CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-70632 - FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerabi
CVE-2026-70631 - FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosu
CVE-2026-70630 - FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vul
CVE-2026-70629 - FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vul
CVE-2026-70628 - FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerabili
CVE-2026-70559 - Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @S
CVE-2026-70558 - Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directl
CVE-2026-70557 - diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @T
CVE-2026-69125 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason:
CVE-2026-69124 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason:
CVE-2026-69123 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67319. Reason:
CVE-2026-68948 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason:
CVE-2026-68947 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67317. Reason:
CVE-2026-68946 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67315. Reason:
CVE-2026-68944 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason:
CVE-2026-68943 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason:
CVE-2026-68942 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason:
CVE-2026-68941 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason:
CVE-2026-68480 - In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust
CVE-2026-67689 - SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via
CVE-2026-67688 - ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the
CVE-2026-67687 - Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges
CVE-2026-67622 - Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assis
CVE-2026-67621 - Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated works
CVE-2026-67434 - PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Pri
CVE-2026-67422 - pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to
CVE-2026-65400 - An authentication issue was addressed with improved state management. This issue is fixed in macOS S
CVE-2026-64677 - Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local
CVE-2026-64665 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, w
CVE-2026-64664 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, a
CVE-2026-64663 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, m
CVE-2026-64662 - Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, a
CVE-2026-64655 - GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify buil
CVE-2026-64654 - GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI
CVE-2026-64653 - GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs inte
CVE-2026-64652 - GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status mask
CVE-2026-63725 - sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around
CVE-2026-63637 - Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/res
CVE-2026-62857 - Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From versi
CVE-2026-61632 - PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up t
CVE-2026-5857 - Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_receive
CVE-2026-5856 - Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name
CVE-2026-5855 - Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-s
CVE-2026-5336 - The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access
CVE-2026-54717 - Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in th
CVE-2026-53984 - Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-in
CVE-2026-53983 - Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerab
CVE-2026-50159 - Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and char
CVE-2026-49391 - Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does no
CVE-2026-48088 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48087 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48086 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48085 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48084 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48083 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48082 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48081 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48080 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48079 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48078 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48077 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48076 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48075 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48074 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48071 - OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl
CVE-2026-48054 - OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of component
CVE-2026-47765 - Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bul
CVE-2026-47194 - Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic log
CVE-2026-47185 - Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a
CVE-2026-45573 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0
CVE-2026-45572 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0
CVE-2026-45415 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0
CVE-2026-45414 - Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2,
CVE-2026-45378 - Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0
CVE-2026-43632 - llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-ser
CVE-2026-43631 - llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab
CVE-2026-43630 - llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent me
CVE-2026-43629 - llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache st
CVE-2026-43628 - llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerabili
CVE-2026-43627 - llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_in
CVE-2026-41861 - Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a r
CVE-2026-3418 - The System REST API accepts user-supplied file uploads without enforcing sufficient validation on th
CVE-2026-3415 - The XML and schema validation functionalities within the SchemaValidator Mediator process XML input
CVE-2026-33181 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason:
CVE-2026-1289 - A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulne
CVE-2026-19177 - Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a
CVE-2026-19176 - Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had co
CVE-2026-19175 - Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to pot
CVE-2026-19174 - Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute
CVE-2026-19173 - Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who h
CVE-2026-19172 - Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had c
CVE-2026-19171 - Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19170 - Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19169 - Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.
CVE-2026-19168 - Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19167 - Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had c
CVE-2026-19166 - Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attac
CVE-2026-19165 - Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convin
CVE-2026-19164 - Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowe
CVE-2026-19163 - Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19162 - Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to exec
CVE-2026-19161 - Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had
CVE-2026-19160 - Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had
CVE-2026-19159 - Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convi
CVE-2026-19158 - Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19157 - Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote at
CVE-2026-19156 - Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convin
CVE-2026-19155 - Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who ha
CVE-2026-19154 - Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker
CVE-2026-19153 - Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allow
CVE-2026-19152 - Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a rem
CVE-2026-19151 - Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute a
CVE-2026-19150 - Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19149 - Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker t
CVE-2026-19148 - Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attack
CVE-2026-19147 - Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker w
CVE-2026-19146 - Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attack
CVE-2026-19145 - Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to ex
CVE-2026-19144 - Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potenti
CVE-2026-19143 - Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.792
CVE-2026-19142 - Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convi
CVE-2026-19141 - Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote att
CVE-2026-19140 - Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had com
CVE-2026-19139 - Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attac
CVE-2026-19138 - Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote att
CVE-2026-19137 - Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacke
CVE-2026-19127 - An issue in the billing and license activation subsystem allows remote attackers to bypass payment a
CVE-2026-19111 - Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools
CVE-2026-19110 - A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTpl
CVE-2026-19108 - A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the func
CVE-2026-19071 - A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown functio
CVE-2026-19070 - A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown
CVE-2026-19069 - A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affe
CVE-2026-19068 - A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element
CVE-2026-19067 - A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected ele
CVE-2026-19066 - A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0
CVE-2026-19065 - A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0
CVE-2026-19064 - A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. Thi
CVE-2026-19062 - A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670.
CVE-2026-19061 - A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function
CVE-2026-19060 - A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown func
CVE-2026-19059 - A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function re
CVE-2026-19058 - A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the funct
CVE-2026-19054 - A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd
CVE-2026-18487 - A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fa
CVE-2026-18367 - A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos
CVE-2026-17032 - Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised
CVE-2026-16620 - The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-si
CVE-2026-16619 - The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-facto
CVE-2026-16067 - The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the
CVE-2026-15734 - A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allo
CVE-2026-15733 - A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple
CVE-2026-15732 - A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. T
CVE-2026-15256 - The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, u
CVE-2026-15208 - The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's
CVE-2026-15152 - The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corre
CVE-2026-15149 - The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resu
CVE-2026-15147 - The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticit
CVE-2026-14936 - The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notificati
CVE-2026-14842 - The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to
CVE-2026-14831 - The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured m
CVE-2026-14812 - The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a h
CVE-2026-14306 - The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting ac
CVE-2026-14225 - The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in
CVE-2026-13399 - The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper autho
CVE-2026-13342 - The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to
CVE-2026-12901 - The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay pay
CVE-2026-12584 - The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the
CVE-2026-12501 - The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment n
CVE-2026-11976 - The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa
CVE-2026-11803 - A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read
CVE-2026-11361 - The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPa
CVE-2026-10599 - The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verif
CVE-2026-10524 - The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the a
CVE-2025-6508 - The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API
CVE-2025-15674 - The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_po
CVE-2025-14561 - In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. Thi
CVE-2025-12317 - When internal roles are removed from a user within the WSO2 product, the system fails to invalidate
CVE-2024-6541 - The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are
CVE-2024-39024 - In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2026-68750 - Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex
CVE-2026-68749 - Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_
CVE-2026-68747 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') v
CVE-2026-66843 - Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrre
CVE-2026-66829 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene ht
CVE-2026-66370 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene ht
CVE-2026-5423 - @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied,
CVE-2026-53985 - Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Soc
CVE-2026-53977 - OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remot
CVE-2026-43622 - llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wr
CVE-2026-3430 - The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter befo
CVE-2026-19047 - A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function execu
CVE-2026-19046 - A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted elem
CVE-2026-18427 - @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass.
CVE-2026-18359 - Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through
CVE-2026-18277 - Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 2
CVE-2026-18276 - Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a rem
CVE-2026-18275 - Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium thro
CVE-2026-18258 - Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoint
CVE-2026-70646 - aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHand
CVE-2026-70637 - LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous a
CVE-2026-67261 - Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a
CVE-2026-66712 - Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
CVE-2026-66711 - Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
CVE-2026-66710 - Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-66709 - Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-66708 - Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVE-2026-66707 - Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-66706 - Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
CVE-2026-66705 - Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
CVE-2026-66703 - Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-66702 - Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-66701 - Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
CVE-2026-66699 - Custom role Broken Access Control in Dokan <= 5.0.10 versions.
CVE-2026-66696 - Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
CVE-2026-66695 - Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66694 - Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-66692 - Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour
CVE-2026-66690 - Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
CVE-2026-66688 - Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-66686 - Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <=
CVE-2026-66685 - Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
CVE-2026-66684 - Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-66683 - Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
CVE-2026-66681 - Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
CVE-2026-66678 - Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVE-2026-66665 - Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-66664 - Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
CVE-2026-66663 - Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-66662 - Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66470 - Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-66457 - Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
CVE-2026-66452 - Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 vers
CVE-2026-66451 - Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
CVE-2026-66447 - Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
CVE-2026-66440 - Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
CVE-2026-66439 - Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-66425 - Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Bo
CVE-2026-65581 - Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-65579 - Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-65578 - Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-65577 - Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65576 - Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65575 - Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-65574 - Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
CVE-2026-65573 - Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65572 - Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-65571 - Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
CVE-2026-65570 - Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
CVE-2026-65569 - Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.