-2026-57626 - Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This
CVE-2026-57428 - Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
CVE-2026-57427 - Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
CVE-2026-57425 - Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
CVE-2026-57397 - Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
CVE-2026-57384 - Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
CVE-2026-57374 - Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-57373 - Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.
CVE-2026-57370 - Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 ver
CVE-2026-57367 - Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
CVE-2026-27423 - Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
CVE-2026-27422 - Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Co
CVE-2026-27418 - Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
CVE-2026-27403 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-27399 - Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
CVE-2026-27392 - Contributor Broken Access Control in uListing <= 2.2.0 versions.
CVE-2026-27391 - Subscriber Broken Access Control in uListing <= 2.2.0 versions.
CVE-2026-27377 - Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.
CVE-2026-27372 - Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-27355 - Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
CVE-2026-27064 - Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-25466 - Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
CVE-2026-25427 - Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
CVE-2026-25424 - Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
CVE-2026-25405 - Contributor SQL Injection in eRoom <= 1.7.1 versions.
CVE-2026-24639 - Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVE-2026-24628 - Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
CVE-2026-24552 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-24537 - Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions
CVE-2025-68081 - Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2026-64611 - A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite l
CVE-2026-16745 - A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to
CVE-2026-65758 - Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The
CVE-2026-65757 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules An
CVE-2026-65756 - Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configura
CVE-2026-65755 - Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Use
CVE-2026-65754 - Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer
CVE-2026-65713 - Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery
CVE-2026-65712 - Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN ve
CVE-2026-65431 - Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives ha
CVE-2026-65430 - Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credent
CVE-2026-64876 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP ext
CVE-2026-64875 - Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups tr
CVE-2026-64874 - Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN creden
CVE-2026-64873 - Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could a
CVE-2026-64872 - Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge an
CVE-2026-64871 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Clea
CVE-2026-64799 - Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users
CVE-2026-16078 - The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directo
CVE-2026-15906 - The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic
CVE-2026-15827 - The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missi
CVE-2026-15794 - The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-15786 - The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugi
CVE-2026-15761 - The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injecti
CVE-2026-15647 - The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br
CVE-2026-15646 - The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'st
CVE-2026-15448 - The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injecti
CVE-2026-15404 - The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in ver
CVE-2026-15394 - The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulner
CVE-2026-15348 - The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authenti
CVE-2026-15017 - The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions
CVE-2026-15015 - The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypa
CVE-2026-15011 - The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection v
CVE-2026-14481 - The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for Wo
CVE-2026-14282 - The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Video
CVE-2026-13119 - The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JS
CVE-2026-13009 - The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via '
CVE-2026-52688 - RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52686 - The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are acc
CVE-2026-52684 - If the auth responds very slowly and the records expire in between, the capping of TTLs is not enfor
CVE-2026-16723 - A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerabi
CVE-2026-16287 - Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi
CVE-2024-58330 - A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthentic
CVE-2024-58023 - Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to acc
CVE-2026-9729 - The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
CVE-2026-9713 - The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via
CVE-2026-9635 - The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
CVE-2026-59678 - An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and
CVE-2026-59677 - A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is ru
CVE-2026-12421 - The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field V
CVE-2026-9577 - The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL
CVE-2026-9066 - The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter th
CVE-2026-59676 - A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycore
CVE-2026-14291 - The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication f
CVE-2026-12082 - The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of
CVE-2026-7534 - The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scrip
CVE-2026-7232 - The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter
CVE-2026-64600 - In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork map
CVE-2026-63226 - Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrict
CVE-2026-6390 - A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files
CVE-2026-7120 - @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate pat
CVE-2026-15074 - @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request
CVE-2026-21723 - The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) ca
CVE-2026-16653 - A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function ht
CVE-2026-16632 - A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_proto
CVE-2026-16631 - A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of
CVE-2026-61246 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60455 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60439 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60373 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60372 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60371 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60370 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60369 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60368 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60367 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-60366 - Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen
CVE-2026-38766 - An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate priv
CVE-2026-38765 - An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate priv
CVE-2026-38763 - An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denia
CVE-2026-16630 - A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. Th
CVE-2026-16629 - A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git
CVE-2026-16628 - A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function
CVE-2026-64798 - Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL
CVE-2026-64797 - Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trus
CVE-2026-64796 - Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free di
CVE-2026-64795 - Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs exte
CVE-2026-64794 - Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles An
CVE-2026-64793 - Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and
CVE-2026-64792 - Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Re
CVE-2026-64791 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La
CVE-2026-63685 - Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator r
CVE-2026-63684 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various ad
CVE-2026-63683 - Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions man
CVE-2026-63281 - Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored c
CVE-2026-63280 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La
CVE-2026-63265 - Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Re
CVE-2026-13089 - OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token
CVE-2025-60835 - An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330 - An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate pr
CVE-2025-50329 - An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate
CVE-2025-50327 - An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privile
CVE-2025-50325 - BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remo
CVE-2025-50324 - An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary co
CVE-2025-44090 - An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and
CVE-2025-44089 - An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloadin
CVE-2026-9737 - During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t exp
CVE-2026-64829 - Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers wi
CVE-2026-14899 - The code to parse MIME headers for display when forwarding a message (if the setting to view all hea
CVE-2026-14881 - When importing connections in Compass it is possible to override some connection options that are ot
CVE-2026-13078 - A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine uncond
CVE-2026-13077 - A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out
CVE-2026-13076 - An authenticated user can cause a {{mongod}} process to be terminated by the operating system under
CVE-2026-13075 - An authenticated user can cause the mongod process to be terminated by the operating system under me
CVE-2026-13074 - An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending
CVE-2026-13073 - An authenticated user with read-only privileges can cause the mongod process to terminate abnormally
CVE-2026-13072 - When compute mode is enabled on a standalone mongod instance, insufficient validation of externally
CVE-2026-13071 - An authenticated user with read access can cause the mongod process to be terminated through certain
CVE-2026-13070 - A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a ma
CVE-2026-13069 - An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB s
CVE-2026-13068 - An authenticated user holding cursor termination privileges on one database may incorrectly be permi
CVE-2026-13067 - When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certi
CVE-2026-13066 - Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript
CVE-2026-13065 - A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill wind
CVE-2026-13064 - Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate
CVE-2026-13063 - An authenticated user with standard read/write privileges can cause the mongod process to terminate
CVE-2026-13062 - An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able
CVE-2026-13061 - An authenticated user may be able to view session metadata belonging to other users on the system th
CVE-2026-13060 - An authenticated user with limited read privileges may be able to access documents from collections
CVE-2026-13059 - An authenticated user with low privileges may be able to perform unauthorized reads and writes on da
CVE-2026-13058 - An authenticated user with basic write privileges can cause the mongod process to terminate abnormal
CVE-2026-13057 - An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user ac
CVE-2026-13056 - Using expressions that generate large arrays it is possible to craft a query that creates very large
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware