CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-9928 - Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote att
CVE-2026-9927 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9926 - Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9925 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9924 - Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote a
CVE-2026-9923 - Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti
CVE-2026-9922 - Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9921 - Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9920 - Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attack
CVE-2026-9919 - Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
CVE-2026-9918 - Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9917 - Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9916 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9915 - Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9914 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9913 - Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9912 - Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a re
CVE-2026-9911 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perf
CVE-2026-9910 - Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9909 - Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-9908 - Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to ob
CVE-2026-9907 - Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote atta
CVE-2026-9906 - Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha
CVE-2026-9905 - Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote
CVE-2026-9904 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potent
CVE-2026-9903 - Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.21
CVE-2026-9902 - Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker w
CVE-2026-9901 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9900 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9899 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9898 - Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.21
CVE-2026-9897 - Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9896 - Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec
CVE-2026-9895 - Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-9894 - Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had com
CVE-2026-9893 - Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had co
CVE-2026-9892 - Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a r
CVE-2026-9891 - Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who
CVE-2026-9890 - Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker w
CVE-2026-9889 - Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a r
CVE-2026-9888 - Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attac
CVE-2026-9887 - Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9886 - Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to
CVE-2026-9885 - Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 all
CVE-2026-9884 - Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker
CVE-2026-9883 - Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-9882 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak
CVE-2026-9881 - Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who
CVE-2026-9880 - Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed
CVE-2026-9879 - Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to e
CVE-2026-9878 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-9877 - Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had c
CVE-2026-9876 - Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacke
CVE-2026-9875 - Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote att
CVE-2026-9874 - Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti
CVE-2026-9873 - Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec
CVE-2026-9872 - Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
CVE-2026-8809 - The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via
CVE-2026-6816 - An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users pe
CVE-2026-5343 - Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Prov
CVE-2026-10028 - A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting
CVE-2026-10022 - Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a us
CVE-2026-10021 - Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a
CVE-2026-10020 - Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.2
CVE-2026-10019 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak
CVE-2026-10018 - Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obta
CVE-2026-10017 - Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker wh
CVE-2026-10016 - Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-10015 - Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut
CVE-2026-10014 - Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attac
CVE-2026-10013 - Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to ex
CVE-2026-10012 - Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had co
CVE-2026-10011 - Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-10010 - Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a
CVE-2026-10009 - Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had
CVE-2026-10008 - Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attack
CVE-2026-10007 - Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute
CVE-2026-10006 - Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbit
CVE-2026-10005 - Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote at
CVE-2026-10004 - Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 all
CVE-2026-10003 - Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convi
CVE-2026-10002 - Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to poten
CVE-2026-10001 - Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attac
CVE-2026-10000 - Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote att
CVE-2026-49299 - In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on si
CVE-2026-48116 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-47713 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-45410 - TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login f
CVE-2026-45403 - AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe
CVE-2026-45366 - typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vu
CVE-2026-45364 - Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0
CVE-2026-45344 - LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database config
CVE-2026-45343 - LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored
CVE-2026-45342 - LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insec
CVE-2026-45023 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-44973 - Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues
CVE-2026-44885 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44884 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44883 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44882 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44881 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44850 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44849 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-44848 - Portainer Community Edition is a lightweight service delivery platform for containerized application
CVE-2026-39929 - Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-
CVE-2026-10044 - Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GE
CVE-2026-9646 - A reflected cross-site scripting issue exists in URL handling.
CVE-2026-9645 - Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the ser
CVE-2026-49095 - Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to p
CVE-2026-49094 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Al
CVE-2026-49093 - Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector manag
CVE-2026-46843 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-46842 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-46841 - Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affect
CVE-2026-46840 - Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions th
CVE-2026-46839 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-46837 - Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Securi
CVE-2026-46835 - Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are a
CVE-2026-46834 - Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are a
CVE-2026-46833 - Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are a
CVE-2026-46830 - Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affec
CVE-2026-46829 - Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affec
CVE-2026-46828 - Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operatio
CVE-2026-46827 - Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Mana
CVE-2026-46826 - Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operatio
CVE-2026-46824 - Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work
CVE-2026-46823 - Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Su
CVE-2026-46822 - Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operatio
CVE-2026-46821 - Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component:
CVE-2026-46820 - Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component:
CVE-2026-46819 - Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (compo
CVE-2026-46818 - Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmissio
CVE-2026-46817 - Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmissio
CVE-2026-46775 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-45288 - Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's
CVE-2026-44657 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1
CVE-2026-44655 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Proje
CVE-2026-42400 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Al
CVE-2026-42399 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Al
CVE-2026-42398 - Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management
CVE-2026-42071 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing auth
CVE-2026-42070 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update(
CVE-2026-41897 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validat
CVE-2026-35277 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-35266 - Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected
CVE-2026-34311 - Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Appl
CVE-2026-9039 - A configuration weakness in the device’s remote management service allows an authenticated session t
CVE-2026-9038 - A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic all
CVE-2026-9037 - A firmware update mechanism in the affected charging controller fails to validate the authenticity o
CVE-2026-49130 - Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf
CVE-2026-49129 - Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerabilit
CVE-2026-49128 - Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalSto
CVE-2026-49127 - Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in t
CVE-2026-42401 - Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HT
CVE-2026-33590 - Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host
CVE-2026-33464 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive
CVE-2026-33463 - Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized
CVE-2026-33462 - A path traversal vulnerability was identified in Kibana's dashboard management functionality. An aut
CVE-2026-32847 - DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route i
CVE-2026-4944 - vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` paramet
CVE-2026-47337 - Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the
CVE-2026-47336 - Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor
CVE-2026-47335 - Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of
CVE-2026-47334 - Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding
CVE-2026-47333 - Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly comp
CVE-2026-47332 - Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of
CVE-2026-47331 - Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linke
CVE-2026-47330 - Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances
CVE-2026-47329 - Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the nam
CVE-2026-47328 - Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a po
CVE-2026-47327 - Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the
CVE-2026-47326 - Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big respo
CVE-2026-47136 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS conso
CVE-2026-46685 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS
CVE-2026-46526 - Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.1
CVE-2026-46509 - deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is
CVE-2026-45332 - Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-be
CVE-2026-45044 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router
CVE-2026-45042 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authori
CVE-2026-45041 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/s
CVE-2026-45040 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers f
CVE-2026-45039 - RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RP
CVE-2026-44394 - An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping
CVE-2026-43979 - Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0
CVE-2026-43000 - An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application crede
CVE-2026-42999 - An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in en
CVE-2026-42998 - An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential aut
CVE-2026-30761 - An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans M
CVE-2026-30760 - An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitr
CVE-2026-46561 - pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PR
CVE-2026-45787 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3
CVE-2026-45374 - CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawn
CVE-2026-45373 - CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated
CVE-2026-45353 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6
CVE-2026-45348 - pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the pa
CVE-2026-45323 - MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node name
CVE-2026-45311 - CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool ex
CVE-2026-45310 - CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validat
CVE-2026-45307 - Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior
CVE-2026-45306 - pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fi
CVE-2026-45297 - OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on f
CVE-2026-45296 - OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes s
CVE-2026-45058 - electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 a
CVE-2026-45021 - Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs
CVE-2026-44798 - Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a
CVE-2026-44797 - Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Na
CVE-2026-44796 - Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Na
CVE-2026-44794 - Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in
CVE-2026-43898 - SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Funct
CVE-2026-34126 - TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v
CVE-2026-9098 - In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts an
CVE-2026-9097 - Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still activ
CVE-2026-9096 - Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library
CVE-2026-9095 - Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection.
CVE-2026-9094 - Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token excha
CVE-2026-9093 - In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate
CVE-2026-9092 - Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that
CVE-2026-9091 - Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allo
CVE-2026-9090 - Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authe
CVE-2026-8697 - Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1,
CVE-2026-6720 - When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full con
CVE-2026-47676 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-47675 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-47674 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-47673 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-45292 - opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and
CVE-2026-45261 - GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7,
CVE-2026-45078 - Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated us
CVE-2026-45076 - Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, ma
CVE-2026-44543 - Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each
CVE-2026-44477 - CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments.
CVE-2026-44466 - Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via ba
CVE-2026-44465 - Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder wi
CVE-2026-44463 - Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by pre
CVE-2026-44462 - Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via ba
CVE-2026-44461 - Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string
CVE-2026-41185 - When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI
CVE-2026-41184 - In Calico, the install-cni init container logs the rendered CNI configuration to standard output. Wh
CVE-2026-41160 - EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business l
CVE-2026-41141 - EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /ap
CVE-2026-38707 - A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware
CVE-2026-38704 - A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmw
CVE-2026-38703 - A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmwa
CVE-2026-38702 - A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmwa
CVE-2026-24444 - SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded pas
CVE-2026-48735 - pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this
CVE-2026-48526 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding J
CVE-2026-48525 - PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JW
CVE-2026-48524 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() f
CVE-2026-48523 - PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side a
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.