CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-46983 - Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component:
CVE-2026-46982 - Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component:
CVE-2026-46981 - Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applicat
CVE-2026-46980 - Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applicat
CVE-2026-46975 - Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affecte
CVE-2026-46968 - Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle
CVE-2026-46954 - Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Remo
CVE-2026-46948 - Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applicat
CVE-2026-46943 - Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Pl
CVE-2026-46941 - Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Main
CVE-2026-46936 - Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: DDL).
CVE-2026-46924 - Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.
CVE-2026-46923 - Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Su
CVE-2026-46917 - Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ
CVE-2026-46876 - Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.
CVE-2026-43947 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unaut
CVE-2026-43946 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an autho
CVE-2026-43945 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.
CVE-2026-35290 - Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.
CVE-2026-35287 - Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.
CVE-2026-34316 - Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce
CVE-2026-21954 - Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (co
CVE-2026-21953 - Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (co
CVE-2026-16484 - A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vuln
CVE-2026-10680 - The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/
CVE-2026-10679 - The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock
CVE-2026-10678 - The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes
CVE-2026-10677 - The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy
CVE-2026-10675 - In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_rec
CVE-2026-10674 - The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFI
CVE-2026-8983 - Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that
CVE-2026-8982 - Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. T
CVE-2026-65058 - Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign
CVE-2026-65057 - Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticat
CVE-2026-65056 - mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to
CVE-2026-65055 - Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to
CVE-2026-65054 - MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to e
CVE-2026-64881 - The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow int
CVE-2026-64822 - djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPassword
CVE-2026-64821 - djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that al
CVE-2026-63764 - LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vuln
CVE-2026-63358 - FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the
CVE-2026-63140 - Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipula
CVE-2026-63139 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Al
CVE-2026-63136 - Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exces
CVE-2026-63092 - kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerabili
CVE-2026-63080 - Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backe
CVE-2026-56147 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized inform
CVE-2026-52476 - SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive informa
CVE-2026-52475 - Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive
CVE-2026-52474 - An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUti
CVE-2026-52472 - SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the
CVE-2026-52470 - SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via t
CVE-2026-52469 - SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via t
CVE-2026-47714 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline
CVE-2026-47708 - MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3,
CVE-2026-47697 - Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organi
CVE-2026-47695 - CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game.
CVE-2026-47690 - MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions o
CVE-2026-47689 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47688 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47687 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47685 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47237 - Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clust
CVE-2026-47143 - Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer de
CVE-2026-46556 - FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.
CVE-2026-45383 - libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a
CVE-2026-45382 - libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decode
CVE-2026-44879 - A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authe
CVE-2026-44878 - A vulnerability in the web-based management interface of an ECOS device could allow a highly privile
CVE-2026-30633 - Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc
CVE-2026-30631 - An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11
CVE-2026-16318 - The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n
CVE-2026-16317 - Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an
CVE-2026-12139 - Tanium addressed an information disclosure vulnerability in Connect.
CVE-2026-11925 - Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Ta
CVE-2026-65069 - Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file an
CVE-2026-65068 - Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file an
CVE-2026-65067 - Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and ope
CVE-2026-65066 - Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and
CVE-2026-65065 - Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file
CVE-2026-65064 - Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and op
CVE-2026-65063 - Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and
CVE-2026-65062 - Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and
CVE-2026-65061 - Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and ope
CVE-2026-64880 - Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL que
CVE-2026-64879 - A filename supplied during file upload is not properly sanitized before being used in system command
CVE-2026-64878 - Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument
CVE-2026-64617 - Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and ope
CVE-2026-64616 - Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and op
CVE-2026-64615 - Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open
CVE-2026-64614 - Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open
CVE-2026-64613 - Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and ope
CVE-2026-59147 - Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an
CVE-2026-59146 - Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unv
CVE-2026-59145 - Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot,
CVE-2026-59144 - Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalida
CVE-2026-59143 - Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalid
CVE-2026-56852 - A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
CVE-2026-56146 - Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytic
CVE-2026-56145 - Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exces
CVE-2026-56144 - Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited inde
CVE-2026-50759 - An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /stat
CVE-2026-50758 - Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to
CVE-2026-50757 - Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to e
CVE-2026-50756 - An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat
CVE-2026-50755 - An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat
CVE-2026-49092 - Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized in
CVE-2026-47671 - Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0,
CVE-2026-47667 - CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the
CVE-2026-46600 - Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the messa
CVE-2026-46403 - Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `
CVE-2026-42397 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-30632 - Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the c
CVE-2026-15957 - Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers fr
CVE-2026-64877 - An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access
CVE-2026-63454 - An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln
CVE-2026-63453 - Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitati
CVE-2026-59142 - Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated a
CVE-2026-59141 - Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated no
CVE-2026-59140 - Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated no
CVE-2026-59139 - Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated ar
CVE-2026-55084 - DHIS2 is a flexible information system for data capture, management, validation, analytics and visua
CVE-2026-55082 - DHIS2 is a flexible information system for data capture, management, validation, analytics and visua
CVE-2026-55081 - DHIS2 is a flexible information system for data capture, management, validation, analytics and visua
CVE-2026-16441 - In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superc
CVE-2026-12548 - A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an intege
CVE-2026-12547 - SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority
CVE-2016-20096 - Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnera
CVE-2026-56583 - HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthoriz
CVE-2026-56582 - HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerab
CVE-2026-56581 - HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorize
CVE-2026-56580 - HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow a
CVE-2026-56579 - HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misu
CVE-2026-56578 - HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit kn
CVE-2026-56577 - HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise t
CVE-2026-47657 - HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing aut
CVE-2026-47425 - Rattler is a library that provides common functionality used within the conda ecosystem. Prior to ve
CVE-2026-47419 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47418 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47417 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47416 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47415 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47414 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47413 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47412 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47411 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-44880 - A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploi
CVE-2026-21579 - This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8
CVE-2026-21577 - This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.
CVE-2026-21575 - This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sou
CVE-2026-16493 - A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's conc
CVE-2026-16439 - In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer un
CVE-2026-16243 - In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if t
CVE-2026-47410 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47409 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47408 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47407 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to versio
CVE-2026-47406 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47405 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47399 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to versio
CVE-2026-47398 - PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-443
CVE-2026-47397 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage cause
CVE-2026-44907 - A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to s
CVE-2026-24232 - NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserializati
CVE-2026-16454 - In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862
CVE-2026-16451 - A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a
CVE-2026-15829 - A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt
CVE-2026-15793 - BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true whe
CVE-2026-15792 - A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon cra
CVE-2026-15791 - A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp
CVE-2026-15789 - A custom client can produce such an upload request to the BuildKit daemon that files can escape from
CVE-2026-15724 - In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated
CVE-2026-15432 - When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non
CVE-2026-15342 - Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticat
CVE-2025-68640 - The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET
CVE-2026-64825 - Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthentica
CVE-2026-64824 - Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore fu
CVE-2026-64823 - Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly inte
CVE-2026-56586 - HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform
CVE-2026-56585 - HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attacker
CVE-2026-47396 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a
CVE-2026-47395 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers
CVE-2026-47394 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw /
CVE-2026-47393 - PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that Praison
CVE-2026-47392 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers
CVE-2026-47391 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server
CVE-2026-47390 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers
CVE-2026-28321 - SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary fi
CVE-2026-28317 - SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
CVE-2026-28316 - SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
CVE-2026-28315 - SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could
CVE-2026-28314 - SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an
CVE-2026-28313 - SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
CVE-2026-28312 - SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s
CVE-2026-28310 - SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administr
CVE-2026-28309 - SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administ
CVE-2026-28308 - SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
CVE-2026-28307 - SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user grou
CVE-2026-28306 - SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administr
CVE-2026-28305 - SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
CVE-2026-28304 - SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can all
CVE-2026-28302 - SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
CVE-2026-16450 - A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cea
CVE-2026-16449 - A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cea
CVE-2026-8933 - A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component
CVE-2026-65052 - Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerab
CVE-2026-65051 - Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side securi
CVE-2026-65050 - Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability
CVE-2026-65049 - Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorizat
CVE-2026-65048 - Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored c
CVE-2026-59851 - A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does no
CVE-2026-59850 - A flaw was found in libssh. If data packets are processed after a channel is closed, channel data ca
CVE-2026-59849 - A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication ca
CVE-2026-56587 - HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform
CVE-2026-56584 - HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identi
CVE-2026-47122 - Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate
CVE-2026-46681 - @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.
CVE-2026-16448 - A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-3
CVE-2026-15226 - A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution e
CVE-2026-11876 - In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_s
CVE-2024-5300 - An access control bypass and information disclosure vulnerability exists in the base AppArmor securi
CVE-2026-9499 - An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. W
CVE-2026-59848 - A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that
CVE-2026-59847 - A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backen
CVE-2026-47121 - Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaA
CVE-2026-16447 - A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file
CVE-2025-66390 - In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Ba
CVE-2026-8285 - Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. F
CVE-2026-8284 - URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCit
CVE-2026-6792 - Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectl
CVE-2026-59846 - A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can in
CVE-2026-16445 - A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability
CVE-2026-16412 - Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence
CVE-2026-16411 - Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption a
CVE-2026-16410 - JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
CVE-2026-16409 - Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thun
CVE-2026-16408 - Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153
CVE-2026-16407 - Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153
CVE-2026-16406 - Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thund
CVE-2026-16405 - Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Fire
CVE-2026-16404 - Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
CVE-2026-16403 - Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunder
CVE-2026-16402 - Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 an
CVE-2026-16401 - Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox
CVE-2026-16400 - Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 a
CVE-2026-16399 - Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a
CVE-2026-16398 - Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thun
CVE-2026-16397 - Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fix
CVE-2026-16396 - Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware