CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
16109 CVEs gefunden (Seite 11/65)

CVE-2026-22097 - The firmware update mechanism does not include cryptographic signature validation. This allows anyon

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-22096 - The webserver running on port 8090 does not require authentication. This allows for sensitive inform

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-22095 - The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-22093 - The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the ce

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-15557 - A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15548 - A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affe

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-14846 - In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of e

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-13014 - A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-9708 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 4.9
4.9

CVE-2026-9597 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is dea

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-9571 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-6850 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the len

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-62143 - A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion mod

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-15574 - A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-15547 - A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15546 - A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15545 - A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is t

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-14453 - This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-t

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 9.6
9.6

CVE-2026-10106 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-10103 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post owne

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-10085 - Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the gro

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-57830 - Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.

🏢 Joomla 📅 13.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-57829 - Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Jooml

🏢 Joomla 📅 13.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-4769 - Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability durin

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-15544 - A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15543 - A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the f

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15542 - A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15541 - A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15540 - A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-14165 - An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Editio

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-15539 - A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 4.7
4.7

CVE-2026-15538 - A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the functio

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15537 - A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerabili

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15536 - A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unkno

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-12582 - The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supp

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 8.6
8.6

CVE-2026-12397 - The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employe

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-12396 - The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks bef

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-12275 - The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integrat

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 7.1
7.1

CVE-2026-12274 - The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-12273 - The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target vali

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-12271 - The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-12081 - The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not res

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 5.0
5.0

CVE-2026-11964 - The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity o

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-11963 - The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-10551 - The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Sc

🏢 Wordpress 📅 13.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-15535 - A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99.

🏢 F5 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15533 - A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 4.7
4.7

CVE-2026-15532 - A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects so

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 2.4
2.4

CVE-2026-15531 - A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15530 - A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-9492 - The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYT

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.8
7.8

CVE-2026-7162 - Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve sys

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.8
7.8

CVE-2026-15553 - Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing una

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15552 - Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowi

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-15529 - A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persi

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15528 - A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown proc

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 3.3
3.3

CVE-2026-15527 - A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects u

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15526 - A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProje

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 3.3
3.3

CVE-2026-15525 - A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _v

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15524 - A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 3.3
3.3

CVE-2026-15523 - A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by t

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15522 - A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerabili

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15521 - A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15520 - A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decom

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15519 - A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the fil

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.0
5.0

CVE-2026-15551 - Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

🏢 Samsung 📅 13.7.2026 📊 CVSS: 5.5
5.5

CVE-2026-15518 - A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the functio

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 4.7
4.7

CVE-2026-15517 - A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15516 - A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of t

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 5.6
5.6

CVE-2026-15515 - A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.0
7.0

CVE-2026-15514 - A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affec

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15513 - A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uc

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15512 - A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown f

🏢 Sonstige 📅 13.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15511 - A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerabilit

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-15510 - A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15509 - A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser o

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15508 - A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_ta

🏢 Aws 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15507 - A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown f

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15506 - A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected elemen

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.8
7.8

CVE-2026-15505 - A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 3.5
3.5

CVE-2026-10668 - The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the co

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 2.4
2.4

CVE-2026-10667 - Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c)

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.8
7.8

CVE-2026-10666 - parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-10665 - In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.4
7.4

CVE-2026-10664 - The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drive

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 5.0
5.0

CVE-2026-10663 - In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/us

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-58596 - Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to

🏢 Microsoft 📅 12.7.2026 📊 CVSS: 8.3
8.3

CVE-2026-15502 - A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15501 - A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this iss

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-61876 - LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allo

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-61875 - luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN c

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-61874 - filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in Delet

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 3.1
3.1

CVE-2026-59260 - OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticat

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-56336 - Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /priva

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-56313 - Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prel

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-56308 - Capgo before 12.128.2 allows email address changes without requiring current password re-authenticat

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-56281 - Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoi

🏢 Cloudflare 📅 12.7.2026 📊 CVSS: 3.8
3.8

CVE-2026-56271 - Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-56260 - Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /scr

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-56259 - Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.2
8.2

CVE-2026-56252 - Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint t

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-56241 - Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.3
8.3

CVE-2026-56238 - Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST glo

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-15500 - A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this vulnerability i

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15499 - A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function Fu

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15498 - A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15497 - A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown fun

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15496 - A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the func

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15495 - A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15494 - A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 4.7
4.7

CVE-2026-15493 - A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0ed

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 3.5
3.5

CVE-2026-15492 - A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c64

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-15491 - A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3a

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15490 - A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15489 - A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3a

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15488 - A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileCon

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15487 - A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of th

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15486 - A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15485 - A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15484 - A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function su

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15483 - A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15482 - A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown proces

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15481 - A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15480 - A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15479 - A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function chang

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-15478 - A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15477 - A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalPa

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15476 - A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15475 - A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an u

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-15474 - A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-15473 - A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unkn

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 6.3
6.3

CVE-2026-15472 - A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects u

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-15471 - A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of t

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-15470 - A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is so

🏢 Sonstige 📅 12.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-58281 - Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker

🏢 Microsoft 📅 11.7.2026 📊 CVSS: 8.3
8.3

CVE-2026-10660 - The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-61870 - ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory all

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 2.9
2.9

CVE-2026-61861 - ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption metho

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-61858 - ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 3.3
3.3

CVE-2026-61857 - ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null chec

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 3.7
3.7

CVE-2026-61465 - ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 3.3
3.3

CVE-2026-61454 - The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-61448 - Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0,

🏢 Azure 📅 11.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-61447 - PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python(

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 10.0
10.0

CVE-2026-61445 - PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the A

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 9.9
9.9

CVE-2026-61442 - PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on t

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 7.1
7.1

CVE-2026-61439 - PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-61429 - PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 8.5
8.5

CVE-2026-61428 - PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing una

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 7.3
7.3

CVE-2026-61426 - PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 8.6
8.6

CVE-2026-60090 - PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector a

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-60088 - PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 5.5
5.5

CVE-2026-56763 - Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially c

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 4.8
4.8

CVE-2026-56372 - ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation t

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 3.3
3.3

CVE-2026-56303 - Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value P

🏢 Postgresql 📅 11.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-56296 - Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app R

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-56240 - Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calcu

🏢 Sonstige 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-57828 - Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla ex

🏢 Joomla 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-57827 - Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The J

🏢 Joomla 📅 11.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-1359 - The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modifi

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-9282 - The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to,

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-9017 - The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorizat

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-6939 - The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Sc

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.2
7.2

CVE-2026-6801 - The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-4661 - The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-1382 - The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fresh

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-15155 - The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is v

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-15010 - The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-12994 - The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypa

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-12738 - The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-12126 - The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-12103 - The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all version

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-11901 - The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authent

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-11898 - The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.4
4.4

CVE-2026-11591 - The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via

🏢 Google 📅 11.7.2026 📊 CVSS: 4.4
4.4

CVE-2026-10865 - The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-10041 - The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Ob

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2025-6784 - The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, a

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2025-5017 - The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Inj

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.9
4.9

CVE-2026-7655 - The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in vers

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-13378 - The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.2
7.2

CVE-2026-9738 - The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scrip

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.4
4.4

CVE-2026-7620 - The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all vers

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-7559 - The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-6804 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization byp

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-6803 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authoriza

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-3576 - The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forge

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.2
7.2

CVE-2026-3552 - The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modific

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-2354 - The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-1832 - The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-15335 - The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Par

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-15097 - The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_sl

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-15096 - The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-14262 - The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable t

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-13250 - The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, a

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-13116 - The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Dire

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-12141 - The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vu

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.9
4.9

CVE-2025-13968 - The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Sc

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-8678 - The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-7544 - The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all v

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-5743 - The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scriptin

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.4
6.4

CVE-2026-3367 - The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scri

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.4
4.4

CVE-2026-15338 - The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion i

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-15073 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-15072 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-13353 - The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress i

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-13262 - The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-13114 - The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Store

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 7.2
7.2

CVE-2026-12426 - The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive I

🏢 Oracle 📅 11.7.2026 📊 CVSS: 5.3
5.3

CVE-2026-10628 - The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 4.3
4.3

CVE-2026-13756 - The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 8.8
8.8

CVE-2026-11426 - The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versi

🏢 Wordpress 📅 11.7.2026 📊 CVSS: 6.5
6.5

CVE-2026-55175 - Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-44383 - Multiple connections to the backend using the same charging station ID are allowed, which could all

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-42952 - Previously, there was no throttling on repeated authentication attempts to the charging station bac

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 7.5
7.5

CVE-2026-20744 - The charging station websocket endpoint accepts connections without proper authentication, which co

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-15089 - vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest regis

🏢 Drupal 📅 10.7.2026 📊 CVSS: 9.1
9.1

CVE-2026-15087 - vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-15086 - vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-14480 - OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web U

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 9.9
9.9

CVE-2026-14286 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-11915 - vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-11914 - vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-11913 - vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

🏢 Drupal 📅 10.7.2026 📊 CVSS: 9.8
9.8

CVE-2026-59155 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prio

🏢 Cloudflare 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-58591 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-58590 - Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-58589 - Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-58588 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i

🏢 Drupal 📅 10.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-58587 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i

🏢 Drupal 📅 10.7.2026 📊 CVSS: 6.1
6.1

CVE-2026-58503 - Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration co

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-57584 - Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC applicat

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-55884 - Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-55883 - Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-55882 - Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-55852 - Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was pos

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-55810 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup

🏢 Drupal 📅 10.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-55809 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup

🏢 Drupal 📅 10.7.2026 📊 CVSS: 8.1
8.1

CVE-2026-55808 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.4
5.4

CVE-2026-55807 - Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Fo

🏢 Drupal 📅 10.7.2026 📊 CVSS: 3.1
3.1

CVE-2026-55806 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Conte

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-55804 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-55803 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup

🏢 Drupal 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-55187 - Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped fo

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 5.8
5.8

CVE-2026-54736 - Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-52761 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS

🏢 Apache 📅 10.7.2026 📊 CVSS: 5.8
5.8

CVE-2026-52747 - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS

🏢 Apache 📅 10.7.2026 📊 CVSS: 8.6
8.6

CVE-2026-49844 - Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache

🏢 Apache 📅 10.7.2026 📊 CVSS: 5.9
5.9

CVE-2026-49394 - Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possibl

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 0.0
0.0

CVE-2026-49213 - TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/

🏢 Sonstige 📅 10.7.2026 📊 CVSS: 8.1
8.1
«« « Zurück Seite 11 von 65 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.