CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-47368 - A malicious actor with access to the network could exploit a Path Traversal vulnerability found in c
CVE-2026-47367 - A malicious actor with access to the network and low privileges could exploit an Improper Input Vali
CVE-2026-47366 - Improper verification of access permissions when modifying permissions through the Administration Co
CVE-2026-47365 - Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows
CVE-2026-20746 - Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorize
CVE-2026-9125 - The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_ur
CVE-2026-45170 - Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and con
CVE-2026-11933 - A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when convert
CVE-2026-49482 - ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5
CVE-2026-10676 - Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis de
CVE-2026-47238 - ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal auth
CVE-2026-45418 - ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authentic
CVE-2026-45060 - ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/p
CVE-2026-42846 - ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's
CVE-2026-6250 - An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to impr
CVE-2026-49060 - Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege E
CVE-2026-45174 - Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potent
CVE-2026-45173 - Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit
CVE-2026-45172 - Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior
CVE-2026-45171 - Incomplete input validation and improperly configured folder permissions within Idira Privileged Ses
CVE-2026-44890 - Netty is a network application framework for development of protocol servers and clients. In netty-c
CVE-2026-44250 - Netty is a network application framework for development of protocol servers and clients. In netty-c
CVE-2026-44249 - Netty is a network application framework for development of protocol servers and clients. In netty-h
CVE-2026-42653 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42647 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-39494 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-12035 - Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacke
CVE-2026-12034 - Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior
CVE-2026-12033 - Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacke
CVE-2026-12032 - Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowe
CVE-2026-12031 - Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a
CVE-2026-12030 - Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote atta
CVE-2026-12029 - Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacke
CVE-2026-12028 - Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker
CVE-2026-12027 - Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote a
CVE-2026-12026 - Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote at
CVE-2026-12025 - Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allow
CVE-2026-12024 - Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remot
CVE-2026-12023 - Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who
CVE-2026-12022 - Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who
CVE-2026-12020 - Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker
CVE-2026-12019 - Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowe
CVE-2026-12018 - Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a l
CVE-2026-12017 - Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote
CVE-2026-12016 - Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote a
CVE-2026-12015 - Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who ha
CVE-2026-12014 - Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local net
CVE-2026-12013 - Rejected reason: Determined not a vulnerability
CVE-2026-12012 - Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileg
CVE-2026-12011 - Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attac
CVE-2026-12010 - Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote att
CVE-2026-12009 - Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7
CVE-2026-12008 - Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attac
CVE-2026-12007 - Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker
CVE-2026-53819 - OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows
CVE-2026-53818 - OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature
CVE-2026-53817 - OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that al
CVE-2026-53816 - OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event
CVE-2026-53815 - OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions tha
CVE-2026-53814 - OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent r
CVE-2026-53813 - OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading wh
CVE-2026-53812 - OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control th
CVE-2026-53811 - OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom featu
CVE-2026-53810 - OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extensio
CVE-2026-53809 - OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allo
CVE-2026-53808 - OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop appl
CVE-2026-53807 - OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive call
CVE-2026-53806 - OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX s
CVE-2026-50245 - Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no
CVE-2026-50005 - Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to si
CVE-2026-41005 - Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a
CVE-2026-53782 - Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers w
CVE-2026-53781 - Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to
CVE-2026-49973 - Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows u
CVE-2026-49949 - CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent a
CVE-2026-46622 - SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authe
CVE-2026-46489 - SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload
CVE-2026-45802 - FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and us
CVE-2026-45175 - Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within
CVE-2026-12038 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-53702 - A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad)
CVE-2026-53701 - An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser
CVE-2026-52860 - Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-comple
CVE-2026-52859 - Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() fu
CVE-2026-52858 - Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completi
CVE-2026-48547 - KanaDojo contains a command injection vulnerability that allows an attacker with pull request access
CVE-2026-47250 - mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to
CVE-2026-47189 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47188 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47181 - PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection v
CVE-2026-47177 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47176 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47175 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47174 - In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build wo
CVE-2026-47173 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47172 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47171 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47170 - Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-ho
CVE-2026-47169 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47167 - Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnera
CVE-2026-47163 - Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to
CVE-2026-47162 - Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injecti
CVE-2026-46519 - mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to
CVE-2026-45178 - Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within i
CVE-2026-45177 - Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its int
CVE-2026-45176 - Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within
CVE-2026-11774 - An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In s
CVE-2025-46315 - A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2
CVE-2025-46313 - A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1.
CVE-2025-46308 - An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4
CVE-2025-46293 - This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15
CVE-2025-43339 - An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tah
CVE-2025-43278 - This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15
CVE-2025-31272 - The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may
CVE-2025-30459 - A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia
CVE-2025-30431 - The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonom
CVE-2025-24284 - This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i
CVE-2025-24268 - A parsing issue in the handling of directory paths was addressed with improved path validation. This
CVE-2025-24165 - A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia
CVE-2026-49261 - MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11
CVE-2026-48546 - KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute ar
CVE-2026-47157 - aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted serve
CVE-2026-46698 - Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds
CVE-2026-46697 - Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds
CVE-2026-3329 - A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user ac
CVE-2026-11986 - A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative u
CVE-2026-49982 - tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard a
CVE-2026-44705 - tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package conta
CVE-2026-44496 - Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on th
CVE-2026-44495 - Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1
CVE-2026-44494 - Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the A
CVE-2026-44492 - Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios
CVE-2026-44490 - Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios
CVE-2026-44489 - Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nest
CVE-2026-44488 - Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.
CVE-2026-44487 - Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’
CVE-2026-44486 - Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’
CVE-2026-11945 - PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by cr
CVE-2026-9648 - The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS cli
CVE-2026-7870 - IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified li
CVE-2026-7787 - IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive i
CVE-2026-53777 - Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server t
CVE-2026-4096 - IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper valid
CVE-2026-3341 - IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (
CVE-2026-11839 - Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies
CVE-2024-45636 - IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read
CVE-2026-8406 - openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging modu
CVE-2026-6338 - A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.
CVE-2026-53723 - Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service de
CVE-2026-53661 - Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up t
CVE-2026-38581 - SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attacker
CVE-2026-11816 - Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction ut
CVE-2026-10847 - A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS.
CVE-2026-7852 - Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allo
CVE-2026-49214 - guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did
CVE-2026-48998 - guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 cont
CVE-2026-11956 - A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of th
CVE-2026-11561 - Improper neutralization of special elements used in an expression language statement ('expression la
CVE-2026-9694 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.1
CVE-2026-9204 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.
CVE-2026-8589 - GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11
CVE-2026-8464 - Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an
CVE-2026-7250 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.
CVE-2026-6976 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.1
CVE-2026-6552 - Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does no
CVE-2026-6277 - GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 b
CVE-2026-6269 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.
CVE-2026-53912 - Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-
CVE-2026-53423 - Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4
CVE-2026-4764 - A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Googl
CVE-2026-3553 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.1
CVE-2026-1500 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.
CVE-2026-10733 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.1
CVE-2026-10087 - GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 b
CVE-2023-32959 - Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectl
CVE-2023-25969 - Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows E
CVE-2022-47150 - Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cro
CVE-2022-45813 - Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Inco
CVE-2026-5497 - vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attac
CVE-2026-53911 - Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input
CVE-2026-11850 - An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins
CVE-2025-7064 - Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freela
CVE-2022-44630 - Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel all
CVE-2022-42479 - Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Prop
CVE-2026-53901 - Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path.
CVE-2024-32110 - Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Reque
CVE-2023-40200 - Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase
CVE-2023-33999 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-41856 - The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly re
CVE-2026-41700 - Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Si
CVE-2026-41699 - Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated G
CVE-2026-41001 - Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis
CVE-2026-41000 - Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestDa
CVE-2026-40999 - When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate o
CVE-2026-40998 - Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code p
CVE-2026-40997 - Several Spring WS integration paths with Spring Security could surface detailed account state (for e
CVE-2026-40996 - Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J'
CVE-2026-40995 - X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presente
CVE-2026-40994 - Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that i
CVE-2026-40992 - Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set t
CVE-2026-40987 - A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client file
CVE-2026-40986 - Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when
CVE-2026-10795 - The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication B
CVE-2026-40985 - Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Uni
CVE-2026-35273 - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Upda
CVE-2026-2827 - The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum
CVE-2026-53465 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53464 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53463 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53462 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53461 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53460 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-52726 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-50223 - Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low
CVE-2026-49219 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-49218 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48994 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48734 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48733 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48724 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-47734 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-47712 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-47342 - A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o
CVE-2026-47213 - Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la
CVE-2026-47166 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-47165 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46703 - Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la
CVE-2026-46695 - Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la
CVE-2026-46693 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46692 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46645 - SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_look
CVE-2026-46559 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46557 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46521 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-44693 - Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior
CVE-2026-42568 - Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnera
CVE-2026-42563 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-42558 - Xibo is an open source digital signage platform with a web content management system and Windows dis
CVE-2026-42305 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting wit
CVE-2024-21944 - Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker wit
CVE-2026-53742 - Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes with
CVE-2026-53741 - Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript s
CVE-2026-53740 - Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Edit
CVE-2026-53739 - Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicat
CVE-2026-53738 - Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in t
CVE-2026-53737 - Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the
CVE-2026-53736 - Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicat
CVE-2026-53634 - Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before
CVE-2026-50131 - Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify pre
CVE-2026-48110 - Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several r
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.