CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-9294 - A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWa
CVE-2026-9284 - The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulatio
CVE-2026-6898 - The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a
CVE-2026-6897 - The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a
CVE-2026-6895 - The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive
CVE-2026-6419 - The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authoriza
CVE-2026-47280 - Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate p
CVE-2026-45659 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
CVE-2026-42901 - Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges
CVE-2026-42827 - Improper neutralization of special elements used in a command ('command injection') in M365 Copilot
CVE-2026-41149 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-41148 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-41104 - Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacke
CVE-2026-41090 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop
CVE-2026-40412 - Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attac
CVE-2026-40411 - Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute
CVE-2026-35430 - Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allow
CVE-2026-33843 - Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C all
CVE-2026-26147 - Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose informa
CVE-2026-23663 - Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privilege
CVE-2026-23652 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow
CVE-2026-41147 - NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-
CVE-2026-41076 - RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in
CVE-2026-41075 - RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.
CVE-2026-41074 - RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.
CVE-2026-41073 - RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 an
CVE-2026-41071 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted
CVE-2026-41069 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malforme
CVE-2026-40864 - JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In ver
CVE-2026-3294 - An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated
CVE-2026-5843 - The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which uncondition
CVE-2026-5817 - The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_c
CVE-2026-40610 - BentoML is a Python library for building online serving systems optimized for AI apps and model infe
CVE-2026-40607 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a
CVE-2026-40598 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, imprope
CVE-2026-40597 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given a
CVE-2026-40596 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow
CVE-2026-40295 - Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when th
CVE-2026-39824 - NewNTUnicodeString does not check for string length overflow. When provided with a string that overf
CVE-2026-9291 - Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0
CVE-2026-6406 - The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Doc
CVE-2026-48700 - An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's pat
CVE-2026-40172 - authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 throu
CVE-2026-40166 - authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 throu
CVE-2026-39970 - TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerabi
CVE-2026-39969 - TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endp
CVE-2026-39968 - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("C
CVE-2026-39967 - TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult que
CVE-2026-39966 - TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns fu
CVE-2026-46727 - An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the
CVE-2026-42627 - In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tenso
CVE-2026-39965 - TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypas
CVE-2026-39964 - TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/
CVE-2026-9255 - Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a
CVE-2026-42626 - HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connection
CVE-2026-37470 - An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authenticatio
CVE-2026-36228 - Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive i
CVE-2026-36227 - Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensiti
CVE-2026-36226 - Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attac
CVE-2026-34207 - TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP R
CVE-2026-33712 - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /ap
CVE-2026-32253 - Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the
CVE-2026-28735 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-28445 - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the e
CVE-2026-28444 - Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint auth
CVE-2026-9251 - Missing authorization in the entry status management feature in Devolutions Server allows a non-admi
CVE-2026-9249 - Unverified password change in Devolutions Server allows an attacker to change a user's password with
CVE-2026-9248 - Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated
CVE-2026-9247 - Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user
CVE-2026-9246 - Improper access control in the entry documentation and attachment features in Devolutions Server all
CVE-2026-9245 - Improper input validation in the external authentication provider flow in Devolutions Server allows
CVE-2026-9224 - Missing authorization in the user profile update feature in Devolutions Server allows an authenticat
CVE-2026-9223 - Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier all
CVE-2026-9047 - Improper handling of factor key state in the multi-factor authentication management feature in Devol
CVE-2026-8477 - Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in D
CVE-2026-7325 - Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-p
CVE-2026-5171 - Improper access control in the entry activity log feature in Devolutions Server allows an authentica
CVE-2026-42506 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th
CVE-2026-42502 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th
CVE-2026-39821 - The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASC
CVE-2026-27136 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th
CVE-2026-25681 - Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. Th
CVE-2026-25680 - Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CVE-2022-34363 - Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnera
CVE-2022-31231 - Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Manage
CVE-2026-9256 - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vu
CVE-2026-8992 - An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows
CVE-2026-8353 - Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A r
CVE-2026-8347 - Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express associ
CVE-2026-8340 - Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edi
CVE-2025-46371 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algo
CVE-2025-45145 - Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1
CVE-2025-32751 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information
CVE-2021-21508 - Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Ma
CVE-2026-9277 - shell-quote's `quote()` function did not validate object-token inputs against the operator model use
CVE-2026-8997 - vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state
CVE-2026-8673 - Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows
CVE-2026-8672 - Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Co
CVE-2026-8671 - Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Lin
CVE-2026-8670 - Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allow
CVE-2025-32749 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory
CVE-2025-32747 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerabili
CVE-2025-32746 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information
CVE-2025-32745 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerabil
CVE-2025-26483 - Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauth
CVE-2026-44930 - An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF
CVE-2026-44618 - Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform
CVE-2026-44417 - The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete
CVE-2026-5755 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x
CVE-2026-5740 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-5308 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-4646 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-4635 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-3636 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-3473 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-25608 - STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduc
CVE-2026-25607 - Use of a weak password encoding algorithm in STER software allows the value of the password to be gu
CVE-2026-25606 - A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided
CVE-2026-9011 - The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to author
CVE-2026-8692 - The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPr
CVE-2026-8684 - The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versio
CVE-2026-8679 - The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions
CVE-2026-8381 - A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior vers
