CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-73725 - A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Su
CVE-2026-73724 - Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful
CVE-2026-73723 - A privilege escalation vulnerability exists in the web-based management interface of HPE Networking
CVE-2026-73722 - Command injection vulnerabilities in the web-based management interface of HPE Networking Fabric Com
CVE-2026-73721 - Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote att
CVE-2026-73720 - Insecure file operations in the API of HPE Networking Fabric Composer could allow an authenticated r
CVE-2026-73719 - An arbitrary file write vulnerability exists in the API of HPE Networking Fabric Composer and could
CVE-2026-73718 - A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow
CVE-2026-73717 - A command injection vulnerability exists in the web-based management interface of HPE Networking Fab
CVE-2026-73716 - A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fa
CVE-2026-73715 - A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote a
CVE-2026-73714 - A sensitive information disclosure vulnerability exists in the API of HPE Networking Fabric Composer
CVE-2026-73713 - Local privilege-escalation vulnerabilities have been discovered in HPE Networking Fabric Composer. S
CVE-2026-73712 - A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote a
CVE-2026-73711 - A privilege escalation vulnerability exists in the API endpoint of HPE Networking Fabric Composer. S
CVE-2026-73710 - Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an unauthenticated
CVE-2026-73709 - A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an
CVE-2026-73708 - A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful explo
CVE-2026-73707 - Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. Successful
CVE-2026-73706 - A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote a
CVE-2026-73705 - An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an au
CVE-2026-73704 - A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploi
CVE-2026-73703 - A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow
CVE-2026-73702 - A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful
CVE-2026-73701 - An unauthenticated remote code execution vulnerability exists in the underlying operating system of
CVE-2026-73700 - A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow
CVE-2026-72682 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-72654 - Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to i
CVE-2026-72652 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-72649 - Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead
CVE-2026-72644 - Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (
CVE-2026-72641 - Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Access
CVE-2026-72633 - Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitori
CVE-2026-72628 - Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via
CVE-2026-63138 - Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to info
CVE-2026-63137 - Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrec
CVE-2026-56143 - Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial
CVE-2026-45221 - Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local at
CVE-2026-33465 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-19766 - An authentication bypass vulnerability exists in the underlying operating system of HPE Networking F
CVE-2026-8712 - Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticat
CVE-2026-84306 - Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 un
CVE-2026-84305 - sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, rein
CVE-2026-84304 - gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go
CVE-2026-84303 - gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in inte
CVE-2026-83551 - Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in
CVE-2026-81846 - An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.
CVE-2026-52295 - FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding bef
CVE-2026-52132 - llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to
CVE-2026-52131 - llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
CVE-2026-52130 - llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.
CVE-2026-52111 - An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the
CVE-2026-52023 - An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via th
CVE-2026-52022 - An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via th
CVE-2026-51974 - An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel F
CVE-2026-19593 - OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree sta
CVE-2026-19592 - OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically
CVE-2026-19591 - OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified
CVE-2026-19590 - OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because autom
CVE-2024-7953 - A vulnerability exists in the affected products that allows a threat actor to create a project and b
CVE-2024-7952 - A data exposure vulnerability exists in the affected product. There are hardcoded links in the sourc
CVE-2026-58566 - Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote acc
CVE-2026-51956 - A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An a
CVE-2026-51934 - Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.0
CVE-2026-51788 - An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the a
CVE-2026-84270 - A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read(
CVE-2026-84269 - A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause
CVE-2026-84268 - A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious
CVE-2026-84267 - A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cau
CVE-2026-84232 - A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type reposit
CVE-2026-84207 - Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes,
CVE-2026-84206 - Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of
CVE-2026-84205 - GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that valid
CVE-2026-84204 - GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fail
CVE-2026-84203 - Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their passwor
CVE-2026-84202 - ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary c
CVE-2026-84201 - appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and wri
CVE-2026-84153 - A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the fun
CVE-2026-79687 - Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unau
CVE-2026-79682 - Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privi
CVE-2026-61779 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61778 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61777 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61776 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61775 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61774 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61773 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61772 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61771 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61770 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61769 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61768 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61767 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61766 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61765 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61764 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61763 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61762 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61761 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61760 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61759 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61758 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61757 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61756 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61755 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61754 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61753 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61752 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61751 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-61750 - NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u
CVE-2026-58567 - Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited p
CVE-2026-51770 - Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015
CVE-2026-51769 - Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015
CVE-2026-51768 - Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allo
CVE-2026-51767 - Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allow
CVE-2026-49329 - A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauth
CVE-2026-18931 - Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Ind
CVE-2026-10195 - The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and incl
CVE-2026-84233 - A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containin
CVE-2026-84115 - A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown functio
CVE-2026-84114 - A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUti
CVE-2026-84111 - A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of t
CVE-2026-84110 - A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects
CVE-2026-83619 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83618 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83617 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83616 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83615 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83614 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83613 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83612 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83611 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83610 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83609 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83608 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83607 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83606 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83605 - xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mo
CVE-2026-83557 - DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @Jso
CVE-2026-79686 - Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with li
CVE-2026-79685 - Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited pri
CVE-2026-78012 - An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-messa
CVE-2026-75538 - An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode
CVE-2026-74994 - The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication
CVE-2026-74835 - The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked req
CVE-2026-73812 - httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks
CVE-2026-73276 - Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smugglin
CVE-2026-73270 - Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauth
CVE-2026-71562 - Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a
CVE-2026-71380 - Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows
CVE-2026-70409 - Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malici
CVE-2026-70405 - Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote
CVE-2026-70399 - Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows
CVE-2026-69664 - Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows
CVE-2026-66835 - Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to
CVE-2026-66357 - httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Ev
CVE-2026-5480 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-59696 - Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remot
CVE-2026-58569 - Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability.
CVE-2026-55951 - The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers rece
CVE-2026-18780 - Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft
CVE-2026-18771 - Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co
CVE-2026-18630 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-9637 - A denial-of-service security issue exists in the affected Logix platforms listed in the table above.
CVE-2026-9634 - A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary
CVE-2026-9633 - A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binar
CVE-2026-9625 - A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an overs
CVE-2026-9624 - A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the
CVE-2026-9622 - A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the
CVE-2026-9621 - A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from impr
CVE-2026-84218 - A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-co
CVE-2026-84109 - A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the f
CVE-2026-80047 - A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files
CVE-2026-79684 - Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with li
CVE-2026-58572 - Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileg
CVE-2026-58571 - Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited p
CVE-2026-51766 - Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un
CVE-2026-51765 - Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 a
CVE-2026-51764 - Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211
CVE-2026-51763 - Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows u
CVE-2026-51762 - Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un
CVE-2026-51761 - Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows una
CVE-2026-51760 - Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51757 - Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51756 - Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51754 - Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allo
CVE-2026-51752 - Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51751 - Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51750 - Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allow
CVE-2026-51748 - Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015
CVE-2026-19513 - The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to,
CVE-2026-18808 - Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electr
CVE-2026-18210 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-16675 - A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security is
CVE-2026-13348 - CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could a
CVE-2026-13337 - CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious
CVE-2026-13336 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') v
CVE-2026-12663 - A security issue exists within ControlFLASH™, where the installer grants write permissions to the "E
CVE-2026-12661 - A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network
CVE-2025-12768 - A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level au
CVE-2024-14047 - A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a dir
CVE-2024-10085 - CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause
CVE-2026-84235 - A denial-of-service security issue exists in the affected product. The security issue stems from a c
CVE-2026-84149 - This vulnerability exists in the ERP system due to exposure of repository information through a publ
CVE-2026-84148 - This vulnerability exists in the ERP system due to improper authentication and authorization control
CVE-2026-84147 - This vulnerability exists in the ERP system due to improper authentication controls and inadequate f
CVE-2026-84145 - Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14.
CVE-2026-84144 - Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showe
CVE-2026-84143 - Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14.
CVE-2026-84142 - Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corru
CVE-2026-84141 - Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, F
CVE-2026-84140 - Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155,
CVE-2026-84139 - Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefo
CVE-2026-84138 - Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thund
CVE-2026-84137 - Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firef
CVE-2026-84136 - Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox E
CVE-2026-84135 - Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84134 - Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ES
CVE-2026-84133 - Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firef
CVE-2026-84132 - Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 15
CVE-2026-84131 - Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed
CVE-2026-84130 - Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 15
CVE-2026-84129 - Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155,
CVE-2026-84128 - Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 an
CVE-2026-84127 - Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was
CVE-2026-84126 - Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox
CVE-2026-84125 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firef
CVE-2026-84124 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firef
CVE-2026-84123 - Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was
CVE-2026-84122 - Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ES
CVE-2026-84121 - Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in
CVE-2026-84120 - Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ES
CVE-2026-84119 - Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed
CVE-2026-84118 - Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox
CVE-2026-84117 - Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
CVE-2026-84061 - A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerabil
CVE-2026-7877 - The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
CVE-2026-79683 - Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with li
CVE-2026-58575 - Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attack
CVE-2026-53682 - An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDom
CVE-2026-51747 - Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unaut
CVE-2026-51745 - Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allow
CVE-2026-51744 - Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 al
CVE-2026-51743 - Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51742 - Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows una
CVE-2026-51741 - Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allo
CVE-2026-19472 - A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from impro
CVE-2026-19471 - Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs
CVE-2026-18765 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-84200 - Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in e
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware