CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-103220 - The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bound
CVE-2026-101130 - The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bound
CVE-2026-101094 - The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incom
CVE-2026-62042 - Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exp
CVE-2026-62041 - Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploit
CVE-2026-62040 - Missing Authorization vulnerability in DEV Institute Restrict User Access – Membership Plugin with F
CVE-2026-62039 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-62036 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in AREOI Al
CVE-2026-39779 - Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorre
CVE-2026-107419 - Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translatio
CVE-2026-71575 - The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a m
CVE-2026-96809 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-96761 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-96671 - Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-f
CVE-2026-96607 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-96553 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-96539 - Incorrect Privilege Assignment vulnerability in Ultimate Member Ultimate Member ultimate-member allo
CVE-2026-96518 - Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting
CVE-2026-96461 - Missing Authorization vulnerability in TMS Amelia ameliabooking allows Exploiting Incorrectly Config
CVE-2026-96337 - Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting
CVE-2026-96336 - Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Sp
CVE-2026-96334 - Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploit
CVE-2026-96333 - Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identit
CVE-2026-96332 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-96331 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-96330 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-96329 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-96328 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-96327 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-95610 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-95609 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-95608 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-95607 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-95599 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-95598 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-95597 - Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploit
CVE-2026-95596 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-95591 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-95589 - Missing Authorization vulnerability in Magepeople inc. Deposits and Partial Payments for WooCommerce
CVE-2026-94668 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94667 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94666 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zeal
CVE-2026-94665 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94664 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-
CVE-2026-94663 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-94661 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94641 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94632 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94568 - Deserialization of Untrusted Data vulnerability in WP Hosting AS Pay with Vipps for WooCommerce woo-
CVE-2026-94503 - Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Uploa
CVE-2026-94415 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94170 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94167 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94166 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94161 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94159 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-94158 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-93947 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-71884 - In Bouncy Castle for Java LTS before 2.73.13, the native one-shot CTR packet cipher did not check th
CVE-2026-62049 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-107935 - A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-ta
CVE-2026-107655 - A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service
CVE-2026-97075 - Missing Authorization vulnerability in WP Media WP Rocket wp-rocket allows Exploiting Incorrectly Co
CVE-2026-4264 - Reflected Cross-Site Scripting (XSS) on the BeeTienda e-commerce platform, specifically in the lates
CVE-2026-19575 - The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in ke
CVE-2026-19574 - The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare ro
CVE-2026-19571 - The ITE IT8xxx2 SHI host-command backend (subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_i
CVE-2026-19570 - The LE Audio Broadcast Sink in subsys/bluetooth/audio/bap_broadcast_sink.c copies subgroup metadata
CVE-2026-19569 - dynamic_object_create() in kernel/userspace/userspace.c computed the backing allocation for a dynami
CVE-2026-106155 - In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vul
CVE-2026-106145 - In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in
CVE-2026-77680 - An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after
CVE-2026-77357 - Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, ap
CVE-2026-75465 - The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Acce
CVE-2026-75421 - aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.
CVE-2026-72924 - GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the loca
CVE-2026-65091 - NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS
CVE-2026-65088 - NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using v
CVE-2026-65087 - NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected cred
CVE-2026-55588 - ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORA
CVE-2026-53965 - The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In ve
CVE-2026-52491 - An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary
CVE-2026-52489 - Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to
CVE-2026-51368 - An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter comp
CVE-2026-39113 - Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil c
CVE-2026-77585 - The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH
CVE-2026-68515 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-68514 - OpenEXR is the reference implementation and specification for the EXR image file format, widely used
CVE-2026-68513 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-65367 - A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS
CVE-2026-64705 - A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and i
CVE-2026-59981 - OpenEXR is the reference implementation and specification for the EXR image file format, widely used
CVE-2026-55099 - icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 u
CVE-2026-45019 - Chainlit is a Python framework for building production-ready conversational AI applications. From 2.
CVE-2026-45018 - Chainlit is a Python framework for building production-ready conversational AI applications. From 2.
