CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-48527 - HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26
CVE-2026-45611 - Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-45551 - Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25,
CVE-2026-45312 - RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinj
CVE-2026-45043 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validat
CVE-2026-10071 - DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticat
CVE-2026-9811 - A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic
CVE-2026-9809 - A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When
CVE-2026-9808 - An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platfor
CVE-2026-9559 - A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting up
CVE-2025-41281 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41280 - Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX
CVE-2025-41279 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41278 - Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version
CVE-2025-41277 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41276 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41275 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41274 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41273 - Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel
CVE-2025-41272 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41271 - Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall
CVE-2025-41270 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41269 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41268 - Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Wat
CVE-2025-41267 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41266 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2025-41265 - Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS
CVE-2026-9558 - A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform
CVE-2026-9557 - A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insuff
CVE-2026-49201 - The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryptio
CVE-2026-46579 - A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Al
CVE-2026-42965 - A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vu
CVE-2026-10078 - A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensiti
CVE-2025-12714 - The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unau
CVE-2026-9189 - The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via
CVE-2026-6075 - The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers
CVE-2026-49200 - The acer_cgi.log file in the device firmware is accessible without authentication via the web interf
CVE-2026-49199 - Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the t
CVE-2026-49198 - Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT tr
CVE-2026-49197 - Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, f
CVE-2026-49196 - The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execut
CVE-2026-49195 - Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authenti
CVE-2026-10058 - ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerabi
CVE-2026-10057 - ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerabi
CVE-2026-10056 - CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when run
CVE-2026-10052 - A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with conf
CVE-2026-10039 - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the
CVE-2026-9243 - The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-4776 - An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficie
CVE-2026-49322 - Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tec
CVE-2026-3655 - The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authenticati
CVE-2025-11262 - The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user
CVE-2026-9714 - The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-9493 - Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vul
CVE-2026-8732 - The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account
CVE-2026-6324 - A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error
CVE-2026-6275 - The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Si
CVE-2025-14042 - The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-S
CVE-2025-11993 - The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object
CVE-2026-2128 - The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorize
CVE-2026-8995 - The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Se
CVE-2026-7430 - The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions
CVE-2026-8070 - Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypa
CVE-2026-7480 - An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interf
CVE-2026-6892 - Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a
CVE-2026-6891 - Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or e
CVE-2026-9999 - Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remo
CVE-2026-9998 - Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-9997 - Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9996 - Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attack
CVE-2026-9995 - Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9994 - Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9993 - Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9992 - Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec
CVE-2026-9991 - Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a
CVE-2026-9990 - Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote at
CVE-2026-9989 - Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9988 - Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9987 - Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 14
CVE-2026-9986 - Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778
CVE-2026-9985 - Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778
CVE-2026-9984 - Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker t
CVE-2026-9983 - Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9982 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9981 - Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9980 - Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allo
CVE-2026-9979 - Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9978 - Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9977 - Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.77
CVE-2026-9976 - Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attack
CVE-2026-9975 - Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9974 - Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha
CVE-2026-9973 - Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec
CVE-2026-9972 - Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attack
CVE-2026-9971 - Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote
CVE-2026-9970 - Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9969 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9968 - Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9967 - Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to pot
CVE-2026-9966 - Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9965 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to p
CVE-2026-9964 - Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who
CVE-2026-9963 - Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker w
CVE-2026-9962 - Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execu
CVE-2026-9961 - Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9960 - Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha
CVE-2026-9959 - Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak
CVE-2026-9958 - Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to poten
CVE-2026-9957 - Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9956 - Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9955 - Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote
CVE-2026-9954 - Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who co
CVE-2026-9953 - Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to ob
CVE-2026-9952 - Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exe
CVE-2026-9951 - Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potential
CVE-2026-9950 - Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 al
CVE-2026-9949 - Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9948 - Use after free in Views in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker wh
CVE-2026-9947 - Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9946 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9945 - Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9944 - Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha
CVE-2026-9943 - Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
CVE-2026-9942 - Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha
CVE-2026-9941 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9940 - Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to
CVE-2026-9939 - Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9938 - Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9937 - Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker w
CVE-2026-9936 - Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9935 - Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to lea
CVE-2026-9934 - Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convin
CVE-2026-9933 - Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convi
CVE-2026-9932 - Use after free in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9931 - Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had com
CVE-2026-9930 - Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9929 - Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a
CVE-2026-9928 - Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote att
CVE-2026-9927 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9926 - Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9925 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9924 - Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote a
CVE-2026-9923 - Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti
CVE-2026-9922 - Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9921 - Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9920 - Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attack
CVE-2026-9919 - Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
CVE-2026-9918 - Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9917 - Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9916 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9915 - Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9914 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9913 - Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9912 - Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a re
CVE-2026-9911 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perf
CVE-2026-9910 - Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9909 - Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-9908 - Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to ob
CVE-2026-9907 - Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9906 - Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha
CVE-2026-9905 - Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote
CVE-2026-9904 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potent
CVE-2026-9903 - Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.21
CVE-2026-9902 - Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker w
CVE-2026-9901 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9900 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9899 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9898 - Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.21
CVE-2026-9897 - Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9896 - Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec
CVE-2026-9895 - Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-9894 - Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had com
CVE-2026-9893 - Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had co
CVE-2026-9892 - Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a r
CVE-2026-9891 - Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9890 - Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker w
CVE-2026-9889 - Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a r
CVE-2026-9888 - Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9887 - Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9886 - Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to
CVE-2026-9885 - Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 all
CVE-2026-9884 - Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9883 - Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9882 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak
CVE-2026-9881 - Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who
CVE-2026-9880 - Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9879 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to e
CVE-2026-9878 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9877 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9876 - Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9875 - Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
CVE-2026-9874 - Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti
CVE-2026-9873 - Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec
CVE-2026-9872 - Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
CVE-2026-8809 - The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via
CVE-2026-6816 - An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users pe
CVE-2026-5343 - Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Prov
CVE-2026-10028 - A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting
CVE-2026-10022 - Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a us
CVE-2026-10021 - Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a
CVE-2026-10020 - Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.2
CVE-2026-10019 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak
CVE-2026-10018 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obta
CVE-2026-10017 - Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker wh
CVE-2026-10016 - Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-10015 - Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-10014 - Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attac
CVE-2026-10013 - Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to ex
CVE-2026-10012 - Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had co
CVE-2026-10011 - Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-10010 - Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a
CVE-2026-10009 - Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-10008 - Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attack
CVE-2026-10007 - Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-10006 - Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbit
CVE-2026-10005 - Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote at
CVE-2026-10004 - Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 all
CVE-2026-10003 - Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convi
CVE-2026-10002 - Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to poten
CVE-2026-10001 - Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-10000 - Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote att
CVE-2026-49299 - In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on si
CVE-2026-48116 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-47713 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-45410 - TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login f
CVE-2026-45403 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-45366 - typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vu
CVE-2026-45364 - Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0
CVE-2026-45344 - LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database config
CVE-2026-45343 - LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored
CVE-2026-45342 - LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insec
CVE-2026-45023 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-44973 - Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues
CVE-2026-44885 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44884 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44883 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44882 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44881 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44850 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44849 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44848 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-39929 - Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-
CVE-2026-10044 - Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GE
CVE-2026-9646 - A reflected cross-site scripting issue exists in URL handling.
CVE-2026-9645 - Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the ser
CVE-2026-49095 - Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to p
CVE-2026-49094 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Al
CVE-2026-49093 - Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector manag
CVE-2026-46843 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-46842 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.