CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-45417 - DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasour
CVE-2026-45320 - DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboar
CVE-2026-40958 - CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with i
CVE-2026-40957 - o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior
CVE-2026-40956 - CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55.
CVE-2026-40955 - CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Acces
CVE-2026-40954 - CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Acces
CVE-2026-40953 - CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior
CVE-2026-40952 - CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client
CVE-2026-33443 - CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with
CVE-2026-62947 - OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download h
CVE-2026-62355 - TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to
CVE-2026-62353 - TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, sour
CVE-2026-62351 - TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, sour
CVE-2026-62350 - TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to
CVE-2026-62349 - TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.
CVE-2026-62348 - TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDen
CVE-2026-54443 - Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/com
CVE-2026-49988 - Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP s
CVE-2026-49987 - Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitC
CVE-2026-46485 - Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow
CVE-2026-46421 - The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applicatio
CVE-2026-26032 - The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a
CVE-2026-15895 - OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allo
CVE-2026-15746 - Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-t
CVE-2026-12997 - The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a
CVE-2026-8055 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason:
CVE-2026-62948 - OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DH
CVE-2026-62389 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a dupl
CVE-2026-61643 - FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authentica
CVE-2026-59258 - immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:user
CVE-2026-59255 - BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in
CVE-2026-58660 - Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kan
CVE-2026-58659 - PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerabi
CVE-2026-58658 - GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure
CVE-2026-56687 - Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A l
CVE-2026-56087 - Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability.
CVE-2026-53518 - Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11,
CVE-2026-53517 - Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1
CVE-2026-53516 - Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better A
CVE-2026-53515 - Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11,
CVE-2026-53514 - Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1
CVE-2026-53513 - Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @bet
CVE-2026-53512 - Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the lega
CVE-2026-50562 - FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c
CVE-2026-45337 - Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11,
CVE-2026-40501 - Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code executio
CVE-2026-20298 - In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform ve
CVE-2026-20297 - In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Pla
CVE-2026-20296 - In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform ve
CVE-2026-14961 - Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly re
CVE-2026-14960 - Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\
CVE-2026-12382 - A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event strea
CVE-2026-10673 - The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reasse
CVE-2026-62378 - RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until
CVE-2026-62287 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61873. Reason:
CVE-2026-62248 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61438. Reason:
CVE-2026-62180 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61440. Reason:
CVE-2026-62178 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61427. Reason:
CVE-2026-62177 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60085. Reason:
CVE-2026-62174 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61435. Reason:
CVE-2026-62173 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61433. Reason:
CVE-2026-62172 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61436. Reason:
CVE-2026-62169 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61430. Reason:
CVE-2026-62168 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61443. Reason:
CVE-2026-62165 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61446. Reason:
CVE-2026-62164 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60087. Reason:
CVE-2026-61841 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61449. Reason:
CVE-2026-61839 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61451. Reason:
CVE-2026-61829 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61452. Reason:
CVE-2026-61710 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61453. Reason:
CVE-2026-61606 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61457. Reason:
CVE-2026-59955 - Apollo is a reliable configuration management system suitable for microservice configuration managem
CVE-2026-59954 - Apollo is a reliable configuration management system suitable for microservice configuration managem
CVE-2026-52843 - Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch()
CVE-2026-52842 - Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched
CVE-2026-49997 - SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. P
CVE-2026-48799 - Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IP
CVE-2026-47703 - AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Ho
CVE-2026-45804 - Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPip
CVE-2026-45793 - Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer
CVE-2026-20187 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
CVE-2026-20158 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
CVE-2026-20157 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
CVE-2026-20156 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
CVE-2026-20153 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
CVE-2026-20150 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en
CVE-2026-20146 - A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (IS
CVE-2026-1563 - Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS)
CVE-2026-1562 - Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vul
CVE-2025-32781 - Apollo is a reliable configuration management system suitable for microservice configuration managem
CVE-2026-9007 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-62843 - File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing
CVE-2026-62685 - File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing
CVE-2026-62683 - File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing
CVE-2026-61828 - Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Pri
CVE-2026-61605 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-58655. Reason:
CVE-2026-61371 - Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix,
CVE-2026-60005 - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the
CVE-2026-55242 - ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0,
CVE-2026-50148 - Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54
CVE-2026-50147 - Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57
CVE-2026-47164 - Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO log
CVE-2026-47160 - Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/
CVE-2026-47159 - Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO dis
CVE-2026-47158 - Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO aut
CVE-2026-46709 - Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby insert
CVE-2026-45806 - Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's re
CVE-2026-45805 - Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP'
CVE-2026-45150 - Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly
CVE-2026-44986 - Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot expo
CVE-2026-41580 - Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. P
CVE-2026-62294 - Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature
CVE-2026-61836 - Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, wh
CVE-2026-61835 - Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, th
CVE-2026-61740 - LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is d
CVE-2026-61736 - LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server default
CVE-2026-61684 - FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse
CVE-2026-61646 - FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF g
CVE-2026-61644 - FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api
CVE-2026-61613 - Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, b
CVE-2026-60065 - When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (n
CVE-2026-60062 - The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and writ
CVE-2026-59762 - When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase
CVE-2026-56434 - NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulner
CVE-2026-55723 - When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annot
CVE-2026-54563 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV a
CVE-2026-54562 - Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote d
CVE-2026-54560 - Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's
CVE-2026-52865 - When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remo
CVE-2026-42533 - A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching
CVE-2026-33213 - Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() fu
CVE-2026-62175 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60091. Reason:
CVE-2026-59838 - A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in For
CVE-2026-43637 - Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to writ
CVE-2026-58559 - DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability ma
CVE-2026-58558 - Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnera
CVE-2026-58557 - Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerabilit
CVE-2026-58556 - Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vu
CVE-2026-58555 - Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerab
CVE-2026-58554 - Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vul
CVE-2026-58553 - Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
CVE-2026-58552 - Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
CVE-2026-58551 - Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
CVE-2026-58550 - Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
CVE-2026-58549 - Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this
CVE-2026-46459 - ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endp
CVE-2026-46458 - ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential
CVE-2026-15809 - A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allow
CVE-2026-15779 - A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target ac
CVE-2026-61873 - Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.f
CVE-2026-61872 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid
CVE-2026-61871 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs whe
CVE-2026-61869 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs whe
CVE-2026-61868 - ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder tha
CVE-2026-61867 - ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory all
CVE-2026-61866 - ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cann
CVE-2026-61865 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when
CVE-2026-61864 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log
CVE-2026-61863 - ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder th
CVE-2026-61862 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a p
CVE-2026-61860 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when f
CVE-2026-61859 - ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in
CVE-2026-61464 - ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that
CVE-2026-61457 - The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass i
CVE-2026-61453 - Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint valida
CVE-2026-61452 - The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation
CVE-2026-61451 - The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-suppli
CVE-2026-61449 - Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size
CVE-2026-61446 - PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plug
CVE-2026-61443 - PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_scrip
CVE-2026-61440 - PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowin
CVE-2026-61438 - PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_
CVE-2026-61436 - PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing
CVE-2026-61435 - PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints
CVE-2026-61433 - PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Pytho
CVE-2026-61430 - PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool t
CVE-2026-61427 - PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the
CVE-2026-60087 - PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reus
CVE-2026-60085 - PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subproce
CVE-2026-59259 - n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in exter
CVE-2026-59254 - n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorr
CVE-2026-59236 - Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImp
CVE-2026-58655 - The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stor
CVE-2026-57996 - phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint tha
CVE-2026-56764 - Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewar
CVE-2026-56699 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazu
CVE-2026-56400 - open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrar
CVE-2026-56398 - Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentica
CVE-2026-56375 - ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action
CVE-2026-56353 - n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a
CVE-2026-56352 - n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's local
CVE-2026-56349 - n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allo
CVE-2026-56339 - Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabas
CVE-2026-59235 - Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/B
CVE-2026-40633 - Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains
CVE-2026-8281 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-58077 - Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extens
CVE-2026-57833 - Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extens
CVE-2026-57821 - A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in
CVE-2026-56287 - A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/
CVE-2026-49501 - Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 cont
CVE-2026-35152 - A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint)
CVE-2026-57832 - Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joo
CVE-2026-57831 - Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10
CVE-2026-15804 - The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can
CVE-2026-15583 - A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate
CVE-2026-14251 - A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate reso
CVE-2026-42936 - The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at t
CVE-2026-12512 - The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied
CVE-2026-12281 - The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode
CVE-2026-11580 - The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perfor
CVE-2026-11579 - The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify
CVE-2026-8920 - Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Nam
CVE-2026-8919 - Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user
CVE-2026-15030 - Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Busi
CVE-2026-15029 - Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, an
CVE-2026-13585 - Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Remo
CVE-2026-13385 - An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS
CVE-2026-11851 - Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web mana
CVE-2026-9770 - Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only
CVE-2026-13230 - An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the lo
CVE-2026-5270 - An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control
CVE-2026-5269 - In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden sys
CVE-2026-51808 - Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitra
CVE-2026-51807 - Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions
CVE-2026-36035 - Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantVi
CVE-2026-15753 - A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerab
CVE-2026-15752 - A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f92
CVE-2026-15751 - A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The af
CVE-2025-56365 - A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the
CVE-2025-56364 - A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0,
CVE-2025-56363 - A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, af
CVE-2025-56362 - A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifi
CVE-2026-59733 - Rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-59732 - Rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-54684 - jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to writ
CVE-2026-54572 - Rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-50130 - Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-
CVE-2026-49981 - Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function all
CVE-2026-48808 - Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox st
CVE-2026-48807 - Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully c
CVE-2026-48806 - Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping
CVE-2026-48805 - Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/
CVE-2026-48357 - CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could
CVE-2026-48354 - CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could re
CVE-2026-48353 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to
CVE-2026-48352 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result
CVE-2026-48351 - CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result
CVE-2026-48337 - Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.