CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-33514 - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 a
CVE-2026-33234 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-33233 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-33232 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-33052 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a lo
CVE-2026-32323 - Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and be
CVE-2026-32312 - GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authe
CVE-2026-32244 - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 a
CVE-2026-30950 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-27964 - FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contai
CVE-2026-27892 - FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the L
CVE-2026-27891 - FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain
CVE-2026-27737 - BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playba
CVE-2026-8851 - SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List man
CVE-2026-8838 - Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift
CVE-2026-4137 - In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/uti
CVE-2026-27130 - Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS com
CVE-2026-26978 - FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not p
CVE-2026-25244 - WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebD
CVE-2026-22810 - Joplin is an open source note-taking and to-do application that organises notes and lists into noteb
CVE-2026-47092 - Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability tha
CVE-2026-47091 - Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that a
CVE-2026-47090 - Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape seq
CVE-2026-45246 - Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free con
CVE-2026-45245 - Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows maliciou
CVE-2026-45244 - Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to ex
CVE-2026-21789 - HCL Connections contains a broken access control vulnerability that may allow unauthorized user to u
CVE-2025-65954 - SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp mod
CVE-2026-8836 - A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of
CVE-2026-45243 - Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script windo
CVE-2026-45242 - Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoi
CVE-2026-45231 - DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields inclu
CVE-2026-45495 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-45494 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45492 - Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypa
CVE-2026-45230 - DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpo
CVE-2026-42822 - Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to el
CVE-2026-32849 - NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op(
CVE-2026-32848 - NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the
CVE-2026-29965 - HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.
CVE-2026-29964 - HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php e
CVE-2026-29963 - HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supp
CVE-2026-29962 - HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper co
CVE-2023-24215 - Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unaut
CVE-2026-8843 - Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subse
CVE-2026-45829 - A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python
CVE-2026-41085 - Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability th
CVE-2026-38719 - OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (C
CVE-2026-36438 - An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain se
CVE-2026-20685 - An attacker in a privileged network position may be able to leak sensitive information. A path handl
CVE-2025-57282 - ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-56352 - In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles prot
CVE-2026-41949 - Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoi
CVE-2026-41948 - Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users
CVE-2026-41947 - Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated
CVE-2026-39079 - An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to o
CVE-2026-26462 - Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron re
CVE-2026-42009 - A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer
CVE-2026-8803 - A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the functi
CVE-2026-7304 - SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when th
CVE-2026-7302 - SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerabili
CVE-2026-7301 - SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and cont
CVE-2026-0983 - Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and bef
CVE-2026-8802 - A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affe
CVE-2026-4320 - Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unaut
CVE-2026-41119 - Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation
CVE-2026-7498 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-6902 - A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the
CVE-2026-6347 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensiti
CVE-2026-6346 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensiti
CVE-2026-6345 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure
CVE-2026-6343 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/pri
CVE-2026-6339 - Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header
CVE-2026-6333 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when cons
CVE-2026-5163 - Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted m
CVE-2026-4643 - Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from cl
CVE-2026-4286 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being cha
CVE-2026-3471 - Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in
CVE-2026-3117 - Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions w
CVE-2026-28732 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash co
CVE-2026-8788 - Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the s
CVE-2026-6342 - Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid na
CVE-2026-6341 - Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which g
CVE-2026-6340 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip ar
CVE-2026-6334 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding du
CVE-2026-4273 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken d
CVE-2026-3637 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create
CVE-2026-3495 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could c
CVE-2026-2325 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size o
CVE-2026-28759 - Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a
CVE-2026-6495 - The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before ou
CVE-2026-6381 - The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in
CVE-2026-6379 - The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a p
CVE-2026-3220 - The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed
CVE-2026-1631 - The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is
CVE-2026-8786 - A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the functio
CVE-2026-8785 - A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulne
CVE-2026-8784 - A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_
CVE-2026-8783 - A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the fun
CVE-2026-8782 - A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function
CVE-2026-8781 - A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the
CVE-2026-8780 - A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unkno
CVE-2026-8779 - A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetup
CVE-2026-8777 - A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup
CVE-2026-8776 - A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function for
CVE-2026-8775 - A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file
CVE-2026-8774 - A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of
CVE-2026-8773 - A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vuln
CVE-2026-8772 - A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function o
CVE-2026-8771 - A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function li
CVE-2026-8770 - A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsToo
CVE-2026-8769 - A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function creat
CVE-2026-8768 - A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDo
CVE-2026-8767 - A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .
CVE-2026-8766 - A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the
CVE-2026-8765 - A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the funct
CVE-2026-8764 - A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function
CVE-2026-8721 - Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Pass
CVE-2026-8507 - Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When pa
CVE-2026-46720 - Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and se
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.