CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-76609 - Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - Th
CVE-2026-76608 - Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fab
CVE-2026-76607 - Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
CVE-2026-76606 - Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
CVE-2026-76605 - Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
CVE-2026-76604 - Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabr
CVE-2026-76603 - Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7
CVE-2026-76602 - Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The
CVE-2026-76601 - Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugi
CVE-2026-76600 - Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The De
CVE-2026-76599 - Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in
CVE-2026-76598 - Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders
CVE-2026-76597 - Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email p
CVE-2026-76596 - Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.
CVE-2026-76571 - Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter i
CVE-2026-74584 - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page
CVE-2026-70626 - NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows
CVE-2026-6258 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-68768 - hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function
CVE-2026-68767 - hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's
CVE-2026-68766 - hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inj
CVE-2026-66393 - NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_
CVE-2026-65915 - NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox va
CVE-2026-63312 - NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView tha
CVE-2026-63311 - NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulner
CVE-2026-63310 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62388 - NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation
CVE-2026-62385 - NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPC
CVE-2026-62384 - NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allo
CVE-2026-62383 - nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpu
CVE-2026-75870 - Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a
CVE-2026-75866 - Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registere
CVE-2026-71514 - NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lan
CVE-2026-71513 - NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validat
CVE-2026-68769 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-5093 - The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorize
CVE-2026-4561 - The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-4559 - The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scr
CVE-2026-2996 - The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to I
CVE-2026-62382 - PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in t
CVE-2026-62381 - luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1
CVE-2026-62380 - Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.1
CVE-2026-62243 - Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4
CVE-2026-62204 - SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package conte
CVE-2026-60084 - SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/re
CVE-2026-60083 - SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails t
CVE-2026-59809 - SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http
CVE-2026-59808 - AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEn
CVE-2026-59256 - WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken()
CVE-2026-58003 - WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the relea
CVE-2026-58002 - WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass
CVE-2026-58001 - WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/v
CVE-2026-57998 - better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by inte
CVE-2026-57944 - AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGalle
CVE-2026-56380 - AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that
CVE-2026-4244 - The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a
CVE-2026-11948 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11947 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77988 - A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the func
CVE-2026-66917 - Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, pr
CVE-2026-66916 - Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in Jo
CVE-2026-4245 - The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to
CVE-2026-3424 - The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to a
CVE-2026-77946 - A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is t
CVE-2026-77945 - A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the f
CVE-2026-78003 - The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) v
CVE-2026-12710 - A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration
CVE-2026-77002 - The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verificat
CVE-2026-77001 - The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does no
CVE-2026-77000 - The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was act
CVE-2026-76793 - The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an a
CVE-2026-76789 - The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authori
CVE-2026-19222 - The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restri
CVE-2026-19221 - The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to n
CVE-2026-19093 - The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to
CVE-2026-18052 - The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the
CVE-2026-16738 - The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incomi
CVE-2026-16612 - The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected prod
CVE-2026-16260 - The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escap
CVE-2026-14187 - The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its cou
CVE-2026-76074 - The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPr
CVE-2026-76057 - The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPr
CVE-2026-75027 - The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to
CVE-2026-19883 - The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of da
CVE-2026-77781 - Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys.
CVE-2026-9052 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76069 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73323 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53541 - OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumen
CVE-2026-53525 - WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0,
CVE-2026-53524 - WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0,
CVE-2026-53499 - FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces
CVE-2026-49360 - Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.
CVE-2026-48106 - Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterpr
CVE-2026-48105 - Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterpr
CVE-2026-48050 - Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go
CVE-2026-47735 - Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-
CVE-2026-34949 - Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could
CVE-2026-34948 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the
CVE-2026-11805 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11615 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11609 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11418 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53531 - RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s
CVE-2026-53530 - RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the publ
CVE-2026-53529 - LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API coul
CVE-2026-53528 - LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in
CVE-2026-53527 - LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerabil
CVE-2026-53509 - CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060
CVE-2026-53497 - CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is ac
CVE-2026-53487 - Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can
CVE-2026-53468 - Typemill is a flat-file, Markdown-based content management system designed for informational documen
CVE-2026-49849 - xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xSho
CVE-2026-43980 - Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a8
CVE-2026-34836 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in a
CVE-2026-34741 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows
CVE-2026-33333 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive informati
CVE-2026-33240 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-
CVE-2026-33047 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a
CVE-2026-31936 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthor
CVE-2026-77811 - Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a r
CVE-2026-77415 - JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expre
CVE-2026-77414 - JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js en
CVE-2026-77413 - JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js
CVE-2026-77354 - kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.s
CVE-2026-77220 - PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting fun
CVE-2026-77219 - GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an
CVE-2026-76905 - kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.co
CVE-2026-76904 - GeoTools is an open source Java library that provides tools for geospatial data. Starting in version
CVE-2026-69238 - There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allo
CVE-2026-69237 - There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allo
CVE-2026-69236 - There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that
CVE-2026-69235 - There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that
CVE-2026-69234 - There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and
CVE-2026-69233 - There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that
CVE-2026-69232 - There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that
CVE-2026-69231 - There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that
CVE-2026-69230 - There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that
CVE-2026-69229 - There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allo
CVE-2026-69228 - There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior th
CVE-2026-69225 - There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.
CVE-2026-69224 - There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier
CVE-2026-68508 - Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.ins
CVE-2026-67619 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-64679 - Atlantis is a self-hosted golang application that listens for Terraform pull request events via webh
CVE-2026-63421 - Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packag
CVE-2026-63135 - YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS
CVE-2026-62316 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t
CVE-2026-62283 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezh
CVE-2026-61824 - Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt a
CVE-2026-61539 - Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and
CVE-2026-59989 - Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in pha
CVE-2026-55185 - Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go a
CVE-2026-55168 - Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links
CVE-2026-54457 - TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation,
CVE-2026-53656 - FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior t
CVE-2026-53572 - KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgres
CVE-2026-50538 - LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15
CVE-2026-45271 - Picotls is a TLS protocol library that allows users select different crypto backends based on their
CVE-2026-45099 - Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu o
CVE-2026-44517 - Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDir
CVE-2026-31880 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-S
CVE-2026-31803 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected
CVE-2026-30890 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-S
CVE-2026-30865 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-S
CVE-2026-30826 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-S
CVE-2026-77810 - In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain ac
CVE-2026-76876 - Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated at
CVE-2026-74252 - Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.
CVE-2026-67362 - Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-
CVE-2026-67361 - Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in
CVE-2026-67360 - Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-
CVE-2026-67359 - Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1
CVE-2026-67358 - Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.2
CVE-2026-62960 - Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server
CVE-2026-50290 - SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value
CVE-2026-50288 - SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new
CVE-2026-30866 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can ac
CVE-2026-30819 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-S
CVE-2026-27490 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are acces
CVE-2026-27463 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of
CVE-2026-27462 - Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different respo
CVE-2026-77795 - A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the functio
CVE-2026-63466 - Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.forma
CVE-2026-63462 - Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared
CVE-2026-63004 - Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon a
CVE-2026-56875 - Rejected reason: reserved but not needed
CVE-2026-55850 - Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage
CVE-2026-54682 - DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with
CVE-2026-54681 - DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method i
CVE-2026-54134 - OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc
CVE-2026-54073 - VeraCrypt provides disk encryption with strong security based on TrueCrypt. From 1.26.6 until 1.26.2
CVE-2026-54071 - BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/
CVE-2026-53762 - VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-de
CVE-2026-35163 - OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc
CVE-2026-77237 - Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might all
CVE-2026-77236 - Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might
CVE-2026-77235 - Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.
CVE-2026-77234 - Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-e
CVE-2026-71862 - Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime,
CVE-2026-71494 - Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10
CVE-2026-71493 - Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10
CVE-2026-70656 - Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime,
CVE-2026-62677 - Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prio
CVE-2026-62676 - Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prio
CVE-2026-62675 - Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prio
CVE-2026-62674 - Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prio
CVE-2026-55241 - Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime,
CVE-2026-41451 - UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerabilit
CVE-2026-41450 - UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerabilit
CVE-2026-41449 - UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerabilit
CVE-2026-27875 - Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incid
CVE-2026-17252 - A stack-based out-of-bounds write vulnerability exists in the login request handling functionality o
CVE-2026-17251 - A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6
CVE-2026-17250 - A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400
CVE-2026-9324 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9321 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9244 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9012 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-74583 - In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastm
CVE-2026-74582 - In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_hea
CVE-2026-74581 - In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib
CVE-2026-74580 - In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata
CVE-2026-69701 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-69099 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-63726 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-57835 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53991 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53974 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-39909 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11938 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11902 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11830 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11427 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-7344 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-7336 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-7310 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-4482 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-4476 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-4475 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25725 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25715 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2017-20232 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-75933 - Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and s
CVE-2026-75932 - Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom doma
CVE-2026-75928 - The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes
CVE-2026-69502 - Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate
CVE-2026-54789 - mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x H
CVE-2026-49114 - In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the
CVE-2026-22681 - OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticat
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware