CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-24160 - NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked
CVE-2026-24142 - NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized han
CVE-2025-33255 - NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could caus
CVE-2025-15369 - The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modi
CVE-2026-8685 - The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order
CVE-2026-8627 - The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SE
CVE-2026-8626 - The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Para
CVE-2026-8624 - The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin
CVE-2026-8610 - The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all
CVE-2026-8424 - The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
CVE-2026-8423 - The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in a
CVE-2026-8420 - The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver
CVE-2026-8419 - The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
CVE-2026-8418 - The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to
CVE-2026-8038 - The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'defaul
CVE-2026-7472 - The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via t
CVE-2026-7467 - The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions
CVE-2026-7462 - The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `pa
CVE-2026-7284 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to p
CVE-2026-6555 - The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up
CVE-2026-6549 - The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
CVE-2026-6456 - The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up t
CVE-2026-6452 - The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v
CVE-2026-6404 - The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-S
CVE-2026-6401 - The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
CVE-2026-6400 - The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request For
CVE-2026-6399 - The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up
CVE-2026-6397 - The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` s
CVE-2026-6395 - The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored C
CVE-2026-6394 - The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is
CVE-2026-6391 - The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Sit
CVE-2026-6072 - The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorizati
CVE-2026-5293 - The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-45232 - Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the est
CVE-2026-43620 - Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv
CVE-2026-43619 - Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system ca
CVE-2026-43618 - Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token deco
CVE-2026-43617 - Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's ho
CVE-2026-3985 - The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerabl
CVE-2026-45585 - Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &qu
CVE-2026-39309 - Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe
CVE-2026-35593 - Trilium Notes is an open-source, cross-platform hierarchical note taking application for building la
CVE-2026-34970 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bug
CVE-2026-34754 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an au
CVE-2026-8495 - Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affect
CVE-2026-8493 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i
CVE-2026-8492 - Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTransla
CVE-2026-8491 - Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions a
CVE-2026-6871 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i
CVE-2026-6367 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i
CVE-2026-6366 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup
CVE-2026-6365 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i
CVE-2026-6095 - Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability i
CVE-2026-34744 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a us
CVE-2026-34600 - Joplin is an open source note-taking and to-do application that organises notes and lists into noteb
CVE-2026-34579 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnera
CVE-2026-5090 - Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. T
CVE-2026-34463 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a S
CVE-2026-34390 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Priv
CVE-2026-34358 - CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a
CVE-2026-34246 - CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a
CVE-2026-34241 - CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a
CVE-2026-34234 - CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the we
CVE-2025-15645 - Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware
CVE-2024-36343 - Improper input validation in the System Management Mode (SMM) communications buffer could allow a pr
CVE-2023-7345 - Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer pars
CVE-2026-39250 - An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacke
CVE-2026-34233 - CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multip
CVE-2026-34216 - CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the ad
CVE-2026-32882 - libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap
CVE-2026-32814 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decod
CVE-2026-32741 - libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap
CVE-2025-57798 - Joplin is an open source note-taking and to-do application that organises notes and lists into noteb
CVE-2026-42526 - In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-ama
CVE-2026-32740 - libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap
CVE-2026-32739 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted
CVE-2026-27173 - JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read
CVE-2026-8370 - Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Lin
CVE-2026-8096 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-8073 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-41470 - LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command han
CVE-2026-34154 - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 a
CVE-2026-33741 - EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below all
CVE-2026-33642 - Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_comma
CVE-2026-33637 - Faraday is an HTTP client library abstraction layer that provides a common interface over many adapt
CVE-2026-32738 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted
CVE-2026-8605 - In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to a
CVE-2026-8604 - In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated
CVE-2026-8603 - In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute c
CVE-2026-8602 - In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow a
CVE-2026-6009 - Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE
CVE-2026-47107 - Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox
CVE-2026-33633 - Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overfl
CVE-2026-32134 - NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below,
CVE-2025-61081 - Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by
CVE-2026-5511 - In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly ha
CVE-2026-47358 - Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL re
CVE-2026-47357 - Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url
CVE-2026-47356 - Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url
CVE-2026-36829 - An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to
CVE-2026-36828 - A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM32
CVE-2026-36827 - A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web mana
CVE-2026-8706 - Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another applicat
CVE-2026-5804 - An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.
CVE-2026-37281 - An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin befo
CVE-2026-31072 - The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are
CVE-2026-31071 - API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middlew
CVE-2026-31070 - The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers
CVE-2026-31069 - BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventReposi
CVE-2026-30118 - scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_ur
CVE-2026-30117 - scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the sca
CVE-2026-8711 - NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least o
CVE-2026-47100 - Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerabi
CVE-2026-45557 - Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records
CVE-2026-44159 - Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not requ
CVE-2026-43634 - HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticat
CVE-2026-34883 - An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell moni
CVE-2026-2587 - A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rend
CVE-2026-2586 - An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administrat
CVE-2025-70950 - An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a c
CVE-2025-51427 - An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafte
CVE-2026-8975 - Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these
CVE-2026-8974 - Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence
CVE-2026-8973 - Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption a
CVE-2026-8972 - Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 1
CVE-2026-8971 - Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox
CVE-2026-8970 - Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox
CVE-2026-8969 - Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Th
CVE-2026-8968 - Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerabilit
CVE-2026-8967 - Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 15
CVE-2026-8966 - Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 a
CVE-2026-8965 - Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 a
CVE-2026-8964 - Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thund
CVE-2026-8963 - Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderb
CVE-2026-8962 - Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firef
CVE-2026-8961 - Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox
CVE-2026-8960 - Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8959 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerabili
CVE-2026-8958 - Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerabi
CVE-2026-8957 - Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1
CVE-2026-8956 - Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Fire
CVE-2026-8955 - Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Fir
CVE-2026-8954 - Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was
CVE-2026-8953 - Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was
CVE-2026-8952 - Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 15
CVE-2026-8951 - Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Fire
CVE-2026-8950 - Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox
CVE-2026-8949 - Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefo
CVE-2026-8948 - Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox
CVE-2026-8947 - Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151,
CVE-2026-8946 - Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed
CVE-2026-8945 - Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151
CVE-2026-6354 - Rejected reason: Voluntarily withdrawn
CVE-2026-47323 - Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knat
CVE-2026-43633 - HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal co
CVE-2026-42100 - Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Serv
CVE-2026-42099 - Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php e
CVE-2026-42098 - Sparx Enterprise Architect software has a security feature that limits user's actions to those speci
CVE-2026-42097 - Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "mod
CVE-2026-42096 - Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database
CVE-2026-23558 - The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race wi
CVE-2026-23557 - Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction du
CVE-2025-40904 - A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to impro
CVE-2025-40903 - A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality d
CVE-2025-40902 - A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper vali
CVE-2025-40901 - A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to
CVE-2025-40900 - An Angular template injection vulnerability was discovered in the Reports functionality due to impro
CVE-2025-14575 - An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase)
CVE-2026-8912 - The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' paramet
CVE-2026-4883 - The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file ty
CVE-2026-7860 - A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle
CVE-2026-7571 - A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID
CVE-2026-7507 - A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated
CVE-2026-7504 - A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malici
CVE-2026-7307 - A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML in
CVE-2026-4630 - A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Refere
CVE-2026-45442 - Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly
CVE-2026-43493 - In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling o
CVE-2026-43492 - In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer un
CVE-2026-43491 - In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximu
CVE-2026-37982 - A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `
CVE-2026-37981 - A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lo
CVE-2026-37979 - A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC)
CVE-2026-37978 - A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit
CVE-2026-8827 - The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing
CVE-2026-8727 - The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP'
CVE-2026-8726 - The extension fails to properly sanitize user input before using it in a database query. As a result
CVE-2026-46725 - The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely pr
CVE-2026-46724 - The file indexer does not normalize the configured directory path. A backend user with permission to
CVE-2026-46723 - The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and
CVE-2026-46722 - The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or
CVE-2026-46721 - The create and edit flows do not restrict which user properties may be submitted and do not enforce
CVE-2026-46586 - Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in
CVE-2026-45434 - Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remo
CVE-2026-45187 - Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: bef
CVE-2026-41919 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i
CVE-2026-35086 - Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache
CVE-2026-31986 - Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
CVE-2026-31910 - Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz:
CVE-2026-31909 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issu
CVE-2026-31906 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-31388 - Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affec
CVE-2026-31387 - Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.0
CVE-2026-31380 - Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression La
CVE-2026-31379 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limit
CVE-2026-31378 - Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24
CVE-2026-2611 - In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /
CVE-2026-29226 - Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
CVE-2026-29220 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac
CVE-2026-29207 - Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
CVE-2026-44408 - There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of t
CVE-2026-8922 - A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies
CVE-2026-4885 - The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due
CVE-2026-47317 - Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. T
CVE-2026-47316 - Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot a
CVE-2026-47315 - Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot a
CVE-2026-47314 - Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss
CVE-2026-47313 - Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Exc
CVE-2026-47312 - Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer
CVE-2026-8830 - A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during c
CVE-2026-8814 - Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compr
CVE-2026-8813 - This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mlu
CVE-2026-47311 - Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. T
CVE-2026-47310 - Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issu
CVE-2026-47309 - Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Dat
CVE-2025-15609 - The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthentica
CVE-2026-47308 - NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation. T
CVE-2026-32994 - The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1
CVE-2026-47307 - NULL pointer dereference vulnerability in Samsung Open Source Walrus allows an attacker to cause a d
CVE-2026-33565 - in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28751 - in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28733 - in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
CVE-2026-27781 - in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-27766 - in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.
CVE-2026-27648 - in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-insta
CVE-2026-25850 - in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
CVE-2026-25781 - in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
CVE-2026-25110 - in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-24792 - in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-insta
CVE-2026-22069 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-33514 - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 a
CVE-2026-33234 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-33233 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-33232 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-33052 - Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a lo
CVE-2026-32323 - Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and be
CVE-2026-32312 - GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authe
CVE-2026-32244 - Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 a
CVE-2026-30950 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-27964 - FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contai
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.