CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2025-13477 - Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credenti
CVE-2026-6841 - Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page"
CVE-2026-5118 - The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to,
CVE-2026-45760 - (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through Use
CVE-2026-43502 - In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send c
CVE-2026-43501 - In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len head
CVE-2026-43499 - In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task inste
CVE-2026-43498 - In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporti
CVE-2026-43497 - In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlf
CVE-2026-43496 - In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace dir
CVE-2026-43495 - In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_
CVE-2026-43494 - In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when ze
CVE-2026-0393 - The affected product may expose credentials remotely between low privileged visualization users duri
CVE-2026-45255 - When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of
CVE-2026-45254 - In the case of the cap_net service, when a key present in the old limit was omitted from the new lim
CVE-2026-45253 - ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta
CVE-2026-45252 - When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR messa
CVE-2026-45251 - A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for
CVE-2026-42396 - Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
CVE-2026-42002 - Concurrency and locking defects in GSS-TSIG
CVE-2026-42001 - Insufficient Validation of Autoprimary SOA Queries
CVE-2026-42000 - Insufficient Validation of Names During AXFR
CVE-2026-41999 - Incorrect Behaviour of Views with TCP PROXY Requests
CVE-2026-39461 - libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) syst
CVE-2026-28764 - MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability
CVE-2026-9157 - Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission
CVE-2026-7837 - A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.
CVE-2026-5434 - Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintende
CVE-2026-5433 - Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface
CVE-2026-4858 - Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail t
CVE-2026-45250 - The setcred(2) system call is only available to privileged users. However, before the privilege lev
CVE-2026-44075 - A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSI
CVE-2026-44074 - Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect
CVE-2026-44071 - Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer over
CVE-2026-44057 - A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an
CVE-2026-27393 - Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configure
CVE-2026-27349 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnel
CVE-2026-22880 - Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly
CVE-2026-7836 - An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper upper
CVE-2026-7835 - A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated atta
CVE-2026-4055 - Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the t
CVE-2026-44076 - Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged
CVE-2026-44073 - Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(),
CVE-2026-44072 - Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the err
CVE-2026-44070 - An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allo
CVE-2026-44069 - An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privile
CVE-2026-44068 - Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 a
CVE-2026-44067 - A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a
CVE-2026-44066 - Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through
CVE-2026-44065 - An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network
CVE-2026-44064 - An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent ne
CVE-2026-44063 - An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attack
CVE-2026-44062 - A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows
CVE-2026-44061 - Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allow
CVE-2026-44060 - An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthentica
CVE-2026-44059 - A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local at
CVE-2026-44058 - An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged us
CVE-2026-44056 - A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.2 allows a remote authenticat
CVE-2026-44055 - A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authen
CVE-2026-44054 - Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, whic
CVE-2026-44053 - Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allow
CVE-2026-44052 - Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which
CVE-2026-44051 - An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authentica
CVE-2026-44050 - A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2
CVE-2026-44049 - An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 throu
CVE-2026-44048 - A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 throug
CVE-2026-44047 - An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a re
CVE-2026-6279 - The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code
CVE-2026-2734 - In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSe
CVE-2026-1543 - The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mul
CVE-2026-4811 - The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress
CVE-2026-9152 - A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoin
CVE-2026-48172 - LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exp
CVE-2026-1881 - The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio
CVE-2026-9149 - A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes
CVE-2026-40165 - authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-r
CVE-2026-9150 - A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debi
CVE-2026-8399 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47782 - Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents with
CVE-2026-47372 - Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These v
CVE-2026-40102 - Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint
CVE-2026-40094 - nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.
CVE-2026-40092 - nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.
CVE-2026-39960 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain fla
CVE-2026-8632 - A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software
CVE-2026-8631 - A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software
CVE-2026-47373 - Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions u
CVE-2026-9144 - Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerab
CVE-2026-9141 - Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability
CVE-2026-9139 - Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability
CVE-2026-9137 - The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed
CVE-2026-9136 - A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action acc
CVE-2026-9133 - Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug
CVE-2026-9129 - A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due t
CVE-2026-9126 - Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execu
CVE-2026-9124 - Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allo
CVE-2026-9123 - Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.
CVE-2026-9122 - Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker
CVE-2026-9121 - Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to p
CVE-2026-9120 - Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execu
CVE-2026-9119 - Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker
CVE-2026-9118 - Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker t
CVE-2026-9117 - Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote a
CVE-2026-9116 - Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed
CVE-2026-9115 - Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowe
CVE-2026-9114 - Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to exec
CVE-2026-9113 - Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker
CVE-2026-9112 - Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker
CVE-2026-9111 - Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker
CVE-2026-9110 - Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a rem
CVE-2026-9102 - A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missi
CVE-2026-9082 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-47099 - TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() funct
CVE-2026-45444 - Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerc
CVE-2026-39850 - Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core vie
CVE-2026-39405 - Frappe Learning Management System (LMS) is a learning system that helps users structure their conten
CVE-2026-39352 - Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a p
CVE-2026-39311 - Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe
CVE-2026-39310 - Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe
CVE-2026-35016 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.ph
CVE-2026-35015 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_m
CVE-2026-35014 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm
CVE-2026-35013 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_vi
CVE-2026-35012 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facno
CVE-2026-35011 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php
CVE-2026-35010 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_J
CVE-2026-35009 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.
