CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-65543 - Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-65542 - Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-65541 - Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65523 - Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contra
CVE-2026-65520 - Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CVE-2026-65517 - Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-65515 - Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
CVE-2026-65513 - Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65509 - Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-65508 - Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65507 - Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
CVE-2026-65504 - Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVE-2026-65502 - Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
CVE-2026-61982 - Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-61964 - Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
CVE-2026-61963 - Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-61961 - Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-61959 - Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
CVE-2026-54489 - Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a
CVE-2026-53976 - OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/rea
CVE-2026-53975 - OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remot
CVE-2026-34502 - Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This i
CVE-2026-34501 - Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issu
CVE-2026-34191 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-32548 - Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
CVE-2026-32469 - Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
CVE-2026-32327 - A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library co
CVE-2026-28183 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-28180 - Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <=
CVE-2026-28179 - Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-28178 - Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-28177 - Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-28172 - Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-28169 - Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
CVE-2026-28146 - Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templ
CVE-2026-28143 - Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-28141 - Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28140 - Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
CVE-2026-28139 - Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-28111 - Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
CVE-2026-28082 - Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
CVE-2026-28005 - Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVE-2026-25403 - Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-19045 - A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the f
CVE-2026-19044 - A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function
CVE-2026-15246 - The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment ac
CVE-2025-49506 - APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with re
CVE-2026-64993 - Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in t
CVE-2026-5134 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i
CVE-2026-19041 - A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the fun
CVE-2026-19040 - A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown funct
CVE-2026-18501 - The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for W
CVE-2026-16731 - OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability
CVE-2026-16316 - OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampl
CVE-2026-16315 - OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability
CVE-2026-12605 - In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leak
CVE-2026-70556 - Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /
CVE-2026-66733 - Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in Receiv
CVE-2026-66732 - Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in C
CVE-2026-65551 - Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Ac
CVE-2026-19039 - A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6de
CVE-2026-19038 - A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue aff
CVE-2026-19037 - A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function
CVE-2026-19036 - A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C
CVE-2026-15599 - Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus
CVE-2026-0673 - The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection i
CVE-2026-8166 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-68481 - In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully
CVE-2026-68079 - In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an
CVE-2026-65583 - Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcin
CVE-2026-63687 - Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization
CVE-2026-61466 - In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st
CVE-2026-5391 - The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper
CVE-2026-5158 - The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vu
CVE-2026-57818 - A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code
CVE-2026-19035 - A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function ne
CVE-2026-11983 - The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypas
CVE-2025-9266 - The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missi
CVE-2025-15028 - The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plug
CVE-2026-66909 - Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java
CVE-2026-65432 - Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and e
CVE-2026-64958 - An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service
CVE-2026-57819 - Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFo
CVE-2026-57817 - The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter
CVE-2026-54225 - Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apa
CVE-2026-19034 - A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the fun
CVE-2026-55980 - A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer ov
CVE-2026-55979 - An improper access control check in CatchPulse's named pipe communication interface could allow an a
CVE-2026-55978 - An improper access control vulnerability in CatchPulse could allow a non-administrative local attack
CVE-2026-64640 - Apache Polaris did not consistently validate storage locations supplied during table and view regist
CVE-2026-19022 - A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initi
CVE-2026-64604 - In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 in
CVE-2026-64603 - In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protec
CVE-2026-64602 - In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize com
CVE-2026-64601 - In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_co
CVE-2026-64599 - In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double
CVE-2026-64598 - In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in s
CVE-2026-64597 - In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in
CVE-2026-64596 - In the Linux kernel, the following vulnerability has been resolved: libfs: set SB_I_NOEXEC and SB_I
CVE-2026-64595 - In the Linux kernel, the following vulnerability has been resolved: HID: hid-lenovo-go: cancel cfg_
CVE-2026-64594 - In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: initialize r
CVE-2026-64593 - In the Linux kernel, the following vulnerability has been resolved: btrfs: do not trim a device whi
CVE-2026-64592 - In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Unconditionally sfen
CVE-2026-64591 - In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid WARNING in sv
CVE-2026-64590 - In the Linux kernel, the following vulnerability has been resolved: dma-buf/udmabuf: skip redundant
CVE-2026-64589 - In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix NULL-deref on ad
CVE-2026-64588 - In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on r
CVE-2026-64587 - In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quies
CVE-2026-64586 - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset
CVE-2026-64585 - In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URB
CVE-2026-64584 - In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pen
CVE-2026-64583 - In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ
CVE-2026-5430 - The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly c
CVE-2026-1728 - Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to
CVE-2026-19021 - A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System
CVE-2026-19020 - A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vuln
CVE-2026-19019 - A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function Work
CVE-2026-19011 - A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemProm
CVE-2026-19010 - A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessag
CVE-2026-19009 - A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of th
CVE-2026-19008 - A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function a
CVE-2026-18915 - Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software T
CVE-2026-18649 - A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP de
CVE-2026-18597 - The PDF creation feature of Foxit PDF Services API supports referencing external files. Although loc
CVE-2026-0637 - When an Event Publisher output adapter is configured with irrelevant properties, the affected produc
CVE-2025-15039 - The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the compl
CVE-2025-14779 - The Secret Type Management REST API does not correctly isolate access controls when deleting a secre
CVE-2025-13909 - The system accepts authentication requests without sufficient validation to enforce tenant isolation
CVE-2025-13736 - When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence
CVE-2025-13394 - The Ajax processor within the Carbon console fails to adequately protect state-changing operations f
CVE-2025-12627 - The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associat
CVE-2025-11850 - When secondary user stores are configured, the implicit-association resolver incorrectly initializes
CVE-2024-8995 - Unused authorization codes issued to deleted users are not being properly invalidated or removed fro
CVE-2024-6832 - The account locking mechanism fails to trigger when secondary user stores are inaccessible. The soft
CVE-2024-10302 - The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input
CVE-2023-7355 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-7354 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-7353 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2026-19007 - A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the fu
CVE-2026-19006 - A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file
CVE-2026-19005 - A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreat
CVE-2026-18967 - A flaw was found in the SAML broker component of Keycloak, an identity and access management solutio
CVE-2026-18510 - The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner
CVE-2026-18400 - The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is
CVE-2026-18395 - The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode
CVE-2026-18050 - The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST r
CVE-2026-16954 - The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before expo
CVE-2026-16734 - The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the call
CVE-2026-16537 - The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute va
CVE-2026-16290 - The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before return
CVE-2026-16268 - The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing r
CVE-2026-16065 - The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from
CVE-2026-16054 - The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not preven
CVE-2026-14829 - The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin throug
CVE-2026-14547 - The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam
CVE-2026-14314 - The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requ
CVE-2026-14313 - PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin throug
CVE-2026-14240 - The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable
CVE-2026-14204 - The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its t
CVE-2026-13703 - The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one
CVE-2026-13154 - The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-suppl
CVE-2026-13153 - The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its
CVE-2026-12713 - The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a para
CVE-2026-11588 - The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one o
CVE-2025-15678 - The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG
CVE-2026-19000 - A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function
CVE-2026-18998 - A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the funct
CVE-2026-18997 - A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the fun
CVE-2026-15459 - The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions u
CVE-2026-18996 - A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability af
CVE-2026-18995 - A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTok
CVE-2026-18993 - A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is so
CVE-2026-18992 - A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the functi
CVE-2026-18909 - A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on
CVE-2026-18325 - The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln
CVE-2026-16636 - The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Pr
CVE-2026-15991 - The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f
CVE-2026-18991 - A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknow
CVE-2026-18990 - A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file
CVE-2026-18980 - A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_co
CVE-2026-18976 - A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function
CVE-2026-18974 - A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get
CVE-2026-18973 - A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is
CVE-2026-67873 - A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding
CVE-2026-67872 - An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event
CVE-2026-67871 - Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of
CVE-2026-67870 - In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation
CVE-2026-67869 - Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of serv
CVE-2026-67531 - FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the s
CVE-2026-52466 - Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The appl
CVE-2026-19028 - H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum
CVE-2026-19027 - The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_a
CVE-2026-18970 - A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617.
CVE-2026-18969 - A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20
CVE-2026-18968 - A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658
CVE-2023-54389 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54388 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54387 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54386 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54385 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54384 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54383 - Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54382 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54381 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54380 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54379 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54378 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54377 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54376 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2023-54375 - Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-y
CVE-2026-67867 - Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of
CVE-2026-67866 - Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of
CVE-2026-67863 - In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. Th
CVE-2026-19026 - H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] w
CVE-2026-19025 - H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's s
CVE-2026-19024 - NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denia
CVE-2026-19023 - Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.
CVE-2026-71321 - Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the
CVE-2026-71320 - Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an
CVE-2026-71319 - Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (developm
CVE-2026-71318 - Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an
CVE-2026-71316 - Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:n
CVE-2026-67865 - S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attac
CVE-2026-67864 - An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via t
CVE-2025-63823 - My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module,
CVE-2025-63822 - SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated att
CVE-2026-71315 - Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mi
CVE-2026-71314 - Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an
CVE-2026-71313 - rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-71312 - rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-71311 - rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-71310 - rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-71309 - rclone is a command-line program to sync files and directories to and from different cloud storage p
CVE-2026-34966 - Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated
CVE-2026-18959 - A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileMa
CVE-2026-18839 - An integer underflow was found in the popt library when formatting help text for option tables that
CVE-2026-18411 - The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Blueto
CVE-2026-17583 - The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid ou
CVE-2026-15996 - A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthe
CVE-2026-70618 - Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any
CVE-2026-70617 - Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any
CVE-2026-70616 - boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticate
CVE-2026-70615 - boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-
CVE-2026-69111 - Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that all
CVE-2026-68746 - Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticat
CVE-2026-66885 - Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authe
CVE-2026-66881 - Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook
CVE-2026-66298 - Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output Java
CVE-2026-66297 - Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerabili
CVE-2026-55524 - PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs it
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.