CVE-2026-7798 - The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and C
CVE-2026-7636 - The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable t
CVE-2026-7615 - The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
CVE-2026-5072 - A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined
CVE-2026-9104 - The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Titl
CVE-2026-9018 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to P
CVE-2026-7509 - The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
CVE-2026-7249 - The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to
CVE-2026-6864 - The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting
CVE-2026-4070 - The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
CVE-2026-44409 - There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of
CVE-2026-3481 - The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortc
CVE-2026-2518 - The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activati
CVE-2026-9054 - An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size woul
CVE-2026-9053 - Mothra would respect a default value given by a website for HTML file upload forms. An attacker coul
CVE-2026-4834 - The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in
CVE-2026-46598 - For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, lead
CVE-2026-46597 - An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet dec
CVE-2026-46595 - Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if a
CVE-2026-42508 - Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now
CVE-2026-39835 - SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHost
CVE-2026-39834 - When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in t
CVE-2026-39833 - The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse cons
CVE-2026-39832 - When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.c
CVE-2026-39831 - The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25
CVE-2026-39830 - A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blo
CVE-2026-39829 - The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public k
CVE-2026-39828 - When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, th
CVE-2026-39827 - An authenticated SSH client that repeatedly opened channels which were rejected by the server caused
CVE-2026-9264 - A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remo
CVE-2026-34911 - A malicious actor with access to the network and low privileges could exploit a Path Traversal vulne
CVE-2026-34910 - A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit
CVE-2026-34909 - A malicious actor with access to the network could exploit a Path Traversal vulnerability found in U
CVE-2026-34908 - A malicious actor with access to the network could exploit an Improper Access Control vulnerability
CVE-2026-33000 - A malicious actor with access to the network and high privileges could exploit an Improper Input Val
CVE-2026-5297 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8435 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8434 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8433 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8432 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8427 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8416 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8415 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8414 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8413 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8412 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controll
CVE-2026-8411 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8410 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8409 - Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controlle
CVE-2026-8337 - Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have t
CVE-2026-8327 - Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and sess
CVE-2026-8245 - Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute
CVE-2026-8240 - Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every
CVE-2026-8239 - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' end
CVE-2026-8238 - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' e
CVE-2026-8237 - Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail`
CVE-2026-8236 - Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The
CVE-2026-8139 - Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updat
CVE-2026-7890 - In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and
CVE-2026-7887 - For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A us
CVE-2026-7886 - Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] par
CVE-2026-7882 - Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF to
CVE-2026-7881 - Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express En
CVE-2026-7879 - In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/d
CVE-2026-6960 - The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil
CVE-2026-5091 - Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks
CVE-2026-4929 - Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper out
CVE-2026-4093 - In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter ren
CVE-2026-22678 - Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template descr
CVE-2026-8428 - Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->outp
CVE-2026-8426 - Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard
CVE-2026-8421 - Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concre
CVE-2026-8417 - Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard
CVE-2026-8352 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-8350 - Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php
CVE-2026-8205 - Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since actio
CVE-2026-8204 - Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Di
CVE-2026-8203 - Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validat
CVE-2026-8197 - Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth autho
CVE-2026-8140 - Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard
CVE-2026-8135 - Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization
CVE-2026-8134 - Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutS
CVE-2026-6826 - Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing per
CVE-2026-47102 - LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint.
CVE-2026-47101 - LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to rou
CVE-2026-4843 - The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a
CVE-2026-47114 - IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attack
CVE-2026-46473 - Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated usi
CVE-2026-48249 - Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.ph
CVE-2026-48248 - Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setti
CVE-2026-48247 - Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by s
CVE-2026-48246 - Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting
CVE-2026-48245 - Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committ
CVE-2026-48244 - Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is c
CVE-2026-48243 - Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that
CVE-2026-48242 - Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, user
CVE-2026-48241 - Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a publi
CVE-2026-48240 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where
CVE-2026-48239 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the
CVE-2026-48238 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where
CVE-2026-48237 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_
CVE-2026-48236 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the mu
CVE-2026-48235 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where
CVE-2026-48234 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.
CVE-2026-48233 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php whe
CVE-2026-48232 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php
CVE-2026-48231 - Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multi
CVE-2026-48230 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmd
CVE-2026-48229 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.
CVE-2026-48228 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w
CVE-2026-48227 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.p
CVE-2026-48226 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.
CVE-2026-48225 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php
CVE-2026-48224 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.ph
CVE-2026-48223 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.
CVE-2026-48222 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.ph
CVE-2026-48221 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.p
CVE-2026-48220 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.ph
CVE-2026-48219 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.ph
CVE-2026-48218 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/but
CVE-2026-48217 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_mo
CVE-2026-48216 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader
CVE-2026-48215 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.ph
CVE-2026-48214 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.ph
CVE-2026-39593 - Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Acc
CVE-2026-48213 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php t
CVE-2026-48207 - Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass docu
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.