CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2019-25748 - Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated a
CVE-2017-20282 - Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthe
CVE-2017-20281 - Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthentic
CVE-2017-20280 - Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticat
CVE-2017-20279 - Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to
CVE-2017-20278 - Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticate
CVE-2017-20277 - Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author
CVE-2017-20276 - Joomla! Component SIMGenealogy 2.1.5 contains an SQL injection vulnerability that allows unauthentic
CVE-2017-20275 - Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticat
CVE-2017-20274 - Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthentic
CVE-2017-20273 - Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows una
CVE-2017-20272 - Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthent
CVE-2017-20271 - Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated a
CVE-2017-20270 - Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated
CVE-2017-20269 - Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthentica
CVE-2017-20268 - Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauth
CVE-2026-12622 - The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form su
CVE-2026-12621 - Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000
CVE-2026-12620 - The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.
CVE-2026-12619 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab
CVE-2017-20267 - Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthe
CVE-2017-20266 - Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated att
CVE-2017-20265 - Joomla! Component Flip Wall 8.0 contains an SQL injection vulnerability that allows unauthenticated
CVE-2017-20264 - Joomla! Component Sponsor Wall 8.0 contains an SQL injection vulnerability that allows unauthenticat
CVE-2017-20263 - Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unau
CVE-2017-20262 - Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated
CVE-2017-20261 - Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauth
CVE-2017-20260 - Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthentica
CVE-2017-20259 - Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attacke
CVE-2017-20258 - Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows
CVE-2017-20257 - Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthentica
CVE-2017-20256 - Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated
CVE-2017-20255 - Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated at
CVE-2017-20254 - Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated
CVE-2017-20253 - Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticate
CVE-2017-20252 - Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated atta
CVE-2026-52910 - In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog a
CVE-2026-52909 - In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on
CVE-2026-52908 - In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure th
CVE-2026-49358 - PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version
CVE-2026-21768 - The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email compos
CVE-2025-71326 - AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that
CVE-2023-54353 - Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that
CVE-2022-50971 - Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that
CVE-2021-47985 - Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service bina
CVE-2020-37254 - Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted servic
CVE-2020-37253 - Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service tha
CVE-2020-37252 - Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.
CVE-2020-37251 - RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe b
CVE-2020-37250 - TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service b
CVE-2019-25747 - Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that
CVE-2016-20095 - Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastVi
CVE-2016-20094 - AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arb
CVE-2016-20093 - Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the W
CVE-2016-20092 - NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 s
CVE-2016-20091 - Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local a
CVE-2016-20090 - Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in th
CVE-2016-20089 - Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to exec
CVE-2016-20088 - Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the Chromodo
CVE-2016-20087 - Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to ex
CVE-2016-20086 - Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBa
CVE-2016-20085 - Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that
CVE-2026-9143 - There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missin
CVE-2026-9142 - There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is n
CVE-2026-4027 - A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allo
CVE-2026-4026 - A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an au
CVE-2026-49872 - Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route
CVE-2026-49871 - Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
CVE-2026-49357 - Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows
CVE-2026-49231 - Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed iden
CVE-2026-49230 - Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin
CVE-2026-48895 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker co
CVE-2026-48141 - There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service du
CVE-2026-48140 - There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow a
CVE-2026-48139 - There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that
CVE-2026-48138 - There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bo
CVE-2026-48137 - There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API
CVE-2026-47341 - Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from c
CVE-2026-47339 - Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor
CVE-2026-44915 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default con
CVE-2026-44087 - Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect p
CVE-2026-44046 - Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac
CVE-2026-39999 - Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypas
CVE-2026-39998 - Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certai
CVE-2026-12104 - OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix t
CVE-2025-62821 - Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDat
CVE-2026-56142 - In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 20
CVE-2026-56141 - In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 20
CVE-2026-53915 - In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configu
CVE-2026-50242 - In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 20
CVE-2026-44939 - A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/
CVE-2026-12706 - A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function
CVE-2026-11941 - Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI
CVE-2026-8296 - In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-S
CVE-2026-56138 - AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoi
CVE-2026-41156 - Software installed and run as a non-privileged user may conduct improper GPU system calls to cause m
CVE-2026-34192 - Software installed and run as a non-privileged user may conduct improper GPU system calls to cause a
CVE-2026-11576 - The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP
CVE-2026-6798 - The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized a
CVE-2026-46461 - Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerabi
CVE-2026-3640 - The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all
CVE-2026-9822 - The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of
CVE-2026-9013 - The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
CVE-2026-8713 - The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insu
CVE-2026-8118 - The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vuln
CVE-2026-7547 - The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read vi
CVE-2026-7515 - The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and
CVE-2026-56132 - In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because sc
CVE-2026-56131 - libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within ha
CVE-2026-54414 - FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/fo
CVE-2026-4328 - The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all version
CVE-2026-1856 - The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
CVE-2026-12644 - Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the im
CVE-2026-12430 - The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se
CVE-2026-12157 - The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPres
CVE-2026-11989 - The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin f
CVE-2026-11752 - A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceS
CVE-2026-10779 - The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to M
CVE-2026-10720 - Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal is
CVE-2026-10034 - The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions
CVE-2025-7737 - DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects
CVE-2026-8806 - Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethe
CVE-2026-8805 - Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELS
CVE-2026-11775 - The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
CVE-2026-52866 - An attacker within BLE communication range can monopolize the device's only available BLE connectio
CVE-2026-50034 - An attacker within BLE communication range can passively intercept wireless traffic and obtain sens
CVE-2026-40624 - Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote,
CVE-2026-12050 - SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/
CVE-2026-12049 - Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoin
CVE-2026-12048 - Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text retur
CVE-2026-12047 - HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and
CVE-2026-12046 - Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_i
CVE-2026-12045 - Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence data
CVE-2026-12044 - SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<descripti
CVE-2026-6716 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56078 - PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to
CVE-2026-56077 - PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger co
CVE-2026-56076 - PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint
CVE-2026-56075 - PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI mo
CVE-2026-56074 - PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation argumen
CVE-2026-10746 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8668 - A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to interna
CVE-2026-8100 - Impact A security issue has been identified in Chef 360 that could allow unauthorized access to pro
CVE-2026-54130 - Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disc
CVE-2026-54017 - Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. P
CVE-2026-49205 - phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization
CVE-2026-47647 - Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privilege
CVE-2026-47633 - Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experience
CVE-2026-32174 - Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges ove
CVE-2026-22674 - Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vu
CVE-2026-49454 - Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0
CVE-2026-49257 - mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. I
CVE-2026-49252 - deepstream is a server that allows clients and backend services to sync data, send messages and make
CVE-2026-49248 - OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.unta
CVE-2026-46699 - conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted
CVE-2026-45696 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-44663 - OpenEXR is the reference implementation and specification for the EXR image format, widely used in t
CVE-2026-43994 - Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contai
CVE-2025-15661 - libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability i
CVE-2026-56099 - OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_
CVE-2026-48983 - pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior
CVE-2026-48982 - pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior
CVE-2026-48981 - pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior
CVE-2026-48980 - pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2
CVE-2026-48716 - nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge
CVE-2026-47847 - Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credentia
CVE-2026-47846 - Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When
CVE-2026-43915 - Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contai
CVE-2026-2842 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-25865 - Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows
CVE-2026-9692 - Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The
CVE-2026-55392 - NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to valida
CVE-2026-48937 - A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `G
CVE-2026-47833 - setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via
CVE-2026-12390 - In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by a
CVE-2026-54390 - JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that a
CVE-2026-48986 - pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earli
CVE-2026-48985 - pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1
CVE-2026-48984 - pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1
CVE-2026-12475 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-56024 - Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request F
CVE-2026-56022 - Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agen
CVE-2026-56021 - Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within modu
CVE-2026-56020 - The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a
CVE-2026-55237 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-55205 - Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POS
CVE-2026-55204 - HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability i
CVE-2026-55203 - HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fc
CVE-2026-54106 - The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civil
CVE-2026-54105 - The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civil
CVE-2026-54104 - The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civil
CVE-2026-54103 - The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civil
CVE-2026-48617 - A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path
CVE-2026-38718 - InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discov
CVE-2026-38717 - InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discov
CVE-2026-38716 - InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discov
CVE-2026-38715 - InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discov
CVE-2026-38714 - InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discov
CVE-2026-11982 - Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability i
CVE-2026-10687 - Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, c
CVE-2025-53114 - CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0
CVE-2025-32437 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2025-32436 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2025-32424 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2025-32422 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2025-32392 - AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia
CVE-2026-46580 - In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a
CVE-2026-44691 - In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/t
CVE-2026-44688 - In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory
CVE-2026-22551 - In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI response
CVE-2026-11791 - A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function u
CVE-2025-58175 - GeoServer is an open source server that allows users to share and edit geospatial data. Prior to ver
CVE-2025-52465 - GeoServer is an open source server that allows users to share and edit geospatial data. Prior to ver
CVE-2025-27511 - GeoServer is an open source server that allows users to share and edit geospatial data. Prior to ver
CVE-2026-9158 - In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the
CVE-2026-8461 - An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV de
CVE-2026-8024 - A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in
CVE-2026-56012 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
CVE-2026-56009 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-56007 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2026-54419 - claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commi
CVE-2026-54224 - UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to vie
CVE-2026-54223 - UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to
CVE-2026-54222 - UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in C
CVE-2026-54221 - UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain
CVE-2026-54220 - uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechani
CVE-2026-54219 - UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fail
CVE-2026-50141 - Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability
CVE-2026-44942 - A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.1
CVE-2026-42490 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-42489 - [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabiliti
CVE-2026-42488 - Some shadow paging errors paths will switch the page-tables without updating the currently running v
CVE-2026-42487 - HVM guest I/O port accesses are subject to either emulation or at least translation. Translations a
CVE-2026-40457 - A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before co
CVE-2026-40456 - An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de du
CVE-2026-40455 - An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within th
CVE-2026-12539 - Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time,
CVE-2026-12527 - A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communicati
CVE-2026-12039 - Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolut
CVE-2026-11958 - Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, ve
CVE-2026-11719 - An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missi
CVE-2026-11718 - An authentication bypass vulnerability exists in the generic opaque token validation path (validateO
CVE-2026-11717 - An authentication bypass vulnerability exists in the generic opaque token validation path (validateO
CVE-2026-8811 - SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF
CVE-2026-8039 - The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'au
CVE-2026-50643 - 8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU line
CVE-2026-2021 - The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2025-10560 - Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret materi
CVE-2026-9815 - The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded t
CVE-2026-55746 - Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the P
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.