CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
57 CVEs gefunden (Seite 1/1)

CVE-2026-108096 - Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in

🏢 Aws 📅 9.10.2026 📊 CVSS: 6.5
6.5

CVE-2026-108156 - LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the

🏢 Aws 📅 9.10.2026 📊 CVSS: 7.1
7.1

CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might al

🏢 Aws 📅 9.10.2026 📊 CVSS: 5.9
5.9

CVE-2026-79787 - Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configurat

🏢 Aws 📅 25.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-79782 - rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes sche

🏢 Aws 📅 25.8.2026 📊 CVSS: 3.1
3.1

CVE-2026-21752 - HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker una

🏢 Aws 📅 24.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-77810 - In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain ac

🏢 Aws 📅 21.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-75910 - Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Fede

🏢 Aws 📅 20.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-50173 - Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps

🏢 Aws 📅 19.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-74240 - A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and

🏢 Aws 📅 14.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-73658 - Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4

🏢 Aws 📅 13.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-63299 - An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level di

🏢 Aws 📅 12.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-19643 - An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some pla

🏢 Aws 📅 12.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-19642 - An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow

🏢 Aws 📅 12.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-10579 - A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged

🏢 Aws 📅 11.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-68872 - The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon prov

🏢 Aws 📅 10.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-19359 - A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this is

🏢 Aws 📅 9.8.2026 📊 CVSS: 4.7
4.7

CVE-2026-11976 - The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa

🏢 Aws 📅 6.8.2026 📊 CVSS: 10.0
10.0

CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server be

🏢 Aws 📅 5.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-18953 - Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awsla

🏢 Aws 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-70447 - Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Over

🏢 Aws 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-17578 - Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reachin

🏢 Aws 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-49004 - The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command

🏢 Aws 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-18830 - Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remot

🏢 Aws 📅 4.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-58139 - The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any

🏢 Aws 📅 3.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-18655 - Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ

🏢 Aws 📅 3.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-18654 - Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1

🏢 Aws 📅 3.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-18248 - @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and re

🏢 Aws 📅 3.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-67322 - GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The

🏢 Aws 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-18536 - Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data:

🏢 Aws 📅 1.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-18481 - Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might a

🏢 Aws 📅 31.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-18245 - Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allo

🏢 Aws 📅 30.7.2026 📊 CVSS: 9.0
9.0

CVE-2026-18140 - Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62

🏢 Aws 📅 30.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-58222 - A security flaw combining LDAP filter injection and improper authorization checks was found in Samba

🏢 Aws 📅 30.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-63239 - A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared m

🏢 Aws 📅 29.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-59931 - PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 th

🏢 Aws 📅 28.7.2026 📊 CVSS: 7.7
7.7

CVE-2026-48035 - Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure comp

🏢 Aws 📅 24.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-16796 - Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock Agent

🏢 Aws 📅 23.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-16756 - Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the de

🏢 Aws 📅 23.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-16584 - Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 migh

🏢 Aws 📅 23.7.2026 📊 CVSS: 7.0
7.0

CVE-2026-47695 - CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game.

🏢 Aws 📅 21.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-15957 - Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers fr

🏢 Aws 📅 21.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-47394 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw /

🏢 Aws 📅 21.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-46412 - @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with Op

🏢 Aws 📅 20.7.2026 📊 CVSS: 10.0
10.0

CVE-2026-47871 - VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation

🏢 Aws 📅 18.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-56741 - JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3

🏢 Aws 📅 17.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-50163 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/u

🏢 Aws 📅 17.7.2026 📊 CVSS: 7.1
7.1

CVE-2026-15415 - AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow en

🏢 Aws 📅 17.7.2026 📊 CVSS: 5.5
5.5

CVE-2026-12283 - Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amaz

🏢 Aws 📅 17.7.2026 📊 CVSS: 6.8
6.8

CVE-2026-33731 - WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook h

🏢 Aws 📅 16.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-15737 - AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for bui

🏢 Aws 📅 16.7.2026 📊 CVSS: 5.7
5.7

CVE-2025-45870 - LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOf

🏢 Aws 📅 16.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-56454 - HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TL

🏢 Aws 📅 16.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-15895 - OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allo

🏢 Aws 📅 15.7.2026 📊 CVSS: 7.8
7.8

CVE-2026-15738 - Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Con

🏢 Aws 📅 14.7.2026 📊 CVSS: 8.5
8.5

CVE-2026-15643 - AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that en

🏢 Aws 📅 14.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15508 - A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_ta

🏢 Aws 📅 12.7.2026 📊 CVSS: 6.3
6.3

🏢 CVE nach Hersteller

🛡️

Empfohlene IT-Security & Netzwerk-Hardware

Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware

✓ Geprüfte Qualität
2FA Hardware Key Bestseller

YubiKey 5 NFC (USB-A & NFC)

Verfügbarkeit & Preis prüfen ↗
Juice-Jacking Schutz Impuls-Tipp (~10€)

USB-Datenblocker (USB-Kondom)

Verfügbarkeit & Preis prüfen ↗
Mini Server & Pi-hole Top-Tipp

Raspberry Pi 5 (8GB RAM)

Verfügbarkeit & Preis prüfen ↗
Firewall & Router Netzwerk

UniFi Cloud Gateway Ultra

Verfügbarkeit & Preis prüfen ↗
OPNsense Hardware Profi-Firewall

Protectli Vault 4-Port

Verfügbarkeit & Preis prüfen ↗
MicroSD für Pi / Router Zubehör (~16€)

SanDisk Extreme Pro 128GB

Verfügbarkeit & Preis prüfen ↗
Alle IT-Sicherheit-Produkte bei Amazon durchsuchen → * Als Amazon-Partner verdienen wir an qualifizierten Verkäufen.