CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-45624 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45384 - bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files
CVE-2026-45380 - bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files
CVE-2026-45359 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45358 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45031 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-44692 - Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sha
CVE-2026-42542 - TDengine is an open source, time-series database optimized for Internet of Things devices. In versio
CVE-2026-42462 - Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to v
CVE-2026-42326 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-2049 - GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi
CVE-2026-11604 - An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.
CVE-2026-10143 - kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handl
CVE-2026-10142 - kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that a
CVE-2026-0274 - An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Corte
CVE-2026-0273 - A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated ad
CVE-2026-0272 - A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated
CVE-2026-0271 - A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux
CVE-2026-0270 - A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux
CVE-2026-0269 - A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS®
CVE-2026-0268 - A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to
CVE-2026-0267 - An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a
CVE-2026-0266 - A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a maliciou
CVE-2022-48575 - A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed
CVE-2022-26758 - A malicious application may cause unexpected changes in memory shared between processes. A memory co
CVE-2026-6893 - A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability
CVE-2026-50127 - Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_
CVE-2026-46683 - Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Pr
CVE-2026-46643 - Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Pr
CVE-2026-46529 - Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A si
CVE-2026-45106 - Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview ren
CVE-2026-1220 - Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit
CVE-2026-50639 - Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric inject
CVE-2026-50638 - Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injec
CVE-2026-50637 - Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injectio
CVE-2026-11626 - CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalat
CVE-2026-10740 - Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an un
CVE-2026-9151 - An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. A
CVE-2026-50570 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50569 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50568 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50567 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50566 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50565 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50564 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50563 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50545 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49824 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49823 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49822 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49821 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-48556 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46642 - draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a cra
CVE-2026-46618 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-46617 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-46614 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-46612 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-45062 - FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the
CVE-2026-20260 - In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthent
CVE-2026-20259 - In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4
CVE-2026-20258 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20257 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20256 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20255 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20254 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20253 - In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated use
CVE-2026-20252 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20251 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versio
CVE-2026-11596 - In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionali
CVE-2026-11417 - OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.
CVE-2026-46616 - Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in
CVE-2026-46609 - Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are abl
CVE-2026-53698 - Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentI
CVE-2026-53694 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in
CVE-2026-53693 - A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several clie
CVE-2026-49760 - Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Ov
CVE-2026-49759 - Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated re
CVE-2026-48860 - Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) all
CVE-2026-48859 - Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows
CVE-2026-48858 - Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP
CVE-2026-48856 - Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Em
CVE-2026-48855 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftp
CVE-2026-48096 - OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when it
CVE-2026-46558 - Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace
CVE-2026-46497 - Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0
CVE-2026-45569 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45567 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45566 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45565 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-25700 - Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affect
CVE-2026-9045 - During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessori
CVE-2026-8637 - A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client appl
CVE-2026-8335 - A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated
CVE-2026-7516 - A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets
CVE-2026-6090 - A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow
CVE-2026-53689 - libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow
CVE-2026-53476 - A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local
CVE-2026-53475 - A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Sec
CVE-2026-53474 - A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerabil
CVE-2026-53473 - A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent w
CVE-2026-53471 - A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for
CVE-2026-53470 - A flaw was found in migration-planner. An authenticated attacker could exploit an improper access co
CVE-2026-53469 - A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sendi
CVE-2026-45564 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45563 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45561 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45560 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45559 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45558 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45556 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45552 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45550 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45549 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-11884 - A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definiti
CVE-2025-10238 - During an internal security assessment, a potential out-of-bounds write vulnerability was discovered
CVE-2025-10237 - During an internal security assessment, a potential vulnerability was discovered in some ThinkPad em
CVE-2026-9758 - Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untru
CVE-2026-53442 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml sub
CVE-2026-53441 - Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not
CVE-2026-53440 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the
CVE-2026-53439 - Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with
CVE-2026-53438 - A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers wi
CVE-2026-53437 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after l
CVE-2026-53436 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after l
CVE-2026-53435 - In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins
CVE-2026-52759 - Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary p
CVE-2026-52758 - Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user
CVE-2026-52757 - Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::me
CVE-2026-52756 - Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that ac
CVE-2026-52755 - Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that
CVE-2026-52754 - Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authen
CVE-2026-52753 - Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allo
CVE-2026-52752 - Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails t
CVE-2026-52751 - Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RM
CVE-2026-52750 - Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows
CVE-2026-49498 - Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of Pos
CVE-2026-49497 - Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to
CVE-2026-49496 - Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd
CVE-2026-49495 - Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.pa
CVE-2026-49069 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2025-71330 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
CVE-2025-71329 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
CVE-2024-58350 - Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined
CVE-2026-24067 - Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.p
CVE-2026-24066 - Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.p
CVE-2026-11859 - An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canaryto
CVE-2026-3018 - The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscrib
CVE-2026-11853 - Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. De
CVE-2026-11852 - Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Fi
CVE-2025-6254 - The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,
CVE-2026-9019 - The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[p
CVE-2026-8853 - The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' para
CVE-2026-8613 - The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
CVE-2026-10721 - Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Pe
CVE-2026-9067 - The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilit
CVE-2026-9060 - The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings bef
CVE-2026-8071 - The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize
CVE-2026-3326 - The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before usi
CVE-2026-29116 - A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker
CVE-2026-29115 - A vulnerability has been found in some Dahua products could allow an authenticated remote attacker t
CVE-2026-29114 - A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root c
CVE-2026-11815 - An attacker who intercepts and tampers with traffic between the client application and the API Gatew
CVE-2026-10846 - NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolv
CVE-2026-26241 - A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can
CVE-2026-26240 - A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can
CVE-2026-11837 - A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The
CVE-2025-8444 - The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for Wo
CVE-2026-26239 - A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gai
CVE-2026-26237 - A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can
CVE-2026-24724 - An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote att
CVE-2026-24720 - An allocation of resources without limits or throttling vulnerability has been reported to affect Fi
CVE-2026-24719 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2026-24717 - A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
CVE-2026-24716 - A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
CVE-2026-22899 - A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote att
CVE-2026-22893 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-66281 - A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
CVE-2025-66280 - An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
CVE-2025-66279 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-66273 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-62851 - A path traversal vulnerability has been reported to affect License Center. If a local attacker gains
CVE-2025-62850 - A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
CVE-2025-66276 - QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.
CVE-2025-59382 - QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the followin
CVE-2025-58468 - A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. T
CVE-2026-46532 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5
CVE-2026-45542 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5
CVE-2026-45541 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5
CVE-2026-45329 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0,
CVE-2026-45328 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0,
CVE-2026-45160 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5
CVE-2026-46546 - Frappe Learning Management System (LMS) is a learning system that helps users structure their conten
CVE-2026-44634 - SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version
CVE-2026-53675 - BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API
CVE-2026-53674 - BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention reso
CVE-2026-53673 - BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST AP
CVE-2026-47838 - SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN val
CVE-2026-46545 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46543 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46542 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46541 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46540 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46539 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46518 - OpenEMR is a free and open source electronic health records and medical practice management applicat
CVE-2026-46517 - LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1
CVE-2026-46491 - SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp mod
CVE-2026-46432 - LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1
CVE-2026-46411 - FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, autho
CVE-2026-45782 - Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before versi
CVE-2026-44716 - Pipecat is an open-source Python framework for building real-time voice and multimodal conversationa
CVE-2026-44505 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-41837 - Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-param
CVE-2026-41732 - JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning t
CVE-2026-41731 - JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust
CVE-2026-41730 - Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentia
CVE-2026-41729 - Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when proces
CVE-2026-41728 - Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-
CVE-2026-41727 - Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value
CVE-2026-41726 - When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou
CVE-2026-41721 - Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if
CVE-2026-41719 - A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passe
CVE-2026-41717 - Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability.
CVE-2026-41716 - Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strin
CVE-2026-41714 - Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://
CVE-2026-41711 - Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading
CVE-2026-41706 - Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication reque
CVE-2026-41701 - Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are pr
CVE-2026-41697 - Spring Data Relational does not properly escape binding values of externally-controlled input when u
CVE-2026-41696 - Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding
CVE-2026-41695 - Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion
CVE-2026-41694 - Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and Lo
CVE-2026-41008 - Spring Security Authorization Server's authorization endpoint performs insufficient validation of th
CVE-2026-41003 - An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code o
CVE-2026-40993 - An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataReposi
CVE-2026-40991 - When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API acc
CVE-2026-40988 - An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Lo
CVE-2026-9754 - An authenticated user with the read role may read limited amounts of uninitialized stack memory via
CVE-2026-9753 - The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff con
CVE-2026-9752 - An authorized user could trigger a server crash by running a query with a 2dsphere index on a field
CVE-2026-9751 - The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new
CVE-2026-9750 - An authenticated user can cause a MongoDB server to crash or return incorrect results by creating do
CVE-2026-9749 - This issue can occur when running an aggregation pipeline that uses the internal $exchange stage con
CVE-2026-9748 - The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this docume
CVE-2026-9747 - Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb serv
CVE-2026-9746 - When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hit
CVE-2026-9743 - In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing
CVE-2026-9742 - When OIDC authentication is enabled in configuration, clients may set specific values in the "mechan
CVE-2026-9741 - A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (
CVE-2026-9740 - A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash th
CVE-2026-9735 - MongoDB server may log authentication parameters, including credentials, to the server log during SA
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.