CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-108156 - LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the
CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might al
CVE-2026-19359 - A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this is
CVE-2026-11976 - The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server be
CVE-2026-18953 - Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awsla
CVE-2026-70447 - Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Over
CVE-2026-17578 - Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reachin
CVE-2026-49004 - The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command
CVE-2026-18830 - Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remot
CVE-2026-58139 - The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any
CVE-2026-18655 - Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ
CVE-2026-18654 - Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1
CVE-2026-18248 - @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and re
CVE-2026-67322 - GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The
CVE-2026-18536 - Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data:
CVE-2026-18481 - Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might a
CVE-2026-18245 - Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allo
CVE-2026-18140 - Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62
CVE-2026-58222 - A security flaw combining LDAP filter injection and improper authorization checks was found in Samba
CVE-2026-63239 - A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared m
CVE-2026-59931 - PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 th
CVE-2026-48035 - Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure comp
CVE-2026-16796 - Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock Agent
CVE-2026-16756 - Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the de
CVE-2026-16584 - Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 migh
CVE-2026-47695 - CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game.
CVE-2026-15957 - Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers fr
CVE-2026-47394 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw /
CVE-2026-46412 - @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with Op
CVE-2026-47871 - VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation
CVE-2026-56741 - JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3
CVE-2026-50163 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/u
CVE-2026-15415 - AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow en
CVE-2026-12283 - Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amaz
CVE-2026-33731 - WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook h
CVE-2026-15737 - AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for bui
CVE-2025-45870 - LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOf
CVE-2026-56454 - HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TL
CVE-2026-15895 - OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allo
CVE-2026-15738 - Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Con
CVE-2026-15643 - AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that en
CVE-2026-15508 - A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_ta
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware