CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-76634 - WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil
CVE-2026-76633 - WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a
CVE-2026-76632 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-70383 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Esto
CVE-2026-64972 - ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker
CVE-2026-64971 - ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially
CVE-2026-64970 - ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can
CVE-2026-64969 - ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related en
CVE-2026-64968 - ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated admi
CVE-2026-64967 - A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative p
CVE-2026-64966 - ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker
CVE-2026-64965 - ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-pr
CVE-2026-64964 - ATutor generates predictable email confirmation tokens due to the use of insufficiently random value
CVE-2026-64963 - A path traversal vulnerability in ATutor allows an authenticated user to access files from other cou
CVE-2026-64962 - ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attack
CVE-2026-64961 - ATutor is vulnerable to authentication bypass . Although a token validation check is present in the
CVE-2026-64960 - ATutor Gameme module allows users to upload files of any type and extension without restriction. Due
CVE-2026-15706 - Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry
CVE-2026-7485 - Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all
CVE-2026-77118 - A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage()
CVE-2026-76989 - A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13
CVE-2026-76988 - A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This
CVE-2026-76987 - A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892.
CVE-2026-74011 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-28164 - Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Sit
CVE-2026-28163 - Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configu
CVE-2026-21784 - HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security heade
CVE-2026-18482 - Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the
CVE-2025-62306 - HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information b
CVE-2025-62300 - HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur w
CVE-2025-62299 - HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow
CVE-2026-77085 - n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent t
CVE-2026-77084 - n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the
CVE-2026-77083 - n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaSc
CVE-2026-77082 - n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denia
CVE-2026-77081 - n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in t
CVE-2026-77080 - n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and
CVE-2026-77079 - n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (r
CVE-2026-77077 - n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape.
CVE-2026-77076 - n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in
CVE-2026-77075 - n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vul
CVE-2026-77074 - n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image n
CVE-2026-77073 - n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_co
CVE-2026-77072 - n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the
CVE-2026-77071 - n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the S
CVE-2026-77070 - n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node
CVE-2026-77069 - n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential
CVE-2026-77068 - n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n
CVE-2026-74021 - Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
CVE-2026-74020 - Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
CVE-2026-74019 - Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
CVE-2026-74018 - Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
CVE-2026-74016 - Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
CVE-2026-74014 - Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVE-2026-74013 - Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
CVE-2026-74001 - Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-73998 - Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
CVE-2026-73993 - Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-73992 - Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-73402 - Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
CVE-2026-68566 - Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-68564 - Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
CVE-2026-66682 - Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-66680 - Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66677 - Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
CVE-2026-66673 - Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
CVE-2026-66672 - Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
CVE-2026-66649 - Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2026-66647 - Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
CVE-2026-66616 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-66615 - Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
CVE-2026-66614 - Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
CVE-2026-66612 - Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
CVE-2026-66611 - Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
CVE-2026-66609 - Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-66607 - Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
CVE-2026-66606 - Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
CVE-2026-66605 - Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products
CVE-2026-66604 - Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
CVE-2026-66601 - Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66600 - Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66598 - Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
CVE-2026-66597 - Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
CVE-2026-66595 - Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
CVE-2026-66594 - Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-66593 - Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66592 - Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2026-66590 - Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
CVE-2026-66586 - Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-66583 - Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2026-66582 - Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-66581 - Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
CVE-2026-28150 - Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
CVE-2025-62307 - HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weak
CVE-2025-53999 - Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
CVE-2025-15689 - Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVE-2025-15688 - Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVE-2025-15637 - Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
CVE-2026-77067 - The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied ur
CVE-2026-77066 - The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplie
CVE-2026-77026 - Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.
CVE-2026-73199 - A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a n
CVE-2026-73198 - A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `
CVE-2026-73197 - A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by se
CVE-2026-73196 - A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by su
CVE-2026-13097 - A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri
CVE-2026-11861 - A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Dire
CVE-2026-18917 - A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabil
CVE-2026-77014 - A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator
CVE-2026-76610 - Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment co
CVE-2026-14953 - A low-privileged remote attacker can enumerate all configured users and identify which accounts hold
CVE-2026-14952 - An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the
CVE-2026-14951 - An low privileged remote attacker can cause authenticated users to perform unintended actions in the
CVE-2026-14950 - An unauthenticated remote attacker in possession of a valid session identifier is able to continue u
CVE-2026-14949 - A low privileged remote attacker with a valid session can submit a request to the user creation func
CVE-2026-14948 - A low privileged remote attacker can hijack an active administrative session without needing to know
CVE-2026-14947 - A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal se
CVE-2026-14946 - A high privileged remote attacker can upload a .php file and then request it directly from /uploads/
CVE-2026-76569 - Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1
CVE-2026-76565 - Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Car
CVE-2026-76564 - Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.
