CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-57385 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-57383 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57382 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57381 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57380 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57379 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57378 - Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting In
CVE-2026-57377 - Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly
CVE-2026-57376 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57375 - Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrect
CVE-2026-57372 - Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server S
CVE-2026-57371 - Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object In
CVE-2026-57369 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57368 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57365 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-57364 - Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Ins
CVE-2026-57363 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-49876 - Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and
CVE-2026-41041 - URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This
CVE-2026-22103 - The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22102 - A POST request sent to a specific webserver endpoint can be used to write to arbitrary file location
CVE-2026-22100 - The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the
CVE-2026-22099 - The charging station does not require authentication for Bluetooth commands to perform actions. The
CVE-2026-22098 - Various sensitive information such as passwords and charging card UIDs are written to log files.
CVE-2026-22097 - The firmware update mechanism does not include cryptographic signature validation. This allows anyon
CVE-2026-22096 - The webserver running on port 8090 does not require authentication. This allows for sensitive inform
CVE-2026-22095 - The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22093 - The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the ce
CVE-2026-15557 - A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the
CVE-2026-15548 - A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affe
CVE-2026-14846 - In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of e
CVE-2026-13014 - A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated
CVE-2026-9708 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an
CVE-2026-9597 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is dea
CVE-2026-9571 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth
CVE-2026-6850 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the len
CVE-2026-62143 - A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion mod
CVE-2026-15574 - A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all
CVE-2026-15547 - A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048
CVE-2026-15546 - A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the
CVE-2026-15545 - A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is t
CVE-2026-14453 - This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-t
CVE-2026-10106 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the
CVE-2026-10103 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post owne
CVE-2026-10085 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the gro
CVE-2026-57830 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.
CVE-2026-57829 - Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Jooml
CVE-2026-4769 - Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability durin
CVE-2026-15544 - A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar
CVE-2026-15543 - A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the f
CVE-2026-15542 - A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of
CVE-2026-15541 - A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.
CVE-2026-15540 - A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is
CVE-2026-14165 - An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Editio
CVE-2026-15539 - A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted
CVE-2026-15538 - A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the functio
CVE-2026-15537 - A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerabili
CVE-2026-15536 - A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unkno
CVE-2026-12582 - The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supp
CVE-2026-12397 - The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employe
CVE-2026-12396 - The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks bef
CVE-2026-12275 - The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integrat
CVE-2026-12274 - The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to
CVE-2026-12273 - The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target vali
CVE-2026-12271 - The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt
CVE-2026-12081 - The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not res
CVE-2026-11964 - The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity o
CVE-2026-11963 - The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization
CVE-2026-10551 - The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Sc
CVE-2026-15535 - A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99.
CVE-2026-15533 - A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file
CVE-2026-15532 - A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects so
CVE-2026-15531 - A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b
CVE-2026-15530 - A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config
CVE-2026-9492 - The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYT
CVE-2026-7162 - Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve sys
CVE-2026-15553 - Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing una
CVE-2026-15552 - Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowi
CVE-2026-15529 - A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persi
CVE-2026-15528 - A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown proc
CVE-2026-15527 - A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects u
CVE-2026-15526 - A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProje
CVE-2026-15525 - A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _v
CVE-2026-15524 - A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects
CVE-2026-15523 - A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by t
CVE-2026-15522 - A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerabili
CVE-2026-15521 - A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown
CVE-2026-15520 - A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decom
CVE-2026-15519 - A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the fil
CVE-2026-15551 - Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
CVE-2026-15518 - A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the functio
CVE-2026-15517 - A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/
CVE-2026-15516 - A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of t
CVE-2026-15515 - A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects
CVE-2026-15514 - A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affec
CVE-2026-15513 - A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uc
CVE-2026-15512 - A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown f
CVE-2026-15511 - A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerabilit
CVE-2026-15510 - A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of
CVE-2026-15509 - A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser o
CVE-2026-15508 - A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_ta
CVE-2026-15507 - A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown f
CVE-2026-15506 - A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected elemen
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware