CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-48594 - Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla
CVE-2026-47265 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.1
CVE-2026-42342 - React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.
CVE-2026-42211 - React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a c
CVE-2026-41577 - authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML so
CVE-2026-40181 - React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certa
CVE-2026-38967 - CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response
CVE-2026-35202 - Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterod
CVE-2026-35049 - wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon r
CVE-2026-34993 - AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.1
CVE-2026-34077 - React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unst
CVE-2026-33553 - Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
CVE-2026-33245 - React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unst
CVE-2026-30586 - Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sen
CVE-2026-28299 - SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when ex
CVE-2026-1829 - The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution
CVE-2026-10702 - JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox
CVE-2026-10701 - Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firef
CVE-2026-10617 - A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the
CVE-2026-10616 - A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the
CVE-2026-10608 - A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the fi
CVE-2026-10607 - A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspec
CVE-2026-10584 - Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, w
CVE-2025-64390 - A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02.
CVE-2021-4479 - Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnera
CVE-2021-4478 - Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-boun
CVE-2019-25724 - Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network
CVE-2019-25723 - Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerab
CVE-2019-25722 - Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded
CVE-2019-25721 - Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a netwo
CVE-2026-49943 - CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP
CVE-2026-42074 - OpenClaude is an open-source coding-agent command line interface for cloud and local model providers
CVE-2026-42073 - OpenClaude is an open-source coding-agent command line interface for cloud and local model providers
CVE-2026-40715 - Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerab
CVE-2026-40713 - Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerab
CVE-2026-40571 - NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePo
CVE-2026-40314 - NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePos
CVE-2026-35447 - NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Co
CVE-2026-35443 - NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/Forum
CVE-2026-33244 - React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with
CVE-2026-24237 - NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of
CVE-2026-24221 - NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of
CVE-2026-1871 - TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due
CVE-2026-10606 - A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of th
CVE-2026-0611 - Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthe
CVE-2024-42206 - HCL iReflection Third party vulnerable and outdated components issue was detected in the web applica
CVE-2026-9590 - Improper access control in the permission validation component in Devolutions Server 2026.1.19 and e
CVE-2026-9522 - Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and ear
CVE-2026-7299 - Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names bef
CVE-2026-49754 - Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attack
CVE-2026-49753 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in el
CVE-2026-48862 - Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attack
CVE-2026-48861 - Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allow
CVE-2026-47117 - OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model
CVE-2026-45686 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45685 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45684 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45683 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45682 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45681 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45680 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45679 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45678 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45676 - OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard
CVE-2026-45554 - NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-c
CVE-2026-45553 - NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reSt
CVE-2026-45080 - Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4
CVE-2026-44367 - Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4
CVE-2026-42654 - Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System fo
CVE-2026-40780 - Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP Boo
CVE-2026-40619 - A high security vulnerability affecting Security Center main server installations has been identifie
CVE-2026-38978 - transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and
CVE-2026-35718 - A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK
CVE-2026-35716 - A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVT
CVE-2026-34460 - NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callbac
CVE-2026-33398 - NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/g
CVE-2026-30652 - A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin i
CVE-2026-30650 - A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cg
CVE-2026-30649 - Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute a
CVE-2026-10629 - SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec inte
CVE-2026-10591 - Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.
CVE-2026-10047 - The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the re
CVE-2026-10046 - Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS I
CVE-2026-9844 - Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Man
CVE-2026-7313 - CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.
CVE-2026-7312 - CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14
CVE-2026-7201 - CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.
CVE-2026-7198 - CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 a
CVE-2026-7195 - CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4
CVE-2026-49782 - Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorre
CVE-2026-43965 - Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion vi
CVE-2026-42795 - Symlink following vulnerability in Gleam's Hex package export allows files outside the project root
CVE-2026-41918 - A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The
CVE-2026-39555 - Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. Thi
CVE-2026-39553 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2026-39552 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2026-35717 - A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VV
CVE-2026-32685 - Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file
CVE-2026-32250 - NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnera
CVE-2026-28116 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-27351 - Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Config
CVE-2026-10622 - Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to a
CVE-2026-10621 - Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via
CVE-2026-10611 - An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with
CVE-2025-69369 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2025-68886 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2025-58897 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2025-58707 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2019-25719 - Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software ver
CVE-2019-25717 - Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulner
CVE-2026-8993 - D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulne
CVE-2026-42685 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-42684 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-42670 - Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservati
CVE-2026-42669 - Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Co
CVE-2026-39551 - Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. Thi
CVE-2026-39550 - Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection.
CVE-2025-58705 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2025-58024 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2025-53440 - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
CVE-2026-5422 - A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root dire
CVE-2026-5191 - The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site s
CVE-2026-46718 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in
CVE-2026-41115 - An improper authorization vulnerability has been identified in Apache Kafka. The implementation of
CVE-2026-34907 - Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of
CVE-2026-34906 - Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to pe
CVE-2026-10549 - LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker w
CVE-2025-53346 - Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured
CVE-2025-53345 - Missing Authorization vulnerability leading to code execution after installing malicious vulnerable
CVE-2025-53302 - Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not
CVE-2025-53209 - Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalat
CVE-2025-52766 - Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectl
CVE-2025-52759 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-9730 - The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery i
CVE-2026-9723 - The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v
CVE-2026-9722 - The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
CVE-2026-9599 - The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u
CVE-2026-9234 - The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in ver
CVE-2026-8885 - The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-8422 - The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery
CVE-2026-4081 - The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] short
CVE-2026-4080 - The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart
CVE-2026-4071 - The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,
CVE-2026-3620 - The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replace
CVE-2026-3514 - In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the imp
CVE-2026-2425 - The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via
CVE-2026-2382 - The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
CVE-2026-1784 - The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through H
CVE-2026-1451 - The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' paramet
CVE-2026-1450 - The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' para
CVE-2025-5085 - The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_l
CVE-2026-8293 - The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor chal
CVE-2026-8206 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-3198 - MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for mul
CVE-2026-10583 - A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this
CVE-2026-10581 - A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decod
CVE-2026-3871 - A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmwa
CVE-2026-3870 - A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware
CVE-2026-3722 - The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)
CVE-2026-10568 - A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown func
CVE-2026-10567 - A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the fun
CVE-2026-10566 - A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Me
CVE-2026-10565 - A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm
CVE-2026-10510 - Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle applicatio
CVE-2026-10100 - The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t
CVE-2026-10559 - A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unk
CVE-2026-10558 - A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown
CVE-2026-10550 - A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code
CVE-2026-10548 - A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the f
CVE-2026-10529 - A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab.
CVE-2026-9050 - The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable t
CVE-2026-9048 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versio
CVE-2026-10528 - A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the fu
CVE-2026-10514 - A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function
CVE-2026-10302 - A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown
CVE-2026-10301 - A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an
CVE-2026-28511 - eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an auth
CVE-2026-25879 - Langroid is a framework for building large-language-model-powered applications. Prior to version 0.6
CVE-2026-25277 - Memory corruption while using Strongbox due to buffer overflow.
CVE-2026-25276 - Memory corruption while using Strongbox due to missing bounds check.
CVE-2026-25260 - Memory Corruption when accessing shared buffers without validation of concurrent user-mode input mod
CVE-2026-25259 - Memory corruption while processing multiple IOCTL command for escape operations.
CVE-2026-25258 - Memory corruption while processing IOCTL calls for escape operations.
CVE-2026-24782 - Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilit
CVE-2026-24761 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Referen
CVE-2026-24756 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Referen
CVE-2026-24755 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Referen
CVE-2026-24754 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kit
CVE-2026-24753 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Referen
CVE-2026-24752 - Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in
CVE-2026-24092 - Memory Corruption when processing fastboot commands to set display mode.
CVE-2026-24091 - Memory corruption while processing fastboot commands with improperly formatted input.
CVE-2026-24090 - Cryptographic issue while processing partition table entries allows unauthorized modification of boo
CVE-2026-24089 - Memory corruption while processing fastboot commands with invalid input.
CVE-2026-24088 - Cryptographic Issue while processing a specific partition which allows unauthorized write access to
CVE-2026-24087 - Memory corruption while processing fastboot OEM commands.
CVE-2026-24085 - Memory Corruption when processing display command line information due to improper initialization of
CVE-2026-10300 - A security vulnerability has been detected in SGLang 0.5.10.post1. Impacted is an unknown function o
CVE-2026-10299 - A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue af
CVE-2026-10298 - A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects
CVE-2026-10297 - A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown p
CVE-2026-10296 - A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is
CVE-2026-10295 - A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability
CVE-2025-59614 - Memory Corruption when sending random number generator command with insufficient output buffer size.
CVE-2025-59613 - Memory Corruption when output buffer size is smaller than input buffer size during data copying oper
CVE-2025-59612 - Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2025-59611 - Memory corruption in diagnostic services due to absence of input validation
CVE-2025-59610 - Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modi
CVE-2025-59609 - Information Disclosure when processing advertisement frames with malformed MBSSID elements of insuff
CVE-2025-59606 - Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion duri
CVE-2025-59605 - Memory Corruption when processing device identifier strings that exceed the expected maximum length.
CVE-2025-59604 - Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointe
CVE-2025-59601 - Information Disclosure when resetting device to factory default settings through powerline interface
CVE-2019-25718 - Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to
CVE-2026-49491 - Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extra
CVE-2026-40965 - Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The s
CVE-2026-40964 - Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unaut
CVE-2026-28586 - In multiple functions of AppOpsService.java, there is a possible missing permission check due to a p
CVE-2026-28581 - In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emer
CVE-2026-28580 - In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. T
CVE-2026-28578 - In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistenc
CVE-2026-28577 - In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/
CVE-2026-10294 - A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of th
CVE-2026-10293 - A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of th
CVE-2026-10292 - A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcp
CVE-2026-10291 - A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted e
CVE-2026-10290 - A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affect
CVE-2026-0100 - In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th
CVE-2026-0099 - In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from th
CVE-2026-0098 - In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictio
CVE-2026-0097 - In multiple locations, there is a possible way to bypass user interaction when pairing an LE device
CVE-2026-0096 - In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgettin
CVE-2026-0095 - In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption wi
CVE-2026-0094 - In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into appr
CVE-2026-0093 - In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to loca
CVE-2026-0091 - In multiple locations, there is a possible way to execute code in the launcher process due to an ove
CVE-2026-0089 - In multiple functions of PackageInstallerService.java, there is a possible way to install unverified
CVE-2026-0088 - In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security di
CVE-2026-0087 - In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hija
CVE-2026-0086 - In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due
CVE-2026-0085 - In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact
CVE-2026-0080 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to
CVE-2026-0079 - In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
CVE-2026-0078 - In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due
CVE-2026-0077 - In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application la
CVE-2026-0076 - In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bou
CVE-2026-0075 - In multiple functions, there is a possible way to access the contacts database due to a SQL injectio
CVE-2026-0074 - In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due t
CVE-2026-0070 - In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system c
CVE-2026-0069 - In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource ex
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.