CVE-2026-75948 - Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The fronte
CVE-2025-14601 - An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative
CVE-2026-71368 - F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged
CVE-2026-14163 - In affected versions of Octopus Server under certain circumstances it is possible for sensitive vari
CVE-2025-14602 - The application generates uploaded file names using a weak and predictable method based on the reque
CVE-2026-75963 - The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t
CVE-2026-75860 - The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica
CVE-2026-74992 - The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives
CVE-2026-73542 - Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle at
CVE-2026-19699 - The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of i
CVE-2026-19697 - The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the uploa
CVE-2026-19615 - The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG f
CVE-2026-17153 - The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all version
CVE-2026-15049 - The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a
CVE-2026-13405 - The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom
CVE-2026-76957 - libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-
CVE-2026-76956 - In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to ins
CVE-2026-19582 - Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is false due to u
CVE-2026-76800 - A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of th
CVE-2026-76799 - A weakness has been identified in code-projects Login Registration System 1.0. This affects an unkno
CVE-2026-76795 - A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of th
CVE-2026-76785 - A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Aff
CVE-2026-76783 - A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown
CVE-2026-75628 - Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login be
CVE-2026-8619 - An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150
CVE-2026-76764 - A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un
CVE-2026-76762 - A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an
CVE-2022-4996 - A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing
CVE-2026-76929 - Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76928 - X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76927 - H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76926 - BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76924 - Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76923 - Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial o
CVE-2026-76922 - Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of
CVE-2026-76921 - CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76920 - 3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76919 - ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76918 - SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76917 - Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial
CVE-2026-76891 - Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76890 - Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76889 - UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76888 - RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76887 - Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of serv
CVE-2026-76886 - C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76885 - Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76884 - ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76883 - Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76882 - Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of
CVE-2026-76881 - CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76880 - RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76879 - C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
CVE-2026-76761 - A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExe
CVE-2026-76760 - A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the f
CVE-2026-19563 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19562 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19561 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18862 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18502 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-76878 - In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects q
CVE-2026-76850 - LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine
CVE-2026-76832 - Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that al
CVE-2026-76591 - A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function
CVE-2026-76590 - A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some
CVE-2026-76589 - A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000
CVE-2026-76405 - In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the
CVE-2026-76404 - In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execut
CVE-2026-76403 - In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network
CVE-2026-76402 - In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Co
CVE-2026-76401 - In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Co
CVE-2026-76400 - In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Co
CVE-2026-76399 - In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app
CVE-2026-76398 - In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk ro
CVE-2026-76397 - In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and
CVE-2026-76396 - In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capabil
CVE-2026-76395 - In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute ar
CVE-2026-76394 - In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "p
CVE-2026-76393 - In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model bein
CVE-2026-76392 - In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk ro
CVE-2026-76391 - In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk ro
CVE-2026-76390 - In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated u
CVE-2026-76389 - In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a
CVE-2026-76388 - In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterpri
CVE-2026-76387 - In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security ro
CVE-2026-76386 - In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to
CVE-2026-76385 - In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission t
CVE-2026-76384 - In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a
CVE-2026-76383 - In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who ho
CVE-2026-76382 - In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission
CVE-2026-76381 - In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a
CVE-2026-76380 - In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role wi
CVE-2026-76379 - In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permiss
CVE-2026-76378 - In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds
CVE-2026-76377 - In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with perm
CVE-2026-76376 - In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission
CVE-2026-76375 - In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission
CVE-2026-76374 - In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission
CVE-2026-76373 - In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission
CVE-2026-76372 - In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playboo
CVE-2026-76371 - In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in
CVE-2026-76370 - In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use t
CVE-2026-76369 - In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outsi
CVE-2026-76368 - In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permis
CVE-2026-76367 - In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role coul
CVE-2026-76366 - In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representatio
CVE-2026-76365 - In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role cou
CVE-2026-76364 - In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role cou
CVE-2026-76363 - In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbit
CVE-2026-76362 - In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffi
CVE-2026-76361 - In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/suppor
CVE-2026-76360 - In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest
CVE-2026-76359 - In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversa
CVE-2026-76358 - In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal dur
CVE-2026-76357 - In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a craf
CVE-2026-76356 - In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a
CVE-2026-76355 - In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the informat
CVE-2026-76354 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76353 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76352 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76351 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
CVE-2026-76350 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit
CVE-2026-76349 - In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could trick
CVE-2026-76348 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk ro
CVE-2026-76347 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway ve
CVE-2026-76346 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"
CVE-2026-76345 - In Splunk Enterprise versions below 10.4.2, a user with a high-privilege Splunk role that can manage
CVE-2026-76344 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
CVE-2026-76343 - In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware