CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-0076 - In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bou
CVE-2026-0075 - In multiple functions, there is a possible way to access the contacts database due to a SQL injectio
CVE-2026-0074 - In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due t
CVE-2026-0070 - In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system c
CVE-2026-0069 - In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource ex
CVE-2026-0067 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent de
CVE-2026-0061 - In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a
CVE-2026-0060 - In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persis
CVE-2026-0059 - In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to
CVE-2026-0056 - In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds che
CVE-2026-0055 - In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Pol
CVE-2026-0052 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to
CVE-2026-0051 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash
CVE-2026-0050 - In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosu
CVE-2026-0048 - In hide of WindowState.java, there is a possible way to trick the user into approving permissions du
CVE-2026-0046 - In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a perm
CVE-2026-0045 - In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connec
CVE-2026-0044 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to
CVE-2026-0043 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
CVE-2026-0042 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
CVE-2026-0041 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an int
CVE-2026-0040 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to
CVE-2026-0039 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
CVE-2026-0036 - In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking
CVE-2026-0018 - In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of
CVE-2026-0016 - In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to ov
CVE-2026-0009 - In multiple locations, there is a possible tapjacking due to a logic error in the code. This could l
CVE-2025-48652 - In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due
CVE-2025-48649 - In multiple locations, there is a possible way to reset user-selected permissions selections due to
CVE-2025-48648 - In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource
CVE-2025-48616 - In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode
CVE-2025-48595 - In multiple locations, there is a possible way to achieve code execution due to an integer overflow.
CVE-2025-48570 - In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from t
CVE-2025-32348 - In multiple locations, there is a possible background activity launch due to a missing permission ch
CVE-2025-26418 - In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass t
CVE-2025-22426 - In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to
CVE-2025-22424 - In multiple locations, there is a possible way to reveal images across users due to improper input v
CVE-2019-25716 - Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerabilit
CVE-2018-25435 - ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform un
CVE-2018-25434 - WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to
CVE-2018-25433 - Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenti
CVE-2018-25432 - Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbit
CVE-2018-25431 - No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege
CVE-2018-25430 - Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execu
CVE-2018-25429 - Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execu
CVE-2018-25428 - Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to exe
CVE-2018-25427 - Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to
CVE-2026-5419 - A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-
CVE-2026-49433 - The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSR
CVE-2026-49140 - Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel medi
CVE-2026-49139 - Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft
CVE-2026-49138 - Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch
CVE-2026-49136 - Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in t
CVE-2026-49135 - CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows loca
CVE-2026-49134 - CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that all
CVE-2026-37234 - FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SET
CVE-2026-24751 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in
CVE-2026-10289 - A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impac
CVE-2026-10288 - A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue
CVE-2026-10287 - A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affe
CVE-2026-10286 - A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file
CVE-2026-10285 - A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this
CVE-2026-10284 - A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerab
CVE-2025-70099 - A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4
CVE-2021-46747 - Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with
CVE-2026-9614 - An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a
CVE-2026-9330 - IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied
CVE-2026-9319 - IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due t
CVE-2026-9311 - IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the b
CVE-2026-8644 - IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-7770 - IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to re
CVE-2026-49121 - AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution v
CVE-2026-47294 - Improper neutralization of special elements used in an os command ('os command injection') in Micros
CVE-2026-45810 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0
CVE-2026-45729 - Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5,
CVE-2026-45727 - CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP mu
CVE-2026-45722 - Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and
CVE-2026-45691 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45690 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45545 - Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8
CVE-2026-45544 - Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0
CVE-2026-45543 - Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2
CVE-2026-45302 - parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. P
CVE-2026-45286 - Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, a
CVE-2026-45285 - Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, a
CVE-2026-45284 - Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4
CVE-2026-45283 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45282 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45281 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45279 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0
CVE-2026-45278 - Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2
CVE-2026-45277 - Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated us
CVE-2026-45275 - Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege esca
CVE-2026-43958 - A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached s
CVE-2026-43625 - CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attacke
CVE-2026-43624 - F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handler
CVE-2026-43623 - microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() f
CVE-2026-41013 - Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows
CVE-2026-40990 - OOM error is possible while attempting to add infinite amount of functions to Function Registry. Af
CVE-2026-40989 - Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Sprin
CVE-2026-37235 - FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's
CVE-2026-37233 - FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality
CVE-2026-37232 - An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PR
CVE-2026-37231 - FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t messa
CVE-2026-37230 - FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id tha
CVE-2026-37229 - FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding
CVE-2026-37228 - FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The fu
CVE-2026-37226 - FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-exis
CVE-2026-30963 - Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hi
CVE-2026-23638 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Referen
CVE-2026-22872 - Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs wi
CVE-2026-10283 - A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of
CVE-2026-10282 - A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the fun
CVE-2026-10281 - A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function
CVE-2026-10280 - A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown
CVE-2026-10279 - A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unkn
CVE-2026-10278 - A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of
CVE-2026-10277 - A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4
CVE-2026-10276 - A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the f
CVE-2026-0072 - In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a mi
CVE-2024-52011 - launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version
CVE-2026-8643 - pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing th
CVE-2026-8501 - Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security a
CVE-2026-46243 - In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace c
CVE-2026-45701 - Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versio
CVE-2026-45267 - Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permis
CVE-2026-45266 - Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and
CVE-2026-45264 - Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15,
CVE-2026-45159 - Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1
CVE-2026-45157 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45156 - Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0
CVE-2026-45155 - Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0
CVE-2026-45154 - Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3
CVE-2026-45153 - Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33
CVE-2026-45132 - CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitH
CVE-2026-45131 - CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitH
CVE-2026-44740 - Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, mult
CVE-2026-44211 - Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 a
CVE-2026-42679 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamu
CVE-2026-42678 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42677 - Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectl
CVE-2026-42676 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42675 - Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configur
CVE-2026-42674 - Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Enc
CVE-2026-42673 - Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity
CVE-2026-42672 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-42671 - Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured A
CVE-2026-38950 - An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted mode
CVE-2026-37227 - FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimp
CVE-2026-37225 - FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEvent
CVE-2026-37224 - FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node.
CVE-2026-37223 - FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validat
CVE-2026-37222 - FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP
CVE-2026-10275 - A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the
CVE-2026-10274 - A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18
CVE-2026-10273 - A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file sr
CVE-2026-10272 - A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a56
CVE-2026-10271 - A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3
CVE-2026-10270 - A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprin
CVE-2026-10269 - A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the fu
CVE-2026-10268 - A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the func
CVE-2026-10118 - A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by
CVE-2022-4991 - Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that ma
CVE-2026-8931 - A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 throu
CVE-2026-48879 - Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue
CVE-2026-48866 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rock
CVE-2026-48865 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-48839 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-48559 - Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability th
CVE-2026-42683 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42682 - Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configure
CVE-2026-42681 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42680 - Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest
CVE-2026-42251 - Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that
CVE-2026-37221 - FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no
CVE-2026-37220 - FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The ne
CVE-2026-10533 - A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not co
CVE-2026-10267 - A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function dofr
CVE-2026-10265 - A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue
CVE-2026-10264 - A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the
CVE-2026-10263 - A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affect
CVE-2026-10262 - A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown fun
CVE-2026-10261 - A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the fi
CVE-2026-10260 - A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown
CVE-2026-10259 - A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is th
CVE-2026-0826 - In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buff
CVE-2025-60495 - A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC
CVE-2025-60486 - A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box befo
CVE-2025-60485 - A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC P
CVE-2025-60483 - A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_pa
CVE-2025-60481 - A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Projec
CVE-2025-55664 - A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4
CVE-2024-40646 - Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos.
CVE-2026-9309 - Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page
CVE-2026-9308 - Firefox for iOS Reader View replaced page content in its HTML template before replacing other intern
CVE-2026-34193 - Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU F
CVE-2026-10532 - Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectI
CVE-2026-10258 - A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown
CVE-2026-10257 - A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affect
CVE-2026-10256 - A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability aff
CVE-2026-10255 - A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected b
CVE-2026-10254 - A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown
CVE-2026-10253 - A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown
CVE-2026-10252 - A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affe
CVE-2026-10251 - A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element
CVE-2026-49328 - Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) f
CVE-2026-25600 - The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. Thi
CVE-2026-25599 - Missing authentication and clear‑text transmission of data from the heat pumps to the control server
CVE-2026-10250 - A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The aff
CVE-2026-10249 - A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is
CVE-2026-10248 - A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This
CVE-2026-10247 - A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerabil
CVE-2026-10246 - A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affec
CVE-2026-10245 - A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this is
CVE-2026-10244 - A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by
CVE-2026-9024 - A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Serv
CVE-2026-8474 - A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8
CVE-2026-7858 - A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 202
CVE-2026-49361 - Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.M
CVE-2026-49298 - A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate a
CVE-2026-49270 - Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache A
CVE-2026-49267 - Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STA
CVE-2026-49157 - Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ:
CVE-2026-48827 - Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upl
CVE-2026-48726 - A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after
CVE-2026-46764 - The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit
CVE-2026-46605 - Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authent
CVE-2026-45505 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
CVE-2026-45426 - Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log
CVE-2026-45360 - Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_r
CVE-2026-44825 - Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr v
CVE-2026-42588 - Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
CVE-2026-42360 - A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g.
CVE-2026-42359 - A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authentic
CVE-2026-42358 - A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-
CVE-2026-42253 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42252 - Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when tr
CVE-2026-41084 - A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_
CVE-2026-41017 - Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deploy
CVE-2026-41014 - The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not p
CVE-2026-40963 - The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Da
CVE-2026-40961 - A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that b
CVE-2026-40861 - A Dag author could either (a) create a symlink under their task's log directory pointing to an arbit
CVE-2026-40549 - SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and dele
CVE-2026-40548 - SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the bac
CVE-2026-40547 - SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is ab
CVE-2026-40546 - SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with lo
CVE-2026-40545 - SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a maliciou
CVE-2026-40544 - SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. A
CVE-2026-40543 - SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker ca
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.