CVE-2026-43670 - A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. T
CVE-2026-43657 - A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and
CVE-2026-80050 - ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to mul
CVE-2026-80049 - Airbyte Platform resolves the workspace used for its authorization decision from a field the caller
CVE-2026-79788 - In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required
CVE-2026-79786 - Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically va
CVE-2026-78379 - Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Ag
CVE-2026-65979 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-62986 - OpenEXR is the reference implementation and specification for the EXR image file format, widely used
CVE-2026-61555 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59985 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55663 - mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm packag
CVE-2026-55620 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-55619 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-55618 - eml_parser serves as a python module for parsing eml files and returning various information found i
CVE-2026-55609 - sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant s
CVE-2026-80051 - github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variabl
CVE-2026-79992 - A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing mal
CVE-2026-76198 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to
CVE-2026-76189 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-75770 - Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-75769 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75768 - Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arb
CVE-2026-75767 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75766 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75752 - Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosu
CVE-2026-75750 - Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-75749 - Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-71564 - Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi
CVE-2026-71444 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-71443 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result
CVE-2026-71442 - CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
CVE-2026-71441 - Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sens
CVE-2026-71382 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-71360 - CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could
CVE-2026-59984 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59983 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59982 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55637 - genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transp
CVE-2026-55623 - Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-55419 - Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exp
CVE-2026-48433 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48432 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48431 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48430 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48429 - Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in
CVE-2026-48428 - Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i
CVE-2026-48427 - Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi
CVE-2026-48426 - Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi
CVE-2026-48425 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48424 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48423 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48422 - Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in
CVE-2026-48421 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48420 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48419 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48418 - Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit
CVE-2026-48417 - Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result i
CVE-2026-26211 - Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the log
CVE-2026-78468 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78270. Reason:
CVE-2026-75498 - Webkul QloApps does not validate request parameters before a database query. A remote, authenticated
CVE-2026-75497 - Webkul QloApps does not validate request parameters before a database query. A remote, authenticated
CVE-2026-75496 - Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before m
CVE-2026-64204 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-64203 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-64202 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-64201 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-59189 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59187 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59186 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-59184 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-55585 - QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, to
CVE-2026-55571 - djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe
CVE-2026-55557 - browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2,
CVE-2026-55553 - urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other re
CVE-2026-47626 - NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could
CVE-2026-47624 - NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privile
CVE-2026-24263 - NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could
CVE-2026-24262 - NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could
CVE-2026-24225 - NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be a
CVE-2026-24170 - NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where a
CVE-2026-24169 - NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated
CVE-2026-24168 - NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker
CVE-2026-24167 - NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authentica
CVE-2026-24166 - NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacke
CVE-2026-19913 - The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to
CVE-2026-19912 - The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vuln
CVE-2026-18445 - There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered i
CVE-2026-18444 - There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images
CVE-2026-16234 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-16233 - There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info
CVE-2026-13478 - The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ex
CVE-2026-13217 - The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the
CVE-2026-13216 - The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during dri
CVE-2026-79785 - X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anyla
CVE-2026-79784 - Vocos instantiates a class named by a configuration file without restricting which class may be name
CVE-2026-79783 - rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metada
CVE-2026-79781 - rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read
CVE-2026-79780 - rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 re
CVE-2026-79779 - rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Ba
CVE-2026-79778 - rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler
CVE-2026-79777 - rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Att
CVE-2026-79776 - rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-clos
CVE-2026-79775 - rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vuln
CVE-2026-79774 - Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability
CVE-2026-79773 - Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter fil
CVE-2026-79772 - Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicali
CVE-2026-79771 - Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when p
CVE-2026-79770 - Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the
CVE-2026-79769 - Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protec
CVE-2026-79676 - NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen roo
CVE-2026-79675 - NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in th
CVE-2026-79674 - NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructor
CVE-2026-70550 - An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticat
CVE-2026-70548 - Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Art
CVE-2026-55640 - Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud ins
CVE-2026-55582 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0
CVE-2026-55581 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0
CVE-2026-55580 - mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0
CVE-2026-55546 - QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() i
CVE-2026-55539 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function
CVE-2026-55536 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connectio
CVE-2026-55533 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows
CVE-2026-55532 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin
CVE-2025-71407 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-71406 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2025-71346 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2024-58378 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2024-58377 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2023-54354 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-51000 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-50999 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2022-50998 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2021-47996 - Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-79717 - A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server
CVE-2026-70551 - A user who can read an existing remote VCS repository can replace its configured origin or supply an
CVE-2026-69104 - An authenticated user may initiate repository migration operations without required repository permi
CVE-2026-55624 - MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba
CVE-2026-55541 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and prais
CVE-2026-55540 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses
CVE-2026-55538 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses co
CVE-2026-55537 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhoo
CVE-2026-55535 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_ur
CVE-2026-55534 - PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents
CVE-2026-55531 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post han
CVE-2026-55530 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the
CVE-2026-55529 - PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_or
CVE-2026-55528 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server
CVE-2026-55527 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor
CVE-2026-55526 - PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc
CVE-2026-16599 - GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The
CVE-2026-16286 - Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Comput
CVE-2026-15310 - When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use
CVE-2026-79655 - A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a
CVE-2026-79623 - A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element
🏢 CVE nach Hersteller
Empfohlene IT-Security & Netzwerk-Hardware
Von NetzBastion getestete & empfohlene Sicherheits- und Netzwerk-Hardware