CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
1412 CVEs gefunden (Seite 1/6)

CVE-2026-74250 - In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediat

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-74247 - A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write acc

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-74245 - A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid f

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-74244 - A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unau

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-74243 - A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a re

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-63650 - OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-63649 - The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-18932 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-73683 - Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows un

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-74248 - OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associ

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-73682 - Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerabili

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-73680 - Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration th

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-64887 - Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-39925 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-34492 - External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipu

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-27871 - Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 all

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-19910 - PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnera

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-19909 - PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnera

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-19908 - PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-18554 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-18178 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitra

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-17227 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-17209 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitr

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-17186 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL command

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-17184 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due t

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-17182 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and ob

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-17181 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary loc

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.3
9.3

CVE-2026-17179 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-17177 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-17175 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-17173 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-17081 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-17079 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-16915 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-16905 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-16879 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-16708 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.3
8.3

CVE-2026-73679 - ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module th

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-73678 - MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 10.0
10.0

CVE-2026-50029 - js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a ke

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-50027 - mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-49457 - erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not au

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-45699 - Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-19188 - A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gate

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 10.0
10.0

CVE-2026-18403 - LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Cent

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2025-7639 - The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Opera

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-73850 - Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vul

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-73849 - Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-73847 - Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on t

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-63361 - LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerab

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-49282 - Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name(

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.1
5.1

CVE-2026-49263 - Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend a

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-19847 - A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the functi

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-19846 - A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-19682 - A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-19681 - An authenticated command injection vulnerability exists in Security Center related to file upload pr

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-19680 - A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-19679 - An input validation vulnerability exists in Security Center's file upload handling, where insufficie

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-19639 - An improper access control vulnerability exists where an authenticated non-administrative applicatio

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-19636 - An issue was identified in which CSRF tokens were generated using a predictable method, potentially

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-19635 - A local privilege escalation vulnerability exists in Security Center. An attacker with write access

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-19631 - A SQL injection vulnerability exists in Security Center that could allow an authenticated administra

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-19629 - A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-12366 - Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-12365 - A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling o

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 5.8
5.8

CVE-2026-12364 - The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 8.4
8.4

CVE-2026-12363 - The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does

🏢 Sonstige 📅 14.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-48926 - Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-48925 - A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and ear

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-48924 - Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allo

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-48923 - Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implemen

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-48922 - Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file na

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-48921 - Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbol

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-48920 - Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-48919 - Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without valid

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.6
6.6

CVE-2026-48918 - Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.6
6.6

CVE-2026-48917 - Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without vali

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.6
6.6

CVE-2026-48916 - Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.6
6.6

CVE-2026-48545 - Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.8
6.8

CVE-2026-48544 - Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-47119 - Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows atta

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2026-47118 - Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated a

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-45571 - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alp

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-45570 - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alp

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.6
9.6

CVE-2026-45022 - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alp

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-44972 - GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes a

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.0
5.0

CVE-2026-44971 - GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic re

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.2
8.2

CVE-2026-44902 - opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP r

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-44839 - RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerabi

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.8
4.8

CVE-2026-44838 - RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin all

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-44830 - Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. P

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-42280 - Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific precon

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42184 - Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a fl

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-37713 - An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker t

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-37712 - An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker t

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-37711 - An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker t

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-31266 - Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-30498 - A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.3
6.3

CVE-2026-1248 - IBM Business Automation Workflow containers and traditional may leak information about its database

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2025-70103 - Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::Decod

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-9704 - A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerabili

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.8
6.8

CVE-2026-9035 - IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tra

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-8405 - IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-8180 - IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tra

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-8179 - IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tra

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-8175 - IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tra

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-7876 - IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability.

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-7528 - IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource co

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-7524 - IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-7365 - IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default pa

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-7254 - IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticate

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-6938 - IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote objec

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-6936 - IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursio

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-6053 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-6052 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-6051 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when e

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-5516 - IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Serv

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.4
4.4

CVE-2026-5515 - IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-5065 - IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a passwor

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-4410 - IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application S

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.8
4.8

CVE-2026-48972 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-48971 - Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploi

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-47104 - libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.0
4.0

CVE-2026-45992 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-42791 - Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows f

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 3.7
3.7

CVE-2026-3623 - IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-3366 - IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-38427 - An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-38426 - Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to e

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-38422 - Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to e

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36540 - Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36539 - Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the en

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36538 - Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sam

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36045 - picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-36044 - @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The creat

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-35090 - In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticate

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-35089 - In Slican telephone exchanges secure key is generated in a predictable manner using properties of th

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-35087 - Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypa

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-2607 - IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.1
5.1

CVE-2026-2340 - A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-23679 - libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.2
6.2

CVE-2026-1933 - A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read onl

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-1718 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2025-3633 - IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 1

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.4
5.4

CVE-2024-56462 - IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malici

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.2
7.2

CVE-2024-40684 - IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.9
5.9

CVE-2024-28765 - IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 cou

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-9689 - A flaw was found in Keycloak, an open-source identity and access management solution. When a client

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.2
4.2

CVE-2026-48906 - The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affec

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-42762 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42761 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-42760 - Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-42759 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42758 - Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ign

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-42757 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sale

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42756 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludw

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42755 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-42754 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42753 - Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Ex

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-42751 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42750 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42749 - Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42748 - Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo all

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42747 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-42746 - Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Cl

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-42745 - Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.3
7.3

CVE-2026-42744 - Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads qu

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42740 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-42739 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42738 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42737 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jv

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.6
8.6

CVE-2026-42736 - Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-bet

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-42735 - Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kiv

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.2
8.2

CVE-2026-42734 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42733 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42732 - Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads qu

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42731 - Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-ot

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-42730 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.5
8.5

CVE-2026-42729 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42728 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-42727 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-42725 - Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-3012 - A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.0
8.0

CVE-2026-8054 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-49002 - Access control failure means that an application does not effectively check user access permissions,

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-48968 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-48877 - Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retriev

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40852 - A highly authenticated attacker can alter the config generator injecting a payload into future creat

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.2
7.2

CVE-2026-40851 - A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40850 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40849 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40848 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40847 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40846 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40845 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40844 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40843 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40842 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40841 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40840 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40839 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40838 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40837 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40836 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-40835 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40834 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-40833 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-40832 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40831 - An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-40830 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-40829 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-40828 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-40827 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-2237 - A use of get request method with sensitive query strings vulnerability in volume encryption of Synol

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.2
6.2

CVE-2025-66593 - An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2025-66592 - An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2025-52747 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2025-30028 - A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.6
8.6

CVE-2025-22741 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.1
7.1

CVE-2025-14713 - An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2025-13593 - Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.1
6.1

CVE-2025-13392 - Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Ma

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 8.1
8.1

CVE-2025-13167 - Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.4
5.4

CVE-2025-12686 - Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 9.8
9.8

CVE-2025-10466 - Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability i

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.9
5.9

CVE-2024-47272 - Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station be

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 2.7
2.7

CVE-2024-47271 - Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance S

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2024-47270 - Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surve

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 2.7
2.7

CVE-2024-47269 - Cleartext transmission of sensitive information vulnerability in Export Key functionality in Synolog

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2024-47268 - Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2024-47267 - Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Arch

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 2.7
2.7

CVE-2024-11399 - Files or directories accessible to external parties vulnerability in redis-server component in Synol

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 6.8
6.8

CVE-2023-52945 - Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for des

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-49001 - Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-41704 - AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (l

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.0
5.0

CVE-2026-41009 - When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is con

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.8
5.8

CVE-2026-40826 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-40825 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-40824 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-40823 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-40822 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-40821 - A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 4.9
4.9

CVE-2026-40819 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40818 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40817 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40816 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40815 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40814 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40813 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-40812 - An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the

🏢 Sonstige 📅 27.5.2026 📊 CVSS: 7.5
7.5
Seite 1 von 6 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.