CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-9566 - A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of t
CVE-2026-9560 - Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows a
CVE-2026-9170 - IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code executio
CVE-2026-8856 - IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker
CVE-2026-8855 - IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configu
CVE-2026-8854 - IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cach
CVE-2026-8835 - IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authen
CVE-2026-8834 - IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authentica
CVE-2026-8633 - IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSpher
CVE-2026-8620 - IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSpher
CVE-2026-7454 - A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
CVE-2026-7453 - A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion v
CVE-2026-7452 - A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
CVE-2026-7451 - A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri
CVE-2026-7450 - A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Deref
CVE-2026-7251 - Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attack
CVE-2026-48696 - FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE
CVE-2026-48695 - FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Mik
CVE-2026-48694 - FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the J
CVE-2026-47202 - Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permi
CVE-2026-46624 - Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vuln
CVE-2026-44776 - Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter met
CVE-2026-44775 - Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is
CVE-2026-44749 - The SAP Gateway allows attackers to inject content into error messages, potentially leading to discl
CVE-2026-44730 - OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables.
CVE-2026-44728 - Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-a
CVE-2026-44707 - Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-A
CVE-2026-44706 - Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability
CVE-2026-44669 - FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vu
CVE-2026-44668 - FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControl
CVE-2026-44667 - FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vu
CVE-2026-42448 - Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to a
CVE-2026-41164 - nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the
CVE-2026-24201 - NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could ca
CVE-2026-24200 - NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could ca
CVE-2026-24199 - NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could caus
CVE-2026-24198 - NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a
CVE-2026-24197 - NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition m
CVE-2026-24196 - NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds r
CVE-2026-24195 - NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper i
CVE-2026-24194 - NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a use
CVE-2026-24193 - NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause a
CVE-2026-24192 - NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect
CVE-2026-24191 - NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-c
CVE-2026-24190 - NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where
CVE-2026-24187 - NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-f
CVE-2026-24182 - NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak he
CVE-2025-33221 - NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a u
CVE-2026-9565 - A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dan
CVE-2026-9564 - A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.
CVE-2026-9562 - A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244
CVE-2026-8852 - IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi
CVE-2026-8850 - IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_uplo
CVE-2026-48905 - Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48904 - An improper access check allows privelege escalation through the com_users group editing webservice
CVE-2026-48903 - Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in vario
CVE-2026-48902 - The password and username reset features created plain http links for https connections if the "Forc
CVE-2026-48901 - The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache
CVE-2026-48900 - An improper access check allowed low privileged users to edit the task types of existing scheduler t
CVE-2026-48899 - An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898 - An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48897 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48896 - Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48864 - A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-c
CVE-2026-48697 - FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connec
CVE-2026-48693 - FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable f
CVE-2026-48691 - FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute
CVE-2026-48690 - FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet
CVE-2026-48126 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started wit
CVE-2026-48091 - Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-47728 - Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug
CVE-2026-47716 - Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list v
CVE-2026-47715 - Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a dir
CVE-2026-46431 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Acces
CVE-2026-46430 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound t
CVE-2026-45836 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-
CVE-2026-45835 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-
CVE-2026-45834 - In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-
CVE-2026-45728 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked wit
CVE-2026-45721 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for a
CVE-2026-44729 - Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /fi
CVE-2026-44723 - Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds
CVE-2026-44680 - MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map pattern
CVE-2026-44502 - Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could
CVE-2026-44314 - Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorize
CVE-2026-43982 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/
CVE-2026-43981 - Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the
CVE-2026-40384 - An improper validation of the search parameter of the com_media files API endpoint leads to a path t
CVE-2026-40383 - An improper validation of user-supplied input leads to a local file inclusion vulnerability.
CVE-2026-35223 - An improper access check allows unauthorized access to com_config webservice endpoints.
CVE-2026-35222 - Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.
CVE-2026-35221 - Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_fi
CVE-2026-35220 - Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_u
CVE-2026-30895 - Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVE-2026-30894 - Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-2264 - A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to
CVE-2026-25901 - Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-25900 - Lack of output escaping leads to a XSS vector in the feed modules.
CVE-2026-24212 - NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitte
CVE-2026-24162 - NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper de
CVE-2025-36221 - IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data Sys
CVE-2025-36220 - IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data Sys
CVE-2025-36148 - IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM
CVE-2025-36145 - IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound con
CVE-2025-36126 - IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is
CVE-2025-14290 - IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS
CVE-2025-13755 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 C
CVE-2026-48692 - FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentic
CVE-2026-48688 - FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH
CVE-2026-48687 - FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Jun
CVE-2026-48686 - FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (N
CVE-2026-48685 - FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly pa
CVE-2026-48684 - FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options
CVE-2026-48683 - FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFl
CVE-2026-46620 - e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF t
CVE-2026-43936 - e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by s
CVE-2026-43935 - e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in
CVE-2026-43934 - e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exi
CVE-2026-40564 - Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerabilit
CVE-2026-38587 - An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace befor
CVE-2026-25112 - A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalati
CVE-2026-9552 - A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerabili
CVE-2026-9551 - A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the func
CVE-2026-9550 - A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance C
CVE-2026-4480 - A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description
CVE-2026-46368 - luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-pro
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection
CVE-2026-45082 - Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection
CVE-2026-43919 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason:
CVE-2026-42785 - OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrator
CVE-2026-42425 - OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated adminis
CVE-2026-42347 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason:
CVE-2026-41917 - OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interfac
CVE-2026-41401 - libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags
CVE-2026-40034 - gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the up
CVE-2026-40033 - FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allow
CVE-2026-9544 - A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System
CVE-2026-9543 - A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setP
CVE-2026-9542 - A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an
CVE-2026-9541 - A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of th
CVE-2026-9540 - A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processi
CVE-2026-8479 - IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing,
CVE-2026-8174 - Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue
CVE-2026-7374 - A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated Op
CVE-2026-7310 - A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An auth
CVE-2026-48136 - When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator wi
CVE-2026-48135 - A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is relate
CVE-2026-48134 - When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice
CVE-2026-48133 - When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated u
CVE-2026-48132 - The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is
CVE-2026-48131 - The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP duri
CVE-2025-11482 - An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in P
CVE-2026-44410 - This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application fun
CVE-2026-39661 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2026-39642 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabR
CVE-2026-27427 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-25713 - MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
CVE-2026-25104 - MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
CVE-2026-24638 - Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Co
CVE-2026-24590 - Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploitin
CVE-2026-8047 - The affected products perform improper length checking when parsing incoming HTTP requests, resultin
CVE-2026-8046 - The affected products insufficiently verify authorization when deleting user accounts. An authentica
CVE-2026-44469 - The affected product extracts installation files to a temporary directory with incorrect default per
CVE-2026-44468 - The affected product creates a directory with insecure default permissions during administrative ins
CVE-2026-39655 - Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Confi
CVE-2026-9534 - A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of
CVE-2026-9533 - A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function re
CVE-2026-9532 - A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is t
CVE-2026-9496 - Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (Do
CVE-2026-9495 - Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control B
CVE-2026-3314 - Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Anal
CVE-2026-9531 - A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUb
CVE-2026-9530 - A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read
CVE-2026-9529 - A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function
CVE-2026-9528 - A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown
CVE-2026-9527 - A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects som
CVE-2026-9526 - A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects
CVE-2026-9525 - A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknow
CVE-2026-9524 - A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the
CVE-2026-9523 - A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Clo
CVE-2026-9538 - Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry siz
CVE-2026-9521 - A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function
CVE-2026-9520 - A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown func
CVE-2026-9519 - A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the funct
CVE-2026-9518 - A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted eleme
CVE-2026-4795 - A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0,
CVE-2026-42497 - Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside th
CVE-2026-42496 - Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside
CVE-2025-71310 - The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors
CVE-2026-9517 - A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected eleme
CVE-2026-9515 - A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function se
CVE-2026-8376 - Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a
CVE-2026-9514 - A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function
CVE-2026-9513 - A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSy
CVE-2026-9512 - A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the f
CVE-2026-48837 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-45438 - Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Inc
CVE-2026-45435 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-45217 - Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment G
CVE-2026-45216 - Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
CVE-2026-45209 - Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrect
CVE-2026-42776 - Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly
CVE-2026-42774 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-42773 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-42763 - Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive D
CVE-2026-39436 - Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forge
CVE-2026-32389 - Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured
CVE-2026-24937 - Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcas
CVE-2026-9511 - A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanI
CVE-2026-9504 - A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU o
CVE-2026-27398 - Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrec
CVE-2026-27357 - Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly
CVE-2026-27346 - Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configure
CVE-2026-24592 - Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorre
CVE-2026-24586 - Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Ac
CVE-2026-24582 - Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Acc
CVE-2026-24554 - Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Requ
CVE-2026-24527 - Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscrip
CVE-2025-62745 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-9503 - A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_e
CVE-2026-9502 - A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R200
CVE-2026-9501 - A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function deco
CVE-2026-9500 - A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004
CVE-2026-48852 - PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
CVE-2026-48851 - PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the t
CVE-2026-48850 - PuTTY 0.72 before 0.84 has a double free in RSA KEX.
CVE-2026-48589 - Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect aft
CVE-2026-44598 - With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Reque
CVE-2026-43828 - Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attr
CVE-2026-43827 - Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Ap
CVE-2026-24597 - Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Req
CVE-2026-24574 - Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows C
CVE-2026-24545 - Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Conf
CVE-2026-9498 - A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyCla
CVE-2026-9497 - A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function F
CVE-2026-9486 - A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This aff
CVE-2026-9485 - A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by t
CVE-2026-9484 - A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by t
CVE-2026-48849 - In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the
CVE-2026-48848 - Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that c
CVE-2026-48847 - Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary fi
CVE-2026-48846 - In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature c
CVE-2026-48845 - In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking w
CVE-2026-48844 - Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in L
CVE-2026-48843 - Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading
CVE-2026-48842 - Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in
CVE-2026-24546 - Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configur
CVE-2026-9483 - A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unk
CVE-2026-9482 - A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the
CVE-2026-9481 - A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /go
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.