CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-48387 - CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could re
CVE-2026-48386 - ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that coul
CVE-2026-48385 - ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS
CVE-2026-48384 - ColdFusion is affected by an Improper Input Validation vulnerability that could result in an applica
CVE-2026-48376 - is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Secur
CVE-2026-48375 - ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an applicati
CVE-2026-48362 - ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS
CVE-2026-47922 - CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could
CVE-2026-47704 - TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read acces
CVE-2026-47299 - Improper neutralization of special elements used in a command ('command injection') in Azure Monitor
CVE-2026-47285 - Improper neutralization of special elements used in a command ('command injection') in Visual Studio
CVE-2026-43606 - Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attac
CVE-2026-42976 - Missing authentication for critical function in Windows RPC API allows an authorized attacker to ele
CVE-2026-40375 - Missing authorization in Dynamics Business Central allows an authorized attacker to disclose informa
CVE-2026-39452 - Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Rin
CVE-2026-35502 - Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 withi
CVE-2026-34635 - is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security f
CVE-2026-34175 - Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723
CVE-2026-32791 - Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version ta
CVE-2026-32788 - Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit
CVE-2026-32677 - Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applicatio
CVE-2026-28757 - Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: U
CVE-2026-28729 - Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disc
CVE-2026-28707 - Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications
CVE-2026-28700 - Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications
CVE-2026-27765 - Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before versio
CVE-2026-25652 - is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A
CVE-2026-25194 - Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service.
CVE-2026-24911 - Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring
CVE-2026-24693 - Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 wit
CVE-2026-24099 - Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may
CVE-2026-22887 - Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring
CVE-2026-21400 - Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring
CVE-2026-21399 - Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library m
CVE-2026-21387 - Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applicati
CVE-2026-21279 - is affected by an Improper Input Validation vulnerability that could result in a Security feature by
CVE-2026-21273 - is affected by an Improper Input Validation vulnerability that could result in privilege escalation.
CVE-2026-21269 - is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privi
CVE-2026-20913 - Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ri
CVE-2026-20908 - Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions wi
CVE-2026-20906 - Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within
CVE-2026-20903 - Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: Us
CVE-2026-20898 - Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R)
CVE-2026-20891 - Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: D
CVE-2026-20890 - Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Rin
CVE-2026-20886 - Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Devic
CVE-2026-20885 - Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust
CVE-2026-20878 - Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2:
CVE-2026-20799 - Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Rin
CVE-2026-20795 - Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring
CVE-2026-20789 - Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: D
CVE-2026-20787 - Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2:
CVE-2026-20786 - Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may
CVE-2026-20783 - Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1
CVE-2026-20780 - Uncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within
CVE-2026-20778 - Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel
CVE-2026-20776 - Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Driv
CVE-2026-20775 - Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of s
CVE-2026-20770 - Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before vers
CVE-2026-20769 - Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applicati
CVE-2026-20765 - Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User A
CVE-2026-20763 - Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User
CVE-2026-20760 - Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Pro
CVE-2026-20755 - Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow
CVE-2026-20752 - Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may al
CVE-2026-20749 - Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may
CVE-2026-20747 - Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Driv
CVE-2026-20745 - Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Devic
CVE-2026-20741 - Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Driver
CVE-2026-20739 - Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2:
CVE-2026-20737 - Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi So
CVE-2026-20734 - Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AM
CVE-2026-20731 - Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applic
CVE-2026-20728 - Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.
CVE-2026-20727 - Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0:
CVE-2026-20716 - Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an e
CVE-2026-20715 - Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R)
CVE-2026-20713 - Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors m
CVE-2026-20708 - Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R)
CVE-2026-20707 - Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within
CVE-2026-20705 - Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform with
CVE-2026-20702 - Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) ma
CVE-2026-20349 - A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security App
CVE-2026-18247 - A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than
CVE-2026-12571 - An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeov
CVE-2025-8087 - A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to
CVE-2025-61970 - Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low
CVE-2025-48506 - Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow
CVE-2025-48505 - Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low
CVE-2025-35987 - Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center At
CVE-2025-35973 - Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare
CVE-2025-31938 - Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable pr
CVE-2025-31936 - Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors
CVE-2025-31356 - Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) T
CVE-2025-0041 - Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows instal
CVE-2026-9214 - Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated admini
CVE-2026-73080 - SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/s
CVE-2026-73079 - Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product s
CVE-2026-73078 - Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim l
CVE-2026-73077 - Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, run
CVE-2026-73076 - Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim all
CVE-2026-73075 - Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zi
CVE-2026-73074 - Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c
CVE-2026-73072 - Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c re
CVE-2026-73071 - Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in
CVE-2026-73070 - Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src
CVE-2026-73069 - Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty al
CVE-2026-73068 - ToolJet is the open-source foundation am AI-native platform for building and deploying internal tool
CVE-2026-6727 - A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged l
CVE-2026-6726 - An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow
CVE-2026-67180 - Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to
CVE-2026-67179 - Genkit does not properly validate host request headers. Any host on the developer's network, and any
CVE-2026-56721 - CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure dir
CVE-2026-56720 - CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin us
CVE-2026-53416 - Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information
CVE-2026-53415 - Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve
CVE-2026-53414 - Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may al
CVE-2026-53413 - Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may a
CVE-2026-48766 - TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a
CVE-2026-48495 - TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes
CVE-2026-42142 - TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST
CVE-2026-19546 - A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.
CVE-2026-19078 - A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'th
CVE-2026-18640 - The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user wit
CVE-2026-18639 - When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a
CVE-2026-18638 - Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the
CVE-2026-14180 - A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly
CVE-2026-11814 - A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker wi
CVE-2026-11739 - A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-ad
CVE-2026-11738 - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
CVE-2026-11737 - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admin
CVE-2026-11736 - A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated
CVE-2026-11735 - A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authentica
CVE-2026-11734 - A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to c
CVE-2026-11733 - A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to tempor
CVE-2025-31114 - Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerab
CVE-2026-73067 - Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through
CVE-2026-73066 - Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component
CVE-2026-72925 - SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-202607
CVE-2026-72922 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-72921 - SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go a
CVE-2026-72920 - SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAcc
CVE-2026-47702 - TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authent
CVE-2026-18860 - Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT o
CVE-2026-18636 - The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore.
CVE-2026-18635 - Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user
CVE-2026-18129 - Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before versio
CVE-2026-18127 - External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows
CVE-2026-18125 - An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remot
CVE-2026-17535 - Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which
CVE-2026-17061 - A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 20
CVE-2023-54374 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54373 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54372 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54371 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54370 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54369 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54368 - Rejected reason: This CVE ID has been rejected.
CVE-2023-54367 - Rejected reason: This CVE ID has been rejected.
CVE-2022-50974 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47995 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47994 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47993 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47992 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47991 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47990 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47989 - Rejected reason: This CVE ID has been rejected.
CVE-2021-47988 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37265 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37264 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37263 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37262 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37261 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37260 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37259 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37258 - Rejected reason: This CVE ID has been rejected.
CVE-2020-37257 - Rejected reason: This CVE ID has been rejected.
CVE-2026-73210 - A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the
CVE-2026-51584 - An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredent
CVE-2026-51583 - An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side R
CVE-2026-48056 - Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p
CVE-2026-48046 - Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p
CVE-2026-46670 - YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection i
CVE-2026-19539 - Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospe
CVE-2026-19434 - Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated
CVE-2026-72785 - Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-pane
CVE-2026-72784 - Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side r
CVE-2026-72783 - Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical p
CVE-2026-72782 - Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment
CVE-2026-72781 - Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code e
CVE-2026-72780 - Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion valida
CVE-2026-72779 - Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnera
CVE-2026-72778 - Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenti
CVE-2026-72775 - n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigge
CVE-2026-72774 - n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Reque
CVE-2026-72773 - n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-us
CVE-2026-72772 - n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed
CVE-2026-72771 - n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI
CVE-2026-72770 - n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, a
CVE-2026-72769 - n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expre
CVE-2026-72768 - n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in
CVE-2026-72767 - n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vul
CVE-2026-72766 - n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerabil
CVE-2026-72765 - n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation.
CVE-2026-72764 - n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In
CVE-2026-72763 - n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level cred
CVE-2026-72762 - n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in th
CVE-2026-72750 - n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node
CVE-2026-72749 - n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fie
CVE-2026-72748 - AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json
CVE-2026-72747 - AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attacker
CVE-2026-72746 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a
CVE-2026-72745 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a
CVE-2026-72744 - Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure v
CVE-2026-69109 - A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affec
CVE-2026-69108 - A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affec
CVE-2026-64629 - A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (
CVE-2026-59701 - A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected app
CVE-2026-59700 - A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected app
CVE-2026-59693 - A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3
CVE-2026-59086 - A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (Al
CVE-2026-58115 - A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions <
CVE-2026-57263 - A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password
CVE-2026-57262 - A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use
CVE-2026-50064 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-50063 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-50062 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-50061 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-50060 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-50059 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-50058 - A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed
CVE-2026-18972 - An authenticated attacker can spoof another GUI user's identity by sending their request with the cu
CVE-2026-72610 - A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allo
CVE-2026-72609 - An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows aut
CVE-2026-72608 - A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allo
CVE-2026-72607 - A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allo
CVE-2026-72606 - A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote at
CVE-2026-72605 - A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers
CVE-2026-72604 - A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated adminis
CVE-2026-72603 - An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permiss
CVE-2026-72602 - A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenti
CVE-2026-72601 - A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to re
CVE-2026-72600 - A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote a
CVE-2026-72599 - An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbi
CVE-2026-72598 - A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role
CVE-2026-72597 - A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authe
CVE-2026-72596 - A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role
CVE-2026-72595 - A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated
CVE-2026-72563 - A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated
CVE-2026-72562 - An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authent
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.