CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2021-4476 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-4475 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25725 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25715 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2017-20232 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-75933 - Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and s
CVE-2026-75932 - Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom doma
CVE-2026-75928 - The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes
CVE-2026-69502 - Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate
CVE-2026-54789 - mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x H
CVE-2026-49114 - In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the
CVE-2026-22681 - OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticat
CVE-2025-3127 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2795 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-77815 - to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collap
CVE-2026-77814 - is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent direct
CVE-2026-77812 - DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low E
CVE-2026-77087 - Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attack
CVE-2026-75501 - Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.
CVE-2026-63343 - Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image c
CVE-2026-63125 - Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, pr
CVE-2026-62941 - Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an ins
CVE-2026-62940 - Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an i
CVE-2026-62867 - Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation
CVE-2026-62313 - Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enfor
CVE-2026-55622 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorizati
CVE-2026-55621 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorizati
CVE-2026-50278 - iccDEV provides a set of libraries and tools for working with ICC color management profiles. Version
CVE-2026-48769 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file w
CVE-2026-48756 - Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateC
CVE-2026-48755 - Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation
CVE-2026-48754 - Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createD
CVE-2026-48753 - Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upl
CVE-2026-48752 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted
CVE-2026-48751 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots
CVE-2026-48750 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output`
CVE-2026-48749 - Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted
CVE-2026-47753 - Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateI
CVE-2026-77806 - SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited i
CVE-2026-75946 - A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to
CVE-2026-15580 - vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authent
CVE-2026-77780 - Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero
CVE-2026-77028 - Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parame
CVE-2026-76613 - Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.
CVE-2026-76612 - Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1
CVE-2026-76611 - Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery elemen
CVE-2026-75115 - Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.
CVE-2026-59654 - Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped glo
CVE-2026-77776 - Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header
CVE-2026-77775 - Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url requ
CVE-2026-77759 - Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM
CVE-2026-77029 - Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
CVE-2026-59318 - In Spring AI's tool calling support, the per-request tool list is advertised to the model as a bound
CVE-2026-59308 - In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between dif
CVE-2026-59279 - The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on t
CVE-2026-19848 - The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fi
CVE-2026-18356 - The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its
CVE-2026-17559 - The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths wh
CVE-2026-16650 - The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square pa
CVE-2026-15150 - The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment ga
CVE-2026-15046 - The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative act
CVE-2026-13176 - The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on e
CVE-2026-77769 - The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboar
CVE-2026-77768 - The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returne
CVE-2026-77767 - Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an a
CVE-2026-77763 - The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync de
CVE-2026-77761 - A parser state isolation vulnerability in misp-stix could cause data from a previously processed STI
CVE-2026-77686 - A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file ht
CVE-2026-77683 - A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi
CVE-2026-77086 - SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall end
CVE-2026-59296 - Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag
CVE-2026-15576 - Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote
CVE-2026-14208 - Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C
CVE-2026-77755 - A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled ST
CVE-2026-77751 - A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 i
CVE-2026-77681 - A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is
CVE-2026-59323 - An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerab
CVE-2026-48590 - XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML
CVE-2026-47827 - Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute a
CVE-2026-47080 - XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML
CVE-2026-47079 - Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module)
CVE-2026-77710 - A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MIS
CVE-2026-74866 - @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits
CVE-2026-68745 - Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on
CVE-2026-66797 - Improper access control in CloudStack's annotation functionality allows unauthorized comment creatio
CVE-2026-66722 - Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain
CVE-2026-66721 - Missing authorization issue for domain admins in CloudStack's host tags listing functionality. D
CVE-2026-65613 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webh
CVE-2026-63046 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in
CVE-2026-62440 - Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowi
CVE-2026-61422 - Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration
CVE-2026-61400 - Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in
CVE-2026-61399 - Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock Use
CVE-2026-61398 - Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance
CVE-2026-61397 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut
CVE-2026-59799 - Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin
CVE-2026-59780 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP
CVE-2026-59657 - Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage
CVE-2026-59655 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut
CVE-2026-59085 - Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable
CVE-2026-50222 - Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A
CVE-2026-50112 - SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing t
CVE-2026-47359 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi
CVE-2026-77264 - The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo
CVE-2026-73537 - Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited
CVE-2026-19441 - Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake
CVE-2026-16323 - Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectP
CVE-2026-75796 - The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized
CVE-2026-19435 - The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before retur
CVE-2026-19085 - The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of
CVE-2026-18781 - The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not v
CVE-2026-16962 - The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any
CVE-2026-16959 - The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before
CVE-2026-16577 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d
CVE-2026-16576 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d
CVE-2026-16575 - The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d
CVE-2026-14601 - The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a paramete
CVE-2026-14325 - The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not e
CVE-2026-13736 - The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-onl
CVE-2025-15671 - The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on
CVE-2026-65645 - Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15,
CVE-2026-65644 - Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 h
CVE-2026-45202 - Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU mem
CVE-2026-45201 - Software installed and run as a non-privileged user may conduct improper GPU system calls to pass in
CVE-2026-45199 - Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmwa
CVE-2026-18409 - The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Te
CVE-2026-76158 - External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center f
CVE-2026-76137 - Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running
CVE-2026-76131 - Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate
CVE-2026-73267 - A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant wi
CVE-2026-77392 - A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and
CVE-2026-77391 - A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS,
CVE-2026-76157 - Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management
CVE-2026-76156 - OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.
CVE-2026-76155 - Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem
CVE-2026-77651 - The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project
CVE-2026-77650 - The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a pr
CVE-2026-77649 - The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project
CVE-2026-43679 - This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An
CVE-2026-20679 - The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Son
CVE-2026-16520 - Improper input validation and Exposure of sensitive information through data queries vulnerability i
CVE-2026-77648 - In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_f
CVE-2026-77647 - SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited i
CVE-2026-77113 - Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allow
CVE-2026-77646 - A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PT
CVE-2026-77645 - A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC Flex
CVE-2026-77644 - A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliabili
CVE-2026-77643 - A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core
CVE-2026-77642 - tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatu
CVE-2026-72860 - The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se
CVE-2026-72858 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-72848 - SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente
CVE-2026-72846 - Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendW
CVE-2026-72843 - The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m
CVE-2026-72818 - The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app
CVE-2026-70105 - Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor
CVE-2026-69855 - Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di
CVE-2026-69851 - Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat
CVE-2026-69836 - Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c
CVE-2026-69558 - Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized
CVE-2026-69555 - Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne
CVE-2026-69543 - Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat
CVE-2026-69519 - Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor
CVE-2026-69419 - Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe
CVE-2026-69400 - Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a
CVE-2026-68789 - Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da
CVE-2026-68782 - Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da
CVE-2026-67448 - Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/
CVE-2026-67447 - Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's interna
CVE-2026-66800 - Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose
CVE-2026-66309 - Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov
CVE-2026-65816 - Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat
CVE-2026-65801 - Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e
CVE-2026-65770 - Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed
CVE-2026-64773 - An attacker that can reach a container's published TCP port may be able to force the host's forwardi
CVE-2026-63509 - Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over
CVE-2026-62945 - TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions a
CVE-2026-62834 - Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack
CVE-2026-55894 - Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.
CVE-2026-55893 - Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.
CVE-2026-55769 - CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.
CVE-2026-55765 - CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.
CVE-2026-55491 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape m
CVE-2026-55489 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could s
CVE-2026-55015 - Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic
CVE-2026-55013 - Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per
CVE-2026-54509 - TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link
CVE-2026-54508 - TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before n
CVE-2026-54505 - TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK int
CVE-2026-54389 - Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser t
CVE-2026-50192 - Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the
CVE-2026-49436 - LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API
CVE-2026-49245 - SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline qu
CVE-2026-49244 - SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public we
CVE-2026-49217 - Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati
CVE-2026-46682 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica
CVE-2026-46355 - BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu
CVE-2026-19783 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory co
CVE-2026-19449 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unpriv
CVE-2026-19448 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the
CVE-2026-19446 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr
CVE-2026-19442 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua
CVE-2026-19437 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-18842 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
CVE-2026-18840 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
CVE-2026-18835 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
CVE-2026-18832 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-18828 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-18824 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
CVE-2026-18822 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-18716 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain
CVE-2026-18670 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17436 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17425 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17424 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restr
CVE-2026-17423 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info
CVE-2026-17422 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
CVE-2026-17195 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-17171 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary fi
CVE-2026-17170 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17168 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute
CVE-2026-17165 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17163 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17160 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17159 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17157 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17152 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17145 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17142 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com
CVE-2026-17141 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17138 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17136 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17124 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
CVE-2026-17122 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17121 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17120 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser
CVE-2026-17118 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17060 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive info
CVE-2026-17040 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17024 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17009 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
CVE-2026-17007 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive infor
CVE-2026-17006 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-17003 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confid
CVE-2026-17000 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod
CVE-2026-16997 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm
CVE-2026-16996 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code
CVE-2026-16991 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
CVE-2026-16989 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg
CVE-2026-16980 - IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of serv
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware