CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-8164 - Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade
CVE-2026-7521 - Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail t
CVE-2026-6879 - `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when us
CVE-2026-67178 - MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrec
CVE-2026-67174 - Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolutio
CVE-2026-66713 - Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache So
CVE-2026-66299 - Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This iss
CVE-2026-63727 - Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation
CVE-2026-51261 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51260 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51259 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51254 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51252 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-51251 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-67173 - Pivotick did not validate the URL scheme of node imagePath values derived from graph data before ass
CVE-2026-66922 - Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node iden
CVE-2026-66921 - Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName v
CVE-2026-61487 - Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
CVE-2026-59878 - Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ Al
CVE-2026-7187 - Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Ac
CVE-2026-66920 - Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and
CVE-2026-66919 - Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node lab
CVE-2026-66918 - Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIco
CVE-2026-66913 - Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed
CVE-2026-65882 - Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url param
CVE-2026-65881 - Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account acces
CVE-2026-62436 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-62435 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-62434 - A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't reg
CVE-2026-62433 - Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for
CVE-2026-62432 - The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without
CVE-2026-62431 - The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled
CVE-2026-62430 - Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs t
CVE-2026-62429 - Accessing the vNUMA configuration data of a guest is still possible when domain destruction has alre
CVE-2026-62428 - When grant-copy operations are processed, the respective grant may or may not already be in use by a
CVE-2026-62427 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-62426 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-62425 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-62424 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-62423 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-49332 - A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only
CVE-2026-42495 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-42494 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-42493 - Addressing certain issues, in particular related to operations which may take excessively long and t
CVE-2026-42492 - Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and
CVE-2026-41874 - Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows
CVE-2026-18047 - A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL
CVE-2026-18038 - A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the
CVE-2026-15393 - The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates
CVE-2026-15016 - The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for W
CVE-2026-4648 - Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from
CVE-2026-21047 - Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potenti
CVE-2026-16774 - The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu
CVE-2026-16773 - The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulner
CVE-2026-15444 - The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic S
CVE-2026-15411 - The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, S
CVE-2026-15025 - The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPre
CVE-2026-13440 - The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, S
CVE-2026-13110 - The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in version
CVE-2026-65880 - Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An
CVE-2026-63303 - A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests,
CVE-2026-63302 - Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter.
CVE-2026-63301 - In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitti
CVE-2026-18029 - Our payment integration with GiroCheckout did not properly validate payment status responses. An at
CVE-2026-18028 - The "quick setup" view presented to users after they first create an event allows to set up the mos
CVE-2026-17072 - A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occ
CVE-2026-65624 - Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an una
CVE-2026-59248 - Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated r
CVE-2026-58246 - SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier info
CVE-2026-16462 - In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unaut
CVE-2026-14785 - The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels'
CVE-2026-14328 - The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is
CVE-2026-11841 - An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via
CVE-2026-11598 - The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortco
CVE-2026-10207 - The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up t
CVE-2026-9680 - Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers t
CVE-2026-8167 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-61376 - ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability
CVE-2026-59764 - ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability
CVE-2026-44387 - ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulne
CVE-2026-15267 - The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress i
CVE-2026-14516 - The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to
CVE-2026-14171 - An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of
CVE-2026-14170 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-14169 - Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent
CVE-2026-14168 - A low privileged remote attacker can gain administrator privileges due to missing authorization at t
CVE-2026-14167 - A low privileged remote attacker can perform privileged configuration changes reserved for the admin
CVE-2026-13161 - The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to gene
CVE-2026-12800 - The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Inje
CVE-2026-55977 - Successful exploitation of this vulnerability could allow an attacker with local network access to b
CVE-2026-15730 - The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plug
CVE-2026-15673 - The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for
CVE-2026-15671 - The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for
CVE-2026-15670 - The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for
CVE-2026-15014 - The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for
CVE-2026-12741 - The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic
CVE-2026-11756 - A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE pla
CVE-2024-14041 - In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided s
CVE-2026-6251 - The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in
CVE-2026-16811 - The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vu
CVE-2026-16797 - The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vu
CVE-2026-16587 - The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to aut
CVE-2026-16585 - The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress i
CVE-2026-15136 - The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-
CVE-2026-15012 - The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to A
CVE-2026-14926 - The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscrip
CVE-2026-14924 - The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability,
CVE-2026-14870 - The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not pro
CVE-2026-14821 - The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check
CVE-2026-14819 - The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event tit
CVE-2026-14545 - The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a u
CVE-2026-14490 - The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to A
CVE-2026-12124 - The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Desi
CVE-2026-17528 - Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via t
CVE-2026-17524 - Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching m
CVE-2026-66473 - Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-65448 - Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1
CVE-2026-65447 - Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-65446 - Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
CVE-2026-65445 - Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
CVE-2026-65443 - Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65442 - Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-65441 - Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-65440 - Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-65439 - Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
CVE-2026-65438 - Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
CVE-2026-65437 - Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.
CVE-2026-61957 - Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61953 - Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-51565 - Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 al
CVE-2025-63913 - An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted r
CVE-2026-59240 - The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationCont
CVE-2026-55685 - React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be
CVE-2026-53669 - React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect t
CVE-2026-53668 - React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, appl
CVE-2026-53667 - React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missin
CVE-2026-53666 - React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was writte
CVE-2026-51564 - An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users t
CVE-2026-51078 - An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str
CVE-2026-51077 - SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive infor
CVE-2021-32088 - An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpo
CVE-2021-32087 - An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with
CVE-2021-32086 - An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcod
CVE-2021-32085 - An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with
CVE-2021-32084 - An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer res
CVE-2026-66825 - Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Value
CVE-2026-66824 - A stored cross-site scripting vulnerability existed in the capture tree visualization page. The appl
CVE-2026-64783 - A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
CVE-2026-64776 - The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, ma
CVE-2026-64775 - A memory initialization issue was addressed with improved memory handling. This issue is fixed in iO
CVE-2026-64774 - An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10
CVE-2026-64772 - An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iO
CVE-2026-64771 - A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 an
CVE-2026-64770 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-64769 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-64768 - An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS
CVE-2026-64767 - A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia
CVE-2026-64766 - An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10
CVE-2026-64765 - An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10
CVE-2026-64764 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-64763 - An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in i
CVE-2026-64762 - An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1
CVE-2026-64758 - The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6
CVE-2026-64757 - A memory corruption issue was addressed with improved state management. This issue is fixed in Safar
CVE-2026-64755 - An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7
CVE-2026-64754 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-64751 - A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
CVE-2026-64749 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-64747 - A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 an
CVE-2026-64746 - An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 an
CVE-2026-64745 - This issue was addressed with additional restrictions on the lock screen. This issue is fixed in mac
CVE-2026-64744 - An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10
CVE-2026-64743 - An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7
CVE-2026-64742 - This issue was addressed by using HTTPS when sending information over the network. This issue is fix
CVE-2026-64741 - A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and
CVE-2026-64740 - A parsing issue in the handling of directory paths was addressed with improved path validation. This
CVE-2026-64739 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-64738 - A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 a
CVE-2026-64737 - An authorization issue was addressed with improved state management. This issue is fixed in macOS Se
CVE-2026-64735 - An inconsistent user interface issue was addressed with improved state management. This issue is fix
CVE-2026-64734 - The issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,
CVE-2026-64733 - This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 2
CVE-2026-64732 - This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and i
CVE-2026-64731 - A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 1
CVE-2026-64730 - The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26
CVE-2026-64729 - A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
CVE-2026-64728 - A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS
CVE-2026-64727 - A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tah
CVE-2026-64726 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-64725 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-64724 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-64723 - A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7
CVE-2026-64722 - A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7
CVE-2026-64721 - This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and i
CVE-2026-64720 - A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPa
CVE-2026-64719 - An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Sa
CVE-2026-64718 - A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari
CVE-2026-64716 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-64713 - This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPad
CVE-2026-64711 - This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPa
CVE-2026-64710 - A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.
CVE-2026-64709 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-64708 - A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia
CVE-2026-64707 - A permissions issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and i
CVE-2026-64704 - A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Seq
CVE-2026-64703 - A use after free issue was addressed with improved memory management. This issue is fixed in macOS S
CVE-2026-64702 - An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Seq
CVE-2026-64700 - A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
CVE-2026-64699 - A memory initialization issue was addressed with improved memory handling. This issue is fixed in ma
CVE-2026-64698 - The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8,
CVE-2026-64697 - The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8,
CVE-2026-64696 - The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8,
CVE-2026-64695 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-64694 - An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequo
CVE-2026-64693 - A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iP
CVE-2026-64692 - An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1
CVE-2026-64691 - A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26
CVE-2026-64555 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix SPSR_EL2 re
CVE-2026-64554 - In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale pr
CVE-2026-64553 - In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in
CVE-2026-64552 - In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in re
CVE-2026-64551 - In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cau
CVE-2026-64550 - In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: validate
CVE-2026-64549 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bpa10x: avoid OOB re
CVE-2026-64548 - In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: reject overflowin
CVE-2026-64547 - In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate pac
CVE-2026-64546 - In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix OOB read in drm_p
CVE-2026-64545 - In the Linux kernel, the following vulnerability has been resolved: net, bpf: check master for NULL
CVE-2026-64544 - In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - fix O
CVE-2026-64543 - In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the
CVE-2026-64542 - In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in
CVE-2026-64541 - In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_
CVE-2026-64540 - In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-boun
CVE-2026-64539 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix stack OOB w
CVE-2026-64538 - In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix null-ptr-deref in fib
CVE-2026-64537 - In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: reject invalid CCM
CVE-2026-59730 - Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailin
CVE-2026-59728 - Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.t
CVE-2026-43822 - A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
CVE-2026-43821 - An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6,
CVE-2026-43819 - An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tah
CVE-2026-43818 - An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10
CVE-2026-43817 - An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 a
CVE-2026-43816 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS
CVE-2026-43814 - A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.
CVE-2026-43813 - A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 a
CVE-2026-43812 - A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.
CVE-2026-43811 - A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 1
CVE-2026-43810 - The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS
CVE-2026-43809 - An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.