CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2019-25744 - WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows au
CVE-2019-25743 - WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows
CVE-2019-25742 - WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability tha
CVE-2019-25741 - Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerab
CVE-2019-25740 - Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated
CVE-2019-25739 - GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attac
CVE-2019-25738 - WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allow
CVE-2019-25737 - Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthent
CVE-2019-25736 - LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to
CVE-2019-25735 - AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers t
CVE-2019-25734 - Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local fi
CVE-2019-25733 - NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that a
CVE-2019-25732 - PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers t
CVE-2019-25731 - Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated a
CVE-2019-25730 - Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to
CVE-2019-25729 - PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated a
CVE-2019-25728 - Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to e
CVE-2019-25727 - WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows
CVE-2019-25726 - All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated
CVE-2026-4104 - Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Auto
CVE-2026-45432 - This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plai
CVE-2026-45431 - This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in
CVE-2026-10843 - A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator
CVE-2026-10840 - A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBi
CVE-2026-10804 - A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the lib
CVE-2026-10803 - A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_uti
CVE-2026-10802 - A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unkno
CVE-2025-52612 - HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflect
CVE-2025-52611 - HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The
CVE-2025-52609 - HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site script
CVE-2025-52608 - HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the appl
CVE-2025-52606 - HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during imp
CVE-2025-12694 - A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-a
CVE-2026-49077 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and
CVE-2026-10801 - A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the func
CVE-2026-8916 - Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issu
CVE-2026-50226 - Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization cred
CVE-2026-50225 - The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious
CVE-2026-50224 - The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 withou
CVE-2026-50214 - The /v1/Plan service relies entirely on a shared global API token for full administrative management
CVE-2026-4881 - In affected versions of Octopus Server, permissions were not checked correctly resulting in any auth
CVE-2026-49771 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-49510 - Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks.
CVE-2026-47320 - Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie
CVE-2026-47319 - Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Exce
CVE-2026-47318 - Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. T
CVE-2026-47306 - Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data
CVE-2026-10800 - A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the
CVE-2026-10305 - Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue
CVE-2026-50213 - The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, wh
CVE-2026-50212 - Weak validation logic within device dissociation API routines allows a remote entity to forcefully u
CVE-2026-50211 - Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail buil
CVE-2026-50210 - The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making
CVE-2026-50209 - Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (
CVE-2026-50208 - High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-cod
CVE-2026-50207 - The system Binder boundary accepts unverified pass-through AT commands, giving local applications th
CVE-2026-3820 - There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attack
CVE-2026-50206 - Incoming VPN network profile settings fail to process special characters safely, enabling command in
CVE-2026-50205 - System log files output unencrypted SMTP server authentication passwords alongside sensitive employe
CVE-2026-49204 - Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking as
CVE-2026-49203 - Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization,
CVE-2026-49202 - Internal multimedia session archives are accessible without authentication, exacerbated by loose Cro
CVE-2026-49194 - The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prom
CVE-2026-49193 - Overly permissive configuration settings on cloud storage containers expose active telemetry informa
CVE-2026-49192 - The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user owners
CVE-2026-49191 - The production build of the M3WebServer hard-codes its backend API keys, which can be easily interce
CVE-2026-49190 - The system fails to evaluate instructional permissions over multiple internal operation codes (opcod
CVE-2026-50219 - libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_P
CVE-2026-49189 - Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software c
CVE-2026-49188 - The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(),
CVE-2026-49187 - The hard-coded APK resource files never expire, and the shared scepter leads to information leaks an
CVE-2026-10805 - A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkM
CVE-2026-49186 - The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any clie
CVE-2026-49185 - The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing
CVE-2026-48681 - OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployme
CVE-2026-44917 - OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read loc
CVE-2026-41283 - OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. The
CVE-2026-41010 - ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@re
CVE-2026-8829 - HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS rou
CVE-2026-41860 - CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token reques
CVE-2026-41859 - A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentia
CVE-2026-41858 - Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem
CVE-2026-41011 - PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packa
CVE-2026-10597 - OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unau
CVE-2026-8653 - The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'co
CVE-2026-7764 - An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLi
CVE-2026-10737 - The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a
CVE-2026-8722 - Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric name
CVE-2026-10783 - A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audi
CVE-2026-2596 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-10777 - A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b8
CVE-2026-10775 - A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is
CVE-2026-46447 - OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can se
CVE-2026-22055 - Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated
CVE-2026-22054 - Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authentic
CVE-2026-10771 - A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntit
CVE-2026-50033 - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected:
CVE-2026-44682 - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected:
CVE-2026-44609 - Local privilege escalation due to EXE hijacking vulnerability. The following products are affected:
CVE-2026-43924 - FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the
CVE-2026-42061 - Local privilege escalation due to excessive permissions assigned to child processes. The following p
CVE-2026-40495 - FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 lea
CVE-2026-37700 - Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensiti
CVE-2026-26825 - A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files.
CVE-2026-26824 - libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE contain
CVE-2026-10766 - A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.help
CVE-2026-8889 - Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matchin
CVE-2026-8888 - Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-pr
CVE-2026-8881 - Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a sing
CVE-2026-8879 - Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content sc
CVE-2026-8878 - Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that al
CVE-2026-8876 - Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in secur
CVE-2026-8874 - Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords
CVE-2026-7888 - Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workfl
CVE-2026-45702 - OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel r
CVE-2026-45614 - OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel r
CVE-2026-42840 - An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a
CVE-2026-42839 - An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScrip
CVE-2026-26379 - Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/
CVE-2026-26378 - Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbi
CVE-2026-46273 - In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packet
CVE-2026-46272 - In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race co
CVE-2026-46271 - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads o
CVE-2026-46270 - In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-
CVE-2026-46269 - In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL
CVE-2026-46268 - In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Fix p2pmem_alloc_mm
CVE-2026-46267 - In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers an
CVE-2026-46266 - In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO
CVE-2026-46265 - In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM wa
CVE-2026-46264 - In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initializa
CVE-2026-46263 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bou
CVE-2026-46262 - In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_xcvr: Revert fix miss
CVE-2026-46261 - In the Linux kernel, the following vulnerability has been resolved: spi: wpcm-fiu: Fix potential NU
CVE-2026-46260 - In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access i
CVE-2026-46259 - In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protect
CVE-2026-46258 - In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: Avoid NULL derefere
CVE-2026-46257 - In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804
CVE-2026-46256 - In the Linux kernel, the following vulnerability has been resolved: NFS/localio: prevent direct rec
CVE-2026-46255 - In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: don't expl
CVE-2026-46254 - In the Linux kernel, the following vulnerability has been resolved: AppArmor: Allow apparmor to han
CVE-2026-46253 - In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow
CVE-2026-46252 - In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix locking in
CVE-2026-46251 - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dir
CVE-2026-46250 - In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when
CVE-2026-46249 - In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Fix PF driver cra
CVE-2026-46248 - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link
CVE-2026-46247 - In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to
CVE-2026-46246 - In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix
CVE-2026-46245 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NU
CVE-2026-46244 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6
CVE-2026-40290 - OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel r
CVE-2026-39107 - A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. T
CVE-2026-36618 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries,
CVE-2026-36616 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials
CVE-2026-36615 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset e
CVE-2026-36613 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal
CVE-2026-36612 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lock
CVE-2026-36611 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer w
CVE-2026-36610 - Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext H
CVE-2026-36609 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce t
CVE-2026-36608 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forwar
CVE-2026-36607 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force a
CVE-2026-36606 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with
CVE-2026-36605 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of se
CVE-2026-36604 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host head
CVE-2026-36603 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions wi
CVE-2026-36602 - Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via t
CVE-2026-36460 - Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerabili
CVE-2026-20233 - A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauth
CVE-2026-20230 - A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication
CVE-2026-20175 - A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary f
CVE-2025-71314 - In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panth
CVE-2025-71313 - In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL
CVE-2019-25720 - Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-o
CVE-2026-6657 - A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS o
CVE-2026-44281 - GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versi
CVE-2026-42321 - GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to ver
CVE-2026-42320 - GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versi
CVE-2026-42318 - GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to vers
CVE-2026-42317 - GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versi
CVE-2026-3276 - unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input
CVE-2026-37462 - An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows
CVE-2026-36748 - RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media link
CVE-2026-36576 - An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up
CVE-2026-36574 - A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escal
CVE-2022-31114 - backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of
CVE-2026-8404 - An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.U
CVE-2026-7666 - An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends
CVE-2026-6873 - An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.g
CVE-2026-5241 - A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows
CVE-2026-48587 - An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_va
CVE-2026-47325 - ProjectsAndPrograms school-management-system uses predictable credentials by generating student's an
CVE-2026-47324 - ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in m
CVE-2026-44546 - daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to au
CVE-2026-44545 - daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocke
CVE-2026-37460 - Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.
CVE-2026-35193 - An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.U
CVE-2026-10729 - An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" C
CVE-2025-70101 - An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.
CVE-2025-70100 - A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the
CVE-2025-60477 - A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filt
CVE-2024-47273 - An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in B
CVE-2024-47263 - An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in B
CVE-2023-52951 - A cleartext transmission of sensitive information vulnerability in Synology Note Station Client befo
CVE-2022-49042 - An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in
CVE-2022-49036 - An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration i
CVE-2026-35085 - A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to ga
CVE-2026-35084 - A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain
CVE-2026-35083 - A remote attacker with user privileges can exploit a stack buffer overflow to gain full system acces
CVE-2026-35082 - The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files
CVE-2026-35081 - The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processe
CVE-2026-35080 - The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local f
CVE-2026-35079 - The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files
CVE-2026-35078 - The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local file
CVE-2026-35077 - The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local
CVE-2026-35076 - The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local fi
CVE-2026-35075 - An unauthenticated remote attacker can recover a default, hard coded password from a firmware image
CVE-2026-10722 - A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of
CVE-2025-41259 - SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allo
CVE-2026-47065 - ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Pro
CVE-2026-41032 - It is possible for an unauthenticated adjacent attacker to download log files of the controller, whi
CVE-2025-15656 - Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalati
CVE-2025-15655 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2025-14774 - Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
CVE-2025-14773 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2025-14772 - Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affect
CVE-2025-14771 - Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue aff
CVE-2026-4035 - A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment v
CVE-2025-15654 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-5078 - Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the
CVE-2026-50052 - In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing c
CVE-2026-50031 - ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intell
CVE-2026-10705 - A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of th
CVE-2026-10704 - A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulne
CVE-2026-10703 - A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the func
CVE-2026-9516 - Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input
CVE-2026-9334 - Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when d
CVE-2026-10694 - A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this iss
CVE-2026-10693 - A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Aff
CVE-2026-9732 - The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross
CVE-2026-7421 - The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versi
CVE-2026-10692 - A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function
CVE-2026-10691 - A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts a
CVE-2026-10690 - A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function
CVE-2026-44654 - LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and in
CVE-2026-44653 - LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and in
CVE-2026-42507 - When returning errors, functions in the net/textproto package would include its input as part of the
CVE-2026-42504 - Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessi
CVE-2026-41412 - alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meet
CVE-2026-40108 - GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a techni
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.