CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-39434 - Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
CVE-2026-34902 - Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
CVE-2026-34901 - Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
CVE-2026-34900 - Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
CVE-2026-34898 - Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
CVE-2026-34892 - Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
CVE-2026-34891 - Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
CVE-2026-34886 - Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
CVE-2026-27407 - Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
CVE-2026-27333 - Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
CVE-2026-27089 - Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
CVE-2026-27053 - Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
CVE-2026-25440 - Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
CVE-2026-25425 - Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
CVE-2026-24637 - Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
CVE-2026-23970 - Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
CVE-2025-69332 - Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
CVE-2025-68872 - Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <=
CVE-2025-68851 - Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
CVE-2025-68840 - Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
CVE-2025-68049 - Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
CVE-2025-60175 - Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
CVE-2025-59133 - Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
CVE-2026-54444 - Rejected reason: ]** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49489. Reason:
CVE-2026-54296 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12075. Reason:
CVE-2026-54295 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12061. Reason:
CVE-2026-54294 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12072. Reason:
CVE-2026-54292 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12074. Reason:
CVE-2026-53705 - A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a special
CVE-2026-53704 - A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a
CVE-2026-53703 - A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a R
CVE-2026-52722 - A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream
CVE-2026-52721 - Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed P
CVE-2026-52720 - A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle
CVE-2026-52719 - An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad.
CVE-2026-52718 - A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The
CVE-2026-50892 - Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager
CVE-2026-50891 - Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to
CVE-2026-50890 - Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-gro
CVE-2026-50889 - An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a
CVE-2026-50888 - An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Ben
CVE-2026-50887 - A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink
CVE-2026-50886 - Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows at
CVE-2026-50885 - Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unaut
CVE-2026-50884 - Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administr
CVE-2026-50883 - An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows a
CVE-2026-50882 - An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Den
CVE-2026-50881 - Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor priv
CVE-2026-50880 - An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to e
CVE-2026-50879 - An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to c
CVE-2026-50878 - An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to ca
CVE-2026-50877 - An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying f
CVE-2026-50876 - A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitra
CVE-2026-50875 - Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows aut
CVE-2026-50874 - An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Remi
CVE-2026-50873 - An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allo
CVE-2026-50872 - An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attacker
CVE-2026-50871 - An OS command injection vulnerability in the media archiving and export pipeline component of kanish
CVE-2026-50870 - An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1
CVE-2026-50869 - An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory t
CVE-2026-49954 - Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that al
CVE-2026-49953 - Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows
CVE-2026-49952 - Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that
CVE-2026-48114 - Metacat is data repository software that helps researchers preserve, share, and discover data. Versi
CVE-2026-47835 - In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary que
CVE-2026-45390 - In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the
CVE-2026-45389 - In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate pro
CVE-2026-45388 - In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate pro
CVE-2026-41708 - In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause
CVE-2026-39197 - An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to ca
CVE-2026-39196 - Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_q
CVE-2026-39118 - An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privilege
CVE-2026-39007 - An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitiv
CVE-2026-39006 - An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgS
CVE-2026-38812 - RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affect
CVE-2026-38329 - Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /ap
CVE-2026-38065 - Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_
CVE-2026-38064 - Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial
CVE-2026-38063 - Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radi
CVE-2026-38062 - Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_
CVE-2026-38061 - Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_
CVE-2026-38060 - Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlo
CVE-2026-37216 - Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
CVE-2026-36933 - An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execu
CVE-2026-36670 - A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Pa
CVE-2026-36537 - ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code e
CVE-2026-36521 - PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration manag
CVE-2026-36213 - An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges v
CVE-2026-30121 - remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
CVE-2026-30120 - remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability
CVE-2026-11931 - Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose th
CVE-2025-70102 - A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing co
CVE-2025-68713 - An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sen
CVE-2025-56814 - A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to ex
CVE-2025-55663 - A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box
CVE-2025-55661 - A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attacker
CVE-2025-55660 - A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4
CVE-2025-55652 - A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.
CVE-2025-55650 - A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box
CVE-2025-55649 - A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Bo
CVE-2025-55648 - A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPA
CVE-2025-55647 - An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 a
CVE-2025-55645 - A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4
CVE-2025-55644 - A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box
CVE-2025-55643 - A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box
CVE-2025-55642 - GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function
CVE-2025-55641 - A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC
CVE-2026-8358 - LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow exis
CVE-2026-8357 - LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed w
CVE-2026-8356 - LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existe
CVE-2026-6047 - LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when rep
CVE-2026-6045 - LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow exi
CVE-2026-6040 - A heap use-after-free existed when importing the blank-width characters of an ODF number format. A p
CVE-2026-6039 - LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow exist
CVE-2026-49294 - Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data
CVE-2026-47777 - Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a m
CVE-2026-20262 - A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow
CVE-2026-9863 - Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch t
CVE-2026-9862 - Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in th
CVE-2026-9595 - Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true
CVE-2026-8683 - Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long
CVE-2026-5038 - Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of
CVE-2026-10634 - Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tc
CVE-2025-15659 - Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.
CVE-2025-15658 - Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.
CVE-2026-6517 - Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which N
CVE-2026-5242 - Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy
CVE-2026-5233 - Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows
CVE-2026-5230 - Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library al
CVE-2026-5079 - Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service
CVE-2026-52704 - Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce P
CVE-2026-49111 - Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalati
CVE-2026-49064 - Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve E
CVE-2026-49062 - Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows
CVE-2026-48969 - Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
CVE-2025-64215 - Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functiona
CVE-2019-25746 - WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows au
CVE-2018-25437 - WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows
CVE-2018-25436 - WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulne
CVE-2016-20084 - WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities
CVE-2016-20083 - WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows att
CVE-2016-20082 - WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated at
CVE-2016-20081 - WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows una
CVE-2016-20080 - WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability i
CVE-2016-20079 - WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allow
CVE-2016-20078 - WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauth
CVE-2016-20077 - WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauth
CVE-2016-20076 - WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attacker
CVE-2016-20075 - WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows
CVE-2016-20074 - WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that al
CVE-2016-20073 - Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unau
CVE-2016-20072 - BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unaut
CVE-2016-20071 - The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injecti
CVE-2016-20070 - WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site s
CVE-2016-20069 - WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulne
CVE-2016-20068 - WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injecti
CVE-2016-20067 - WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers t
CVE-2016-20066 - WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attack
CVE-2026-5482 - Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extensio
CVE-2026-49757 - Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account tak
CVE-2026-34030 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validat
CVE-2026-34029 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptog
CVE-2026-34028 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file p
CVE-2026-34027 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-
CVE-2026-34026 - Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnera
CVE-2026-34025 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction by
CVE-2026-34024 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorizatio
CVE-2026-34023 - The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authori
CVE-2026-34022 - The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses w
CVE-2026-34021 - The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 com
CVE-2026-12057 - When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails
CVE-2026-50100 - Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a pr
CVE-2026-44188 - A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expirati
CVE-2026-11860 - Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity
CVE-2026-9278 - The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration v
CVE-2026-8935 - The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given
CVE-2026-8386 - The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its
CVE-2026-8385 - The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter
CVE-2026-12223 - A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is t
CVE-2026-12222 - A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.B
CVE-2026-12221 - A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the
CVE-2026-12220 - A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgra
CVE-2026-12219 - A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_dia
CVE-2026-12218 - A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function S
CVE-2026-12217 - A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown f
CVE-2026-12216 - A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown pr
CVE-2026-12214 - A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the
CVE-2026-12213 - A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability
CVE-2026-12212 - A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function
CVE-2026-12211 - A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an
CVE-2026-12210 - A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an u
CVE-2026-12209 - A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element i
CVE-2026-12208 - A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the functi
CVE-2026-12207 - A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b0
CVE-2026-12206 - A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::As
CVE-2026-12204 - A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderC
CVE-2026-12203 - A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This af
CVE-2026-12202 - A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is som
CVE-2026-12201 - A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an un
CVE-2026-12200 - A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impac
CVE-2026-12198 - A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path
CVE-2026-12197 - A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function n
CVE-2026-12193 - A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the f
CVE-2026-12192 - A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component
CVE-2026-12191 - A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pi
CVE-2026-12190 - A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability aff
CVE-2026-12189 - A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown pa
CVE-2026-12188 - A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown fun
CVE-2026-12187 - A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulner
CVE-2026-12186 - A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_co
CVE-2026-54413 - driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read i
CVE-2026-54412 - LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underfl
CVE-2026-54411 - Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module
CVE-2026-54410 - nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of
CVE-2026-11527 - Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via
CVE-2026-11526 - GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of
CVE-2025-15546 - The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when t
CVE-2026-54421 - In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the u
CVE-2026-54420 - LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishand
CVE-2026-12176 - A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Ana
CVE-2026-12175 - A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an u
CVE-2026-12174 - A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the functi
CVE-2026-12183 - Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains a
CVE-2026-6428 - SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before
CVE-2026-5513 - The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to
CVE-2026-1291 - The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a mi
CVE-2026-11624 - The Model Context Protocol has a security warning advising servers to validate the "Origin" header o
CVE-2026-9629 - The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter
CVE-2026-3297 - The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to St
CVE-2026-2470 - The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to In
CVE-2026-9134 - The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_att
CVE-2026-9109 - The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin
CVE-2026-9062 - The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a f
CVE-2026-9061 - The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata bef
CVE-2026-11769 - We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity secur
CVE-2026-9848 - The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query par
CVE-2026-54231 - A content injection vulnerability was found in the ABRT post-create event handler scripts in librepo
CVE-2026-54230 - A symlink following vulnerability was found in the ABRT post-create event handler scripts in librepo
CVE-2026-54229 - A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir
CVE-2026-54228 - A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetEl
CVE-2026-12089 - The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbi
CVE-2026-11443 - Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerabil
CVE-2026-11442 - Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability al
CVE-2026-6676 - Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed PO
CVE-2026-12068 - Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may al
CVE-2025-9033 - Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF
CVE-2025-9032 - Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Win
CVE-2025-14098 - Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when
CVE-2026-54398 - An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object e
CVE-2026-54095 - Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reas
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.