CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-53837 - OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handl
CVE-2026-53836 - OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command h
CVE-2026-53835 - OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic
CVE-2026-53834 - OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash
CVE-2026-53833 - OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming comm
CVE-2026-53832 - OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-h
CVE-2026-53831 - OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowli
CVE-2026-53830 - OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers
CVE-2026-53829 - OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticat
CVE-2026-53828 - OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling t
CVE-2026-53827 - OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding t
CVE-2026-53826 - OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spaw
CVE-2026-53825 - OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest fea
CVE-2026-53824 - OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked sl
CVE-2026-53823 - OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that
CVE-2026-53822 - OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could
CVE-2026-53821 - OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server
CVE-2026-53820 - OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback
CVE-2026-53609 - ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4
CVE-2026-53608 - ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.
CVE-2026-53523 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-53522 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-53521 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-53520 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-53519 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prio
CVE-2026-49397 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-49396 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-48119 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-47268 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-47124 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-47120 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-46717 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-46716 - Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From
CVE-2026-41158 - Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitra
CVE-2026-41157 - A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trig
CVE-2026-41155 - An attacker could cooperatively pass data from one secure GPU process to another secure GPU process
CVE-2026-34195 - Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API ca
CVE-2026-12131 - A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability
CVE-2025-7019 - Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may a
CVE-2025-7018 - Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows P
CVE-2025-7017 - Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Win
CVE-2025-7011 - Heap out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed zip file containi
CVE-2025-7010 - Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malfor
CVE-2025-7009 - Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE
CVE-2025-7008 - Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE
CVE-2025-7006 - Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE
CVE-2025-7005 - Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file ma
CVE-2025-7004 - Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows P
CVE-2025-7003 - Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF
CVE-2025-7002 - Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF
CVE-2020-2521 - Rejected reason: This candidate was issued in error.
CVE-2026-54397 - A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit
CVE-2026-54396 - An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a valida
CVE-2026-54395 - MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The url
CVE-2026-54394 - MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable
CVE-2026-54393 - A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setH
CVE-2026-54362 - An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-
CVE-2026-54057 - Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-con
CVE-2026-54056 - Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow
CVE-2026-53607 - ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4
CVE-2026-53606 - ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simp
CVE-2026-4870 - IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading
CVE-2026-47264 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-47263 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-45775 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-45085 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-45014 - ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29
CVE-2026-45013 - ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29
CVE-2026-45012 - ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29
CVE-2026-45011 - ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross
CVE-2026-44990 - ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simp
CVE-2026-44786 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-44785 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-44784 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-44783 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-44782 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-44780 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-44779 - Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2
CVE-2026-42853 - ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cl
CVE-2026-24618 - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThem
CVE-2026-12130 - A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects
CVE-2026-12129 - A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this i
CVE-2026-54361 - MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collecti
CVE-2026-54360 - A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a ne
CVE-2026-54359 - MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header co
CVE-2026-54358 - An incorrect authorization vulnerability in MISP allows an organization administrator to target site
CVE-2026-54357 - An improper authorization vulnerability in MISP allowed an authenticated organization administrator
CVE-2026-54055 - Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalat
CVE-2026-50552 - Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server
CVE-2026-50287 - AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenti
CVE-2026-47260 - Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the pod
CVE-2026-43872 - Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints ar
CVE-2026-42890 - Actual is an open-source personal finance application. In the macOS desktop application version 25.x
CVE-2026-42851 - Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write b
CVE-2026-42850 - Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject
CVE-2026-42604 - Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's
CVE-2026-53726 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
CVE-2026-53725 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
CVE-2026-53724 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
CVE-2026-53408 - Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for A
CVE-2026-53407 - Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for A
CVE-2026-50244 - The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch
CVE-2026-50108 - The Naxclow platform API that returns device relay registration details exposes a persistent credent
CVE-2026-50101 - Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued t
CVE-2026-50099 - During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated
CVE-2026-50008 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
CVE-2026-47248 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
CVE-2026-47236 - Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explici
CVE-2026-47138 - Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.
CVE-2026-42947 - A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind
CVE-2026-42932 - Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, produ
CVE-2026-42306 - Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon
CVE-2026-41568 - Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon
CVE-2026-28742 - Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embed
CVE-2026-12143 - form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5,
CVE-2026-12043 - Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library m
CVE-2026-10715 - Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autos
CVE-2026-53406 - Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows
CVE-2026-48558 - SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass v
CVE-2026-48165 - MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27
CVE-2026-48163 - MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27
CVE-2026-47965 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds writ
CVE-2026-47225 - Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache
CVE-2026-47223 - NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0
CVE-2026-47216 - Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unaut
CVE-2026-44173 - MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26
CVE-2026-44172 - MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an appli
CVE-2026-44171 - MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26
CVE-2026-44170 - MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26
CVE-2026-44169 - MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11
CVE-2026-44168 - MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26
CVE-2026-7387 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mat
CVE-2026-7184 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Rem
CVE-2026-6961 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mat
CVE-2026-6739 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fai
CVE-2026-6689 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fai
CVE-2026-6046 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fai
CVE-2026-53982 - Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow tha
CVE-2026-53981 - Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism th
CVE-2026-47224 - NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0
CVE-2026-47222 - NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0
CVE-2026-3840 - A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a c
CVE-2026-3433 - Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fai
CVE-2026-9641 - Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iteratio
CVE-2026-9638 - Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These ve
CVE-2026-8828 - A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any
CVE-2026-5792 - Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing
CVE-2026-53568 - Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a
CVE-2026-50560 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-50091 - Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same libl
CVE-2026-50090 - The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a
CVE-2026-50089 - The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of
CVE-2026-50088 - The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.
CVE-2026-50087 - The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerabili
CVE-2026-50086 - The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the p
CVE-2026-50085 - The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards th
CVE-2026-50084 - The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer
CVE-2026-50083 - The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is
CVE-2026-50082 - The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address
CVE-2026-50026 - Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of
CVE-2026-50020 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-50011 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-50010 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-50009 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-48748 - Netty is a network application framework for development of protocol servers and clients. Starting i
CVE-2026-48059 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-48043 - Netty is a network application framework for development of protocol servers and clients. In netty-c
CVE-2026-48006 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-47691 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-47190 - IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, an
CVE-2026-47182 - Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user c
CVE-2026-46690 - unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sende
CVE-2026-45833 - A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an a
CVE-2026-45832 - All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database
CVE-2026-45831 - The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaD
CVE-2026-45830 - A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows
CVE-2026-44976 - Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any
CVE-2026-44975 - Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authen
CVE-2026-44967 - OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP
CVE-2026-44208 - Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of va
CVE-2026-44207 - Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vu
CVE-2026-44206 - Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema
CVE-2026-40677 - The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a ma
CVE-2026-8694 - Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthent
CVE-2026-7368 - The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid c
CVE-2026-6853 - Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe
CVE-2026-6211 - Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc.
CVE-2026-54133 - jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elem
CVE-2026-53787 - Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary fil
CVE-2026-53722 - Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <Nu
CVE-2026-53721 - Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 a
CVE-2026-47739 - Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS
CVE-2026-47244 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-47210 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerabilit
CVE-2026-47209 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in b
CVE-2026-47208 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox br
CVE-2026-47141 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-w
CVE-2026-47140 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangero
CVE-2026-47139 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding pub
CVE-2026-47137 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gw
CVE-2026-47135 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-
CVE-2026-47131 - vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call
CVE-2026-46340 - Netty is a network application framework for development of protocol servers and clients. In version
CVE-2026-45674 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-45673 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-45536 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-45416 - Netty is a network application framework for development of protocol servers and clients. Prior to v
CVE-2026-44894 - Netty is a network application framework for development of protocol servers and clients. NoQuicToke
CVE-2026-44893 - Netty is a network application framework for development of protocol servers and clients. In netty-c
CVE-2026-44205 - Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerabil
CVE-2026-41581 - Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a
CVE-2026-10557 - The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical
CVE-2026-54102 - Rejected reason: Reserved but no longer needed.
CVE-2026-54101 - Rejected reason: Reserved but no longer needed.
CVE-2026-49993 - Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpa
CVE-2026-47200 - Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.
CVE-2026-46342 - Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6
CVE-2026-45670 - Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpa
CVE-2026-45669 - Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 an
CVE-2026-1836 - The system stores the username and password from the login form after submitting the request. This c
CVE-2026-12066 - A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the functio
CVE-2026-12065 - A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This
CVE-2026-11967 - MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execu
CVE-2026-11879 - MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execu
CVE-2017-20240 - Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions us
CVE-2026-49347 - Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket p
CVE-2026-48485 - Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentio
CVE-2026-47197 - Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discor
CVE-2026-47196 - Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user i
CVE-2026-47195 - Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands chec
CVE-2026-9266 - A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux fir
CVE-2026-11849 - The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnera
CVE-2026-11848 - The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnera
CVE-2026-50645 - There is no restriction on the amount of attachment headers that a message can contain when being de
CVE-2026-50634 - A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to proce
CVE-2026-50633 - A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can
CVE-2026-50632 - A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lea
CVE-2026-50631 - A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Toke
CVE-2026-50630 - A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the
CVE-2026-50629 - The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log
CVE-2026-50628 - A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP addres
CVE-2026-50627 - The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc
CVE-2026-50623 - An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF.
CVE-2026-49875 - Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w
CVE-2026-48914 - A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly
CVE-2026-11847 - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal v
CVE-2026-11846 - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File D
CVE-2026-11845 - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injecti
CVE-2026-11844 - The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Rea
CVE-2026-12058 - The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.