CVE-2026-35008 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.ph
CVE-2026-35007 - Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_un
CVE-2026-33137 - XWiki Platform is a generic wiki platform offering runtime services for applications built on top of
CVE-2026-2813 - ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authentica
CVE-2026-2812 - ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative en
CVE-2026-26028 - CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the H
CVE-2026-24218 - NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a
CVE-2026-24217 - NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by
CVE-2026-24216 - NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untr
CVE-2026-24188 - NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A suc
CVE-2026-23734 - XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10
CVE-2026-30691 - Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attacker
CVE-2026-20240 - In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform ve
CVE-2026-20239 - In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3
CVE-2026-20238 - In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or '
CVE-2026-9101 - Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arg
CVE-2026-9100 - The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without a
CVE-2026-9087 - A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, i
CVE-2026-8342 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-7613 - The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-44926 - InfoScale CmdServer before 7.4.2 mishandles access control.
CVE-2026-44925 - Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allow
CVE-2026-44924 - InfoScale VIOM 9.1.3 allows XSS.
CVE-2026-44923 - SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges.
CVE-2026-20223 - A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could a
CVE-2026-20206 - A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowe
CVE-2026-20199 - A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow
CVE-2026-20171 - A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nex
CVE-2026-9084 - MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local
CVE-2026-8598 - An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This
CVE-2026-8488 - Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Autom
CVE-2026-8487 - Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve E
CVE-2026-8486 - Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Autom
CVE-2026-5783 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-4293 - The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabli
CVE-2026-39047 - Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary c
CVE-2025-32750 - Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory
CVE-2023-7346 - Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows
CVE-2026-8485 - Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive
CVE-2026-8469 - Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storyboo
CVE-2026-8467 - Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code e
CVE-2026-47068 - Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook al
CVE-2026-24425 - Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a So
CVE-2026-22554 - MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
CVE-2026-21836 - The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain ci
CVE-2026-5950 - An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server
CVE-2026-5947 - Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIN
CVE-2026-5946 - Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS i
CVE-2026-45584 - Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code ove
CVE-2026-45498 - Microsoft Defender Denial of Service Vulnerability
CVE-2026-45443 - Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template
CVE-2026-42834 - Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges
CVE-2026-42383 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-41091 - Improper link resolution before file access ('link following') in Microsoft Defender allows an autho
CVE-2026-3593 - A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects B
CVE-2026-3592 - BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim r
CVE-2026-3039 - BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable
CVE-2026-29518 - Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon
CVE-2026-27424 - Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiti
CVE-2026-27405 - Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Con
CVE-2026-24573 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2025-11954 - Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. W
CVE-2025-31985 - HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or in
CVE-2025-31973 - HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image
CVE-2026-25602 - Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Compon
CVE-2026-22315 - Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meo
CVE-2026-22314 - Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Laun
CVE-2026-0857 - Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher
CVE-2026-0856 - Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Serv
CVE-2026-9064 - A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does
CVE-2026-6728 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versio
CVE-2026-44933 - `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/`
CVE-2026-44608 - NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerabili
CVE-2026-44390 - NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with
CVE-2026-42960 - NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous rec
CVE-2026-42959 - NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the D
CVE-2026-42944 - NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in hea
CVE-2026-42923 - NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator wh
CVE-2026-42534 - NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that c
CVE-2026-41292 - NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service atta
CVE-2026-41054 - In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX
CVE-2026-40622 - NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domai
CVE-2026-35070 - Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of S
CVE-2026-33278 - NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC valid
CVE-2026-32792 - NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability wh
CVE-2026-9065 - SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameter
CVE-2026-9059 - NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderb
CVE-2026-6405 - The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Req
CVE-2026-5200 - The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugi
CVE-2026-7385 - The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email a
CVE-2026-6566 - The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable
CVE-2026-5776 - The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user
CVE-2026-47784 - In memcached before 1.6.42, password data for SASL password database authentication has a timing sid
CVE-2026-47783 - In memcached before 1.6.42, username data for SASL password database authentication has a timing sid
CVE-2026-44392 - Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user wi
CVE-2026-2955 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-9057 - A broken access control issue has been identified in the Talend Administration Center, that allows a
CVE-2026-9056 - A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An a
CVE-2026-7522 - The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion i
CVE-2026-5075 - The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'interna
CVE-2026-9010 - The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and '
CVE-2026-9003 - E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauth
CVE-2026-7637 - The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin
CVE-2026-7460 - mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue M
CVE-2026-24215 - NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could
CVE-2026-24214 - NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could
CVE-2026-24213 - NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could
CVE-2026-24210 - NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer ove
CVE-2026-24209 - NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path travers
CVE-2026-24208 - NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path travers
CVE-2026-24207 - NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authenticat
CVE-2026-24206 - NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authenticat
CVE-2026-24163 - NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could ca
CVE-2026-24160 - NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked
CVE-2026-24142 - NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized han
CVE-2025-33255 - NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could caus
CVE-2025-15369 - The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modi
CVE-2026-8685 - The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order
CVE-2026-8627 - The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SE
CVE-2026-8626 - The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Para
CVE-2026-8624 - The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin
CVE-2026-8610 - The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all
CVE-2026-8424 - The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.