CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-45808 - OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao'
CVE-2026-11743 - The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash
CVE-2026-11742 - The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue
CVE-2026-9031 - An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation
CVE-2026-9030 - A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous sys
CVE-2026-71381 - Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulner
CVE-2026-70624 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-70623 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-69207 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-66061 - Home Assistant is open source home automation software focused on local control and privacy. Prior
CVE-2026-66060 - Home Assistant is open source home automation software focused on local control and privacy. Prior
CVE-2026-59717 - Home Assistant is open source home automation software focused on local control and privacy. Prior t
CVE-2026-54338 - JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior
CVE-2026-50540 - Kata Containers is an open source project focusing on a standard implementation of lightweight Virtu
CVE-2026-47664 - Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health da
CVE-2026-47663 - Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health da
CVE-2026-47662 - Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health da
CVE-2026-46358 - OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao'
CVE-2026-19246 - A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_ima
CVE-2026-19245 - A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._p
CVE-2026-19244 - A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function conn
CVE-2026-11425 - Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile
CVE-2026-71870 - pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause la
CVE-2026-66151 - SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel
CVE-2026-65819 - gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decod
CVE-2026-62296 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J
CVE-2026-62295 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J
CVE-2026-62293 - HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J
CVE-2026-61808 - LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRA
CVE-2026-48039 - Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to
CVE-2026-48007 - Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 repor
CVE-2026-47661 - Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health da
CVE-2026-47660 - Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health da
CVE-2026-47659 - Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health da
CVE-2026-19243 - A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function Ex
CVE-2026-19113 - Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthentica
CVE-2026-19017 - Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arb
CVE-2026-19016 - Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:wr
CVE-2026-19015 - Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled
CVE-2026-19014 - Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolle
CVE-2026-19012 - Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticat
CVE-2026-15972 - Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthentic
CVE-2026-15970 - Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intentio
CVE-2026-71852 - pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause lo
CVE-2026-71851 - crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate
CVE-2026-71850 - Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to
CVE-2026-71849 - Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to
CVE-2026-71848 - Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to
CVE-2026-71847 - Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extensio
CVE-2026-70561 - TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any
CVE-2026-69127 - Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the
CVE-2026-66000 - Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow not
CVE-2026-48098 - NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use
CVE-2026-48097 - NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a use
CVE-2026-19231 - A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vu
CVE-2026-19230 - A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown pa
CVE-2026-17435 - File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rota
CVE-2026-11430 - Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. Wh
CVE-2025-71413 - Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cau
CVE-2025-71412 - Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, o
CVE-2025-71411 - Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearanc
CVE-2025-71410 - Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can te
CVE-2025-71409 - Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to in
CVE-2025-63235 - In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malfor
CVE-2026-66058 - Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access
CVE-2026-64638 - WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a spec
CVE-2026-64637 - Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated re
CVE-2026-64636 - An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authe
CVE-2026-56818 - Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2
CVE-2026-47364 - In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data wi
CVE-2026-47363 - In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity A
CVE-2026-47362 - In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases
CVE-2026-47361 - In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported w
CVE-2026-44965 - In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration act
CVE-2026-44964 - In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is de
CVE-2026-19229 - A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is so
CVE-2026-19213 - A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in
CVE-2026-19082 - Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-
CVE-2026-71557 - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alp
CVE-2026-71556 - go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alp
CVE-2026-68772 - ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component
CVE-2026-67585 - Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation
CVE-2026-66062 - SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Pr
CVE-2026-20348 - A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attac
CVE-2026-20347 - A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote at
CVE-2026-20346 - A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attac
CVE-2026-20345 - A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attac
CVE-2026-20339 - A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote at
CVE-2026-20338 - A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker
CVE-2026-20337 - A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker
CVE-2026-19212 - A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the
CVE-2026-19211 - A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown functio
CVE-2026-17603 - Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be
CVE-2026-17601 - A user holding a permission to update privilege definitions could modify a wildcard privilege alread
CVE-2026-17600 - Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke th
CVE-2026-17599 - Nexus Repository 3 contained an endpoint used to change the administrator account password during in
CVE-2026-17598 - Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied t
CVE-2026-17597 - Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configur
CVE-2026-17596 - Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the
CVE-2026-17595 - Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account hold
CVE-2026-17594 - Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerabi
CVE-2026-17593 - An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nex
CVE-2026-14644 - Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An aut
CVE-2026-66059 - Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permi
CVE-2026-62996 - Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from app
CVE-2026-62992 - Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from app
CVE-2026-48093 - The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting
CVE-2026-19210 - A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an
CVE-2026-19209 - A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown
CVE-2026-19208 - A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTr
CVE-2026-19264 - Postiz is an open-source social media scheduling tool. The route that serves locally stored media jo
CVE-2026-19207 - A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This
CVE-2026-18497 - A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26
CVE-2022-4995 - Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows
CVE-2026-66914 - Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1
CVE-2026-61477 - An injection vulnerability was found in libvirt's virtual network driver. The network XML parser doe
CVE-2026-37171 - A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authent
CVE-2026-19206 - A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the funct
CVE-2026-16637 - OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the A
CVE-2026-15570 - An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in
CVE-2026-66838 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-66494 - Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builde
CVE-2026-56794 - Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal
CVE-2026-56793 - Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authenticatio
CVE-2026-48094 - The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerabilit
CVE-2026-15816 - A flaw was found in dracut. The die() error-handling function writes its message into a shell script
CVE-2026-71560 - Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory
CVE-2026-71559 - Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an at
CVE-2026-71558 - Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache For
CVE-2026-54218 - Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For u
CVE-2026-54217 - Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An
CVE-2026-54216 - Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS)
CVE-2026-54215 - Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl
CVE-2026-54214 - Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through
CVE-2026-54213 - Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server
CVE-2026-54212 - Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable t
CVE-2026-54211 - Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulne
CVE-2026-54210 - Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities
CVE-2026-54209 - Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function trigg
CVE-2026-54208 - Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing
CVE-2026-54207 - Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an
CVE-2026-54206 - Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @
CVE-2026-54205 - Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm)
CVE-2026-54204 - Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter
CVE-2026-54203 - Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allow
CVE-2026-54202 - Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the ar
CVE-2026-54201 - Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks w
CVE-2026-54200 - Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in
CVE-2026-54199 - Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the reques
CVE-2026-12071 - The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input,
CVE-2026-12070 - Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability
CVE-2026-9169 - DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attack
CVE-2026-66493 - Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper
CVE-2026-66492 - Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper
CVE-2026-66491 - Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitati
CVE-2026-49008 - By accessing unencrypted information in the device firmware, an attacker can obtain credentials rela
CVE-2026-18938 - A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC chan
CVE-2026-49007 - By accessing unencrypted information in the device firmware, an attacker can obtain the initial logi
CVE-2026-49006 - By accessing unencrypted information in the device firmware, an attacker can obtain credentials rela
CVE-2026-19079 - A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script i
CVE-2026-16027 - Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature all
CVE-2026-15239 - The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnst
CVE-2026-15211 - The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount
CVE-2026-15148 - The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notific
CVE-2026-12261 - A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resourc
CVE-2026-19196 - A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unkn
CVE-2026-16265 - The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX ac
CVE-2026-16263 - The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX ac
CVE-2026-16262 - The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login fl
CVE-2026-16258 - The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrust
CVE-2026-16041 - The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership
CVE-2026-16039 - The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the c
CVE-2026-16038 - The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway
CVE-2026-16030 - The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature
CVE-2026-15386 - The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outpu
CVE-2026-15361 - The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJA
CVE-2026-15359 - The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its req
CVE-2026-15245 - The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute
CVE-2026-15215 - The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capabilit
CVE-2026-15214 - The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester o
CVE-2026-15032 - The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before out
CVE-2026-14943 - The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress p
CVE-2026-14331 - The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before
CVE-2026-14205 - The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when re
CVE-2026-49005 - The root password hash of the device can be obtained through unencrypted information in the firmware
CVE-2026-19195 - A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an un
CVE-2026-19193 - A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in th
CVE-2026-19192 - A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown proc
CVE-2026-19191 - A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability af
CVE-2026-14365 - The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to auth
CVE-2026-14364 - The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to acco
CVE-2026-12801 - The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
CVE-2026-11907 - The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc
CVE-2026-19190 - A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the
CVE-2026-49746 - Software installed and run as a non-privileged user may conduct improper GPU system calls to cause O
CVE-2026-45204 - Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger
CVE-2026-45198 - Kernel software from a non-secure operating system on a platform with Trusted Execution Environment
CVE-2026-19189 - A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is som
CVE-2026-70332 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
CVE-2026-68823 - Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to e
CVE-2026-65668 - Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate pri
CVE-2026-65667 - Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over
CVE-2026-63508 - Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthori
CVE-2026-62918 - Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker
CVE-2026-62896 - Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over
CVE-2026-62873 - Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorize
CVE-2026-62836 - Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance al
CVE-2026-62830 - Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a
CVE-2026-59118 - Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over
CVE-2026-59115 - '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to el
CVE-2026-56162 - Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges
CVE-2026-56161 - Improper access control in Azure Logic Apps allows an authorized attacker to disclose information ov
CVE-2026-50515 - Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code
CVE-2026-50481 - Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacke
CVE-2026-49163 - Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insigh
CVE-2026-17264 - Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-co
CVE-2026-15805 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8325 - A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write
CVE-2026-7867 - A flaw was found in udisks2. A local attacker with an active console session can exploit insufficien
CVE-2026-7406 - A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted
CVE-2026-7405 - A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, c
CVE-2026-71555 - PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 un
CVE-2026-71554 - h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 ac
CVE-2026-71498 - node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Bu
CVE-2026-71497 - jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML par
CVE-2026-71488 - league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2
CVE-2026-71478 - league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2
CVE-2026-71476 - Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 an
CVE-2026-71447 - AIL Project contains a stored cross-site scripting vulnerability in the translation controls display
CVE-2026-71446 - AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawl
CVE-2026-71445 - AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint
CVE-2026-71439 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-71438 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-71437 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-71436 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-71435 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, t
CVE-2026-71434 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, p
CVE-2026-71433 - LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of L
CVE-2026-71430 - node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedR
CVE-2026-71327 - Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10,
CVE-2026-71326 - Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10,
CVE-2026-71325 - Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prio
CVE-2026-71324 - Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9,
CVE-2026-70640 - llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LL
CVE-2026-70639 - llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-A
CVE-2026-70638 - llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android
CVE-2026-70636 - Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated at
CVE-2026-70635 - TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability th
CVE-2026-70634 - TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionar
CVE-2026-70633 - TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.