CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
28347 CVEs gefunden (Seite 28/114)

CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server be

🏢 Aws 📅 5.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-18953 - Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awsla

🏢 Aws 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-17556 - A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-9205 - IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-9201 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary cod

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-9196 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended co

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-9130 - IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryCom

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-8478 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-8470 - IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-8183 - IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.7
7.7

CVE-2026-8182 - IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrar

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-7869 - IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`P

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-7658 - IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attack

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-70612 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-63457 - A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v

🏢 Hpe 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-48168 - PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Acti

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 10.0
10.0

CVE-2026-18485 - There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.

🏢 Microsoft 📅 5.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-17633 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-17632 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-17624 - IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-10547 - IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /a

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-9081 - IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forge

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-7657 - IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-70611 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.9
6.9

CVE-2026-70610 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-70609 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.7
5.7

CVE-2026-70608 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-70448 - Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-70447 - Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Over

🏢 Aws 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70446 - Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70445 - Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Ov

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70444 - A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70443 - Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context f

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70442 - Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate

🏢 Google 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70441 - Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-70440 - Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controll

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-70439 - Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing at

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-70438 - A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows a

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70437 - Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a cons

🏢 F5 📅 5.8.2026 📊 CVSS: 3.7
3.7

CVE-2026-70436 - Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70435 - A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Ov

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-70434 - A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier a

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.2
4.2

CVE-2026-70433 - Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overa

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70432 - A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-70431 - Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do n

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-70430 - Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can b

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 2.7
2.7

CVE-2026-70429 - Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and grou

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-70428 - Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70427 - Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effect

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70426 - In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.57

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.0
9.0

CVE-2026-44605 - A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer o

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-17625 - IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-10716 - Directus contains an authenticated SQL injection vulnerability in the collection creation flow when

🏢 Postgresql 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-10128 - IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow com

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-9077 - IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass local

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-8446 - IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Co

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-7646 - IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesyste

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-70607 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-20313 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

🏢 Cisco 📅 5.8.2026 📊 CVSS: 7.7
7.7

CVE-2026-20312 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-20311 - A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authen

🏢 Cisco 📅 5.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-20310 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

🏢 Cisco 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-20308 - A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authen

🏢 Cisco 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-20304 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

🏢 Cisco 📅 5.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-20303 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst

🏢 Cisco 📅 5.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-20301 - A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20294 - A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow a

🏢 Cisco 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-20289 - A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacke

🏢 Cisco 📅 5.8.2026 📊 CVSS: 5.7
5.7

CVE-2026-20288 - A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem

🏢 Cisco 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-20273 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20272 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-20271 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20270 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20269 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20268 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20267 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So

🏢 Cisco 📅 5.8.2026 📊 CVSS: 9.0
9.0

CVE-2026-20263 - A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software c

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-20200 - A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem

🏢 Cisco 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-20198 - A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC

🏢 Cisco 📅 5.8.2026 📊 CVSS: 4.8
4.8

CVE-2026-20124 - A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software

🏢 Cisco 📅 5.8.2026 📊 CVSS: 7.7
7.7

CVE-2026-20028 - A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authentica

🏢 Cisco 📅 5.8.2026 📊 CVSS: 5.0
5.0

CVE-2026-18927 - A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-17630 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-17626 - IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-17623 - IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-17617 - IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SS

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-14587 - Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-9203 - A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 al

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-9195 - A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.3
9.3

CVE-2026-9193 - An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Serve

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-9192 - An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-9190 - An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 1

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-8709 - An improper privilege management vulnerability in the REST API document patch operation of Progress

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-8400 - IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continu

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-7557 - An improper verification of cryptographic signature vulnerability in the SAML authentication module

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-7329 - An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces o

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-7327 - An improper privilege management vulnerability in the REST API document processing pipeline of Progr

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-7326 - A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-70606 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-70605 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-70604 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-70603 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.0
6.0

CVE-2026-70602 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.6
6.6

CVE-2026-70601 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-70600 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 3.1
3.1

CVE-2026-70599 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.9
5.9

CVE-2026-70598 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 3.9
3.9

CVE-2026-70597 - Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.3
6.3

CVE-2026-70596 - Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue all

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-70595 - Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed s

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.0
4.0

CVE-2026-60053 - Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: t

🏢 Apache 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-60023 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This iss

🏢 Apache 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-53992 - ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.p

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-50749 - Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.

🏢 Apache 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-49331 - A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-r

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-48912 - Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through

🏢 Apache 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-48911 - Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects A

🏢 Apache 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-48834 - Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affe

🏢 Apache 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-39924 - Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers w

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.8
6.8

CVE-2026-39923 - Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthe

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-32835 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-18531 - IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-16442 - A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federati

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-15656 - IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization to

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-15587 - Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google C

🏢 Google cloud 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-15572 - A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Al

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-13477 - IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an aut

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.7
4.7

CVE-2026-12762 - IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attack

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-12730 - IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fi

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 3.8
3.8

CVE-2026-10025 - IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML Externa

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-54876 - Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-17613 - Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowin

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-16102 - A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and acc

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-16100 - A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the syst

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-16071 - A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-15573 - A flaw was found in Keycloak's Authorization Services. The component responsible for matching reques

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-12410 - Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-7529 - The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthori

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-7456 - The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a mis

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-67623 - Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to e

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-17506 - The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-16443 - A flaw was found in the SAML metadata import functionality of the keycloak-services component, which

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.4
7.4

CVE-2026-15979 - The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable t

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2025-70962 - Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains ha

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-71294 - Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that m

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.6
7.6

CVE-2026-71293 - Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contain

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.2
6.2

CVE-2026-71292 - Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admi

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-71291 - Bolt CMS renders content field values through Twig's full application-level Environment with no Sand

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-71289 - The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default dock

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71288 - Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-71287 - Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-71286 - The render-template component of ember-dynamic-render-template (addon/components/render-template.js)

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-71285 - Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-71284 - Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restor

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-71283 - Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restor

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.9
4.9

CVE-2026-71282 - ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_coun

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71281 - Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~1

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-71280 - go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL usin

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-71279 - Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter receiv

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.0
8.0

CVE-2026-71278 - rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71277 - rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-71276 - Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (reade

🏢 Postgresql 📅 5.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-71275 - OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter dir

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.4
5.4

CVE-2026-71274 - OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQT

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-71273 - OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71272 - Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target h

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-71271 - Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP ag

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.5
8.5

CVE-2026-71270 - Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-71269 - Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-71268 - OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.9
9.9

CVE-2026-71267 - microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71266 - tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl ma

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-71265 - Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies ne

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-71264 - WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no setting

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-71263 - The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP

🏢 Linux 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-71262 - IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71261 - dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-71260 - ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServe

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71259 - ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-71227 - A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchrono

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.1
5.1

CVE-2026-71226 - Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an e

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-71225 - A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-16022 - @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functiona

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-0516 - A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71256 - nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in n

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71255 - nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_devic

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.6
8.6

CVE-2026-71254 - nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_fil

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-64582 - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free

🏢 Linux 📅 5.8.2026 📊 CVSS: 7.8
7.8

CVE-2026-61891 - In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP f

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-46581 - In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not prope

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-18933 - The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line),

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-71252 - toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners,

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.2
8.2

CVE-2026-71251 - Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at u

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71250 - Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 range

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-71249 - 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST f

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.1
6.1

CVE-2026-71248 - Inventory-Management-System-PHP's login.php constructs its authentication query via direct string co

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71247 - Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71246 - Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search paramet

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-71245 - Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-71244 - Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a mask

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71243 - The backmeup npm package assembles shell command strings by directly concatenating its option values

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-71242 - Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with n

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.3
8.3

CVE-2026-71241 - Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_no

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-71240 - DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in l

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-71239 - DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Dja

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-71238 - DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py ra

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-71237 - Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly fro

🏢 Mysql 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71236 - Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestB

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.7
8.7

CVE-2026-71235 - Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-71234 - Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, re

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-71233 - InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Larave

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.7
8.7

CVE-2026-71232 - MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP fu

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-71231 - IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM us

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-66747 - Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every pub

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-60009 - In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /f

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.8
8.8

CVE-2026-17578 - Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reachin

🏢 Aws 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-14574 - In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-14304 - In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.5
5.5

CVE-2026-12609 - In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend expo

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-44945 - A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-25703 - NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to m

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.3
7.3

CVE-2026-15452 - The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 4.7
4.7

CVE-2026-0931 - Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticat

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 0.0
0.0

CVE-2026-8029 - The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNIO

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 3.9
3.9

CVE-2026-10090 - A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.0
9.0

CVE-2026-10059 - A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant admin

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-7726 - The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-7693 - The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up t

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 7.2
7.2

CVE-2026-7520 - The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-7444 - The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 8.1
8.1

CVE-2026-7441 - The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 6.4
6.4

CVE-2026-7105 - The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 4.3
4.3

CVE-2026-71215 - art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-71214 - The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derive

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71213 - Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, fail

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.1
9.1

CVE-2026-71212 - xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 4.4
4.4

CVE-2026-71211 - MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/ser

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.1
7.1

CVE-2026-71210 - Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostnam

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-71209 - audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-all

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-71208 - KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71207 - The Stock-Inventory-Management-System application's login.php assigns raw username/password values t

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.8
9.8

CVE-2026-71206 - Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 8.3
8.3

CVE-2026-71205 - changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.5
6.5

CVE-2026-71204 - changedetection.io's /settings save handler builds an update dict from form.data['application'] and

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 6.2
6.2

CVE-2026-71203 - changedetection.io's REST API resources are protected by an @auth.check_token decorator validating t

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 5.3
5.3

CVE-2026-71202 - The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source di

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-70378 - imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating tha

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-70377 - imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (di

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 7.5
7.5

CVE-2026-70376 - Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in da

🏢 Sonstige 📅 5.8.2026 📊 CVSS: 9.6
9.6

CVE-2026-6972 - The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_s

🏢 Wordpress 📅 5.8.2026 📊 CVSS: 6.4
6.4
«« « Zurück Seite 28 von 114 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.