CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-84196 - Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url th
CVE-2026-84195 - Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outb
CVE-2026-84194 - LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command inje
CVE-2026-84193 - LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template
CVE-2026-84192 - LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates
CVE-2026-84191 - LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages whe
CVE-2026-84190 - LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController
CVE-2026-84189 - LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by th
CVE-2026-84188 - LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<
CVE-2026-84187 - AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows una
CVE-2026-83595 - AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows at
CVE-2026-77194 - The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Adminis
CVE-2026-76111 - Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with lo
CVE-2026-18550 - The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Accoun
CVE-2026-11873 - An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 5
CVE-2026-10420 - Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulatio
CVE-2025-15613 - Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call func
CVE-2023-54356 - Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_
CVE-2026-84165 - A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting
CVE-2026-84059 - A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the fun
CVE-2026-82927 - Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulatio
CVE-2026-82926 - NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. T
CVE-2026-4813 - A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows au
CVE-2026-59681 - A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Dir
CVE-2026-59680 - An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settin
CVE-2026-25706 - Improper neutralization of special elements used in an OS command in yast2-samba-client allows an at
CVE-2026-19914 - The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cu
CVE-2026-16788 - The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cros
CVE-2026-16786 - The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cros
CVE-2026-15101 - The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-78363 - The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values fr
CVE-2026-74916 - The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query
CVE-2026-13611 - The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST
CVE-2026-78319 - A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) r
CVE-2026-83772 - A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. Thi
CVE-2026-77189 - The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising
CVE-2026-75980 - The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPres
CVE-2026-75964 - The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugi
CVE-2026-18488 - The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName
CVE-2026-83744 - A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnera
CVE-2026-83743 - A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown
CVE-2026-82747 - Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy
CVE-2026-77823 - The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of th
CVE-2026-76006 - The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQ
CVE-2026-75965 - The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugi
CVE-2026-75921 - The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widge
CVE-2026-19952 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due t
CVE-2026-19948 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates
CVE-2026-19806 - The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin
CVE-2026-19796 - The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vul
CVE-2026-19573 - The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-18752 - The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id
CVE-2026-17589 - The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via
CVE-2026-16787 - The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cros
CVE-2026-13203 - The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cros
CVE-2026-12747 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
CVE-2026-82749 - Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping
CVE-2026-82748 - Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read acti
CVE-2026-82746 - Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden b
CVE-2026-82745 - Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing
CVE-2026-82744 - Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change whe
CVE-2026-82743 - Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spi
CVE-2026-82742 - Uncontrolled Resource Consumption vulnerability in ash-project ash lets an attacker exhaust node mem
CVE-2026-82741 - Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker con
CVE-2026-82740 - Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constrai
CVE-2026-82739 - Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash disclo
CVE-2026-82738 - Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny r
CVE-2026-82737 - Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored ve
CVE-2026-82736 - Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an atta
CVE-2026-82735 - Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an ex
CVE-2026-82734 - Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attack
CVE-2026-19032 - jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without res
CVE-2026-82733 - Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typesc
CVE-2026-82732 - Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to su
CVE-2026-82731 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allo
CVE-2026-82730 - Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC calle
CVE-2026-77950 - Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typesc
CVE-2026-77856 - Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript all
CVE-2026-75865 - The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode pl
CVE-2026-74837 - Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript all
CVE-2026-67395 - A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due
CVE-2026-67394 - A critical local privilege escalation via OS command injection vulnerability has been discovered in
CVE-2026-65643 - Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitra
CVE-2026-48932 - A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding pro
CVE-2026-18743 - A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configu
CVE-2026-19820 - A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creat
CVE-2026-83524 - A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optim
CVE-2026-82971 - A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown par
CVE-2026-4560 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-82957 - A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the fu
CVE-2026-82954 - A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikCo
CVE-2026-82922 - A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects
CVE-2026-82921 - A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_typ
CVE-2026-82882 - Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webho
CVE-2026-82398 - pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PD
CVE-2026-82397 - Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse
CVE-2026-82396 - Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versio
CVE-2026-82395 - Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versio
CVE-2026-82394 - Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versio
CVE-2026-82393 - pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a t
CVE-2026-77353 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallo
CVE-2026-77352 - Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before
CVE-2026-77351 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallo
CVE-2026-77348 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the f
CVE-2026-83596 - A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to i
CVE-2026-82919 - A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the func
CVE-2026-82914 - A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability
CVE-2026-82909 - A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is s
CVE-2026-82908 - A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is th
CVE-2026-82906 - A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the fi
CVE-2026-82852 - Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.
CVE-2026-82392 - pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package n
CVE-2026-82346 - A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.
