CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-3012 - A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto
CVE-2026-2288 - The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_titl
CVE-2026-2280 - The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings
CVE-2025-0898 - The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all
CVE-2026-8054 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish
CVE-2026-49002 - Access control failure means that an application does not effectively check user access permissions,
CVE-2026-48968 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-48877 - Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retriev
CVE-2026-40852 - A highly authenticated attacker can alter the config generator injecting a payload into future creat
CVE-2026-40851 - A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an
CVE-2026-40850 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40849 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40848 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40847 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40846 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40845 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40844 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40843 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40842 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40841 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40840 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40839 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40838 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40837 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40836 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40835 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40834 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40833 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40832 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40831 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40830 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40829 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40828 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40827 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-2237 - A use of get request method with sensitive query strings vulnerability in volume encryption of Synol
CVE-2025-66593 - An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users
CVE-2025-66592 - An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4
CVE-2025-52747 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2025-30028 - A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary
CVE-2025-22741 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2025-14713 - An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in
CVE-2025-13593 - Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local
CVE-2025-13392 - Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Ma
CVE-2025-13167 - Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability i
CVE-2025-12686 - Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter
CVE-2025-10466 - Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability i
CVE-2024-47272 - Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station be
CVE-2024-47271 - Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance S
CVE-2024-47270 - Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surve
CVE-2024-47269 - Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synolog
CVE-2024-47268 - Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before
CVE-2024-47267 - Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Arch
CVE-2024-11399 - Files or directories accessible to external parties vulnerability in redis-server component in Synol
CVE-2023-52945 - Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for des
CVE-2026-8942 - The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver
CVE-2026-8906 - The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up
CVE-2026-8832 - The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for W
CVE-2026-8143 - The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso'
CVE-2026-8042 - The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo
CVE-2026-7618 - The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based bl
CVE-2026-6169 - The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up
CVE-2026-49001 - Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated
CVE-2026-41704 - AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (l
CVE-2026-41009 - When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is con
CVE-2026-40826 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40825 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40824 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40823 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40822 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40821 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40819 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40818 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40817 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40816 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40815 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40814 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40813 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40812 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40811 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-40810 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the
CVE-2026-3897 - The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scrip
CVE-2026-3896 - The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
CVE-2026-3895 - The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-3375 - The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-js
CVE-2026-3279 - The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of
CVE-2026-3001 - The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' para
CVE-2026-2030 - The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2025-41670 - A local user with low privileges may be able to influence the behavior of a privileged system servic
CVE-2025-41669 - The Web-based Management allows a remote low privileged Engineer user to install additional APPs on
CVE-2026-9200 - The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to
CVE-2026-9014 - The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a mis
CVE-2026-8994 - The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up t
CVE-2026-8943 - The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
CVE-2026-8941 - The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up
CVE-2026-8939 - The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in version
CVE-2026-8938 - The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
CVE-2026-8911 - The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up
CVE-2026-8903 - The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site R
CVE-2026-8899 - The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbn
CVE-2026-8898 - The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-ev
CVE-2026-8897 - The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode
CVE-2026-8894 - The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `
CVE-2026-8891 - The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitf
CVE-2026-8887 - The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'list
CVE-2026-8886 - The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-pl
CVE-2026-8884 - The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
CVE-2026-8877 - The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-8875 - The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-8873 - The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcod
CVE-2026-8872 - The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p
CVE-2026-8871 - The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ki
CVE-2026-8870 - The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cros
CVE-2026-8869 - The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tit
CVE-2026-8868 - The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sing
CVE-2026-8867 - The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-8866 - The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'g
CVE-2026-8847 - The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo'
CVE-2026-8846 - The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' sh
CVE-2026-8845 - The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'isla
CVE-2026-8844 - The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspc
CVE-2026-8842 - The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gpl
CVE-2026-8837 - The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Sit
CVE-2026-8787 - The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in
CVE-2026-8760 - The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to
CVE-2026-8708 - The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi
CVE-2026-8707 - The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via P
CVE-2026-8703 - The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode A
CVE-2026-8702 - The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 vi
CVE-2026-8701 - The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers
CVE-2026-8698 - The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-8048 - The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'su
CVE-2026-8040 - The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color'
CVE-2026-7614 - The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
CVE-2026-6268 - The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eve
CVE-2026-9236 - The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress i
CVE-2026-8450 - HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file()
CVE-2026-6287 - The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to
CVE-2026-49000 - An insecure password scheme refers to vulnerabilities arising from improper selection of encryption
CVE-2025-14481 - The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all version
CVE-2026-9022 - The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url
CVE-2026-48999 - Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems
CVE-2026-48962 - IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an at
CVE-2026-48961 - IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with
CVE-2026-48959 - IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in
CVE-2026-2255 - Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, includin
CVE-2026-2254 - Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, includin
CVE-2026-2253 - Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, includin
CVE-2025-15649 - IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip h
CVE-2026-9632 - A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the f
CVE-2026-9631 - A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnera
CVE-2026-9628 - A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown functi
CVE-2026-9627 - A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the functio
CVE-2026-9609 - A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the
CVE-2026-9608 - A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown fun
CVE-2026-9207 - Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-9156 - Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-7493 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress
CVE-2026-6565 - The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for
CVE-2026-49017 - In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processin
CVE-2026-49014 - In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution v
CVE-2026-9607 - A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an
CVE-2026-9606 - A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown
CVE-2026-9605 - A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC
CVE-2026-9312 - A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that a
CVE-2026-8606 - A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that a
CVE-2026-9604 - A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of th
CVE-2026-8680 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8647 - Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG m
CVE-2026-46740 - Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric na
CVE-2026-9603 - A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. Thi
CVE-2026-9584 - A security vulnerability has been detected in code-projects Project Management System 1.0. Affected
CVE-2026-5260 - A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret dur
CVE-2026-48710 - Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request h
CVE-2026-45574 - epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2
CVE-2026-45298 - Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (
CVE-2026-44985 - Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for th
CVE-2026-44983 - smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer o
CVE-2026-44966 - Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earl
CVE-2026-44905 - Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a d
CVE-2026-44903 - Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3
CVE-2026-44900 - epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2
CVE-2026-44895 - GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in sr
CVE-2026-44788 - SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47
CVE-2026-44213 - The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTel
CVE-2026-43988 - Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a d
CVE-2026-42015 - A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This
CVE-2026-42013 - A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN
CVE-2026-42012 - A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a speci
CVE-2025-46307 - A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An ap
CVE-2025-46284 - A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7
CVE-2025-46280 - An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Taho
CVE-2025-43451 - A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Taho
CVE-2025-43306 - A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS S
CVE-2025-43290 - A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
CVE-2025-43289 - A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, mac
CVE-2026-9642 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9583 - A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Ana
CVE-2026-9582 - A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictiv
CVE-2026-9581 - A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function
CVE-2026-9580 - A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginC
CVE-2026-9579 - A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the
CVE-2026-8676 - An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing b
CVE-2026-48593 - Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modu
CVE-2026-48592 - Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modu
CVE-2026-47672 - epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and
CVE-2026-45575 - epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2
CVE-2026-45413 - MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using
CVE-2026-45412 - MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Imp
CVE-2026-44899 - Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive
CVE-2026-44898 - Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() buil
CVE-2026-44897 - Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading
CVE-2026-44896 - Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune
CVE-2026-44847 - MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoin
CVE-2026-44844 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-44843 - LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3
CVE-2026-44837 - view_component is a framework for building reusable, testable, and encapsulated view components in R
CVE-2026-44836 - view_component is a framework for building reusable, testable, and encapsulated view components in R
CVE-2026-44708 - Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plu
CVE-2026-44451 - Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system tran
CVE-2026-44450 - Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint v
CVE-2026-44449 - Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPat
CVE-2026-44444 - Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeli
CVE-2026-44443 - Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that th
CVE-2026-44209 - Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, b
CVE-2026-42337 - MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broke
CVE-2026-42336 - MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a serve
CVE-2026-42335 - MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vuln
CVE-2026-36239 - PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
CVE-2025-68711 - AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android all
CVE-2025-68708 - SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical a
CVE-2025-14361 - Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functi
CVE-2026-9575 - A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue
CVE-2026-9574 - A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability a
CVE-2026-9573 - A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects
CVE-2026-8453 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-44833 - Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in
CVE-2026-44832 - Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only
CVE-2026-44831 - Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access
CVE-2026-44214 - eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prio
CVE-2026-27331 - Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Conf
CVE-2026-25444 - Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Con
CVE-2026-25426 - Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows E
CVE-2026-24520 - Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured
CVE-2025-68710 - Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a
CVE-2025-68709 - SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbi
CVE-2026-9572 - A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the functi
CVE-2026-9568 - A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the f
CVE-2026-8890 - code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticat
CVE-2026-4051 - IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administra
CVE-2026-48689 - FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.