CVE-2026-82229 - Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
CVE-2026-82228 - Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
CVE-2026-82226 - Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
CVE-2026-82225 - Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-82224 - Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
CVE-2026-82221 - Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-81892 - EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 an
CVE-2026-81891 - elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1
CVE-2026-81890 - elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1
CVE-2026-81889 - elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1
CVE-2026-81888 - @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in so
CVE-2026-81887 - Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-not
CVE-2026-81780 - Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
CVE-2026-81779 - Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows
CVE-2026-81778 - Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
CVE-2026-81768 - Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
CVE-2026-81765 - Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
CVE-2026-81764 - Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
CVE-2026-81763 - Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
CVE-2026-81762 - Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
CVE-2026-81758 - Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.
CVE-2026-81756 - Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
CVE-2026-81298 - Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
CVE-2026-81297 - Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-81296 - Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
CVE-2026-81293 - Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
CVE-2026-81291 - Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.
CVE-2026-81290 - Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
CVE-2026-81287 - Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
CVE-2026-81280 - Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4
CVE-2026-81278 - Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured
CVE-2026-79483 - FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api
CVE-2026-79408 - An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary comma
CVE-2026-79407 - A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbi
CVE-2026-75594 - Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the releas
CVE-2026-75592 - Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the releas
CVE-2026-75460 - XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-en
CVE-2026-75458 - The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <=
CVE-2026-71415 - Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk up
CVE-2026-62993 - Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from app
CVE-2026-61641 - Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before
CVE-2026-61640 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin
CVE-2026-61639 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST
CVE-2026-61638 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST
CVE-2026-54600 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpo
CVE-2026-54599 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login
CVE-2026-54598 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpo
CVE-2026-54179 - backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of
CVE-2026-50199 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpo
CVE-2026-50198 - Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an au
CVE-2026-38577 - Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to
CVE-2025-63607 - TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoe
CVE-2026-82905 - A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of
CVE-2026-82835 - A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unkno
CVE-2026-82834 - A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Pra
CVE-2026-82833 - A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practiti
CVE-2026-81267 - A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address
CVE-2026-52730 - Xibo is an open source digital signage platform with a web content management system and Windows dis
CVE-2026-51740 - Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows una
CVE-2026-51739 - Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 a
CVE-2026-51738 - Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51737 - Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 all
CVE-2026-51736 - Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows una
CVE-2026-51735 - Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau
CVE-2026-51734 - Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allo
CVE-2026-51733 - Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51732 - Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 all
CVE-2026-51731 - Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau
CVE-2026-14697 - net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitat
CVE-2026-13732 - A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/sta
CVE-2026-83497 - Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch
CVE-2026-82821 - A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the functio
CVE-2026-82820 - A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the fil
CVE-2026-82818 - A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the fi
CVE-2026-72001 - Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated a
CVE-2026-53553 - Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traver
CVE-2026-53552 - Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile
CVE-2026-53508 - oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs
CVE-2026-53507 - oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review o
CVE-2026-14696 - When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys
CVE-2026-14368 - The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a par
CVE-2026-14367 - The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes throu
CVE-2023-31308 - A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of
CVE-2023-20511 - Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker
CVE-2026-82817 - A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown func
CVE-2026-82816 - A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an u
CVE-2026-82815 - A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file
CVE-2026-82813 - A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. Thi
CVE-2026-82811 - A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects a
CVE-2026-79750 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79749 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79748 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79747 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79746 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79745 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79744 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-79743 - MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP
CVE-2026-51730 - Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51729 - Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unaut
CVE-2026-51728 - Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 all
CVE-2026-51727 - Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51726 - Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allow
CVE-2026-51725 - Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-19953 - URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via miss
CVE-2026-82810 - A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The im
CVE-2026-82809 - A security flaw has been discovered in vidIQ Vision for YouTube Extension 3.199.0 on Chrome. The aff
CVE-2026-82808 - A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impac
CVE-2026-51724 - Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51723 - Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B20211015 all
CVE-2026-51722 - Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 all
CVE-2026-51721 - Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau
CVE-2026-51720 - Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 a
CVE-2026-17615 - A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker
CVE-2026-14366 - The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx
CVE-2026-83492 - Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affec
CVE-2026-82823 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-82814. Reason:
CVE-2026-82807 - A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown
CVE-2026-82805 - A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of
CVE-2026-82803 - A vulnerability has been found in armink struct2json 1.0. This affects the function S2J_STRUCT_GET_s
CVE-2026-82802 - A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSea
CVE-2026-77975 - The affected Ebyte product exports administrative credentials and other sensitive configuration i
CVE-2026-77966 - The affected Ebyte product does not provide separation between limited and administrative managem
CVE-2026-76133 - The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related oper
CVE-2026-75133 - Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulner
CVE-2026-75132 - WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns`
CVE-2026-73819 - The affected Ebyte product's vendor configuration utility permits access to administrative functi
CVE-2026-51719 - Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allo
CVE-2026-51718 - Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 all
CVE-2026-51717 - Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un
CVE-2026-51716 - Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 al
CVE-2026-51715 - Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allo
CVE-2026-51714 - Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows u
CVE-2026-51713 - Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allow
CVE-2026-51712 - Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51711 - Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
CVE-2026-51710 - Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allow
CVE-2026-51709 - Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware