CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
26100 CVEs gefunden (Seite 87/105)

CVE-2026-44821 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-44820 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44819 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44818 - Concurrent execution using shared resource with improper synchronization ('race condition') in Micro

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-44817 - Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44815 - Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code o

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-44814 - Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-44813 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44812 - Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44811 - Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44810 - Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-44809 - Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate pri

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44808 - Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44807 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44805 - Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny s

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-44804 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44803 - Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44802 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44801 - Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-44799 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42993 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42992 - Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42991 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42989 - Improper link resolution before file access ('link following') in Winlogon allows an authorized atta

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42987 - Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42986 - Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42985 - Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-42984 - Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-42983 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42981 - Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacke

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42980 - Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elev

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42979 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42978 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42977 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42974 - Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to exe

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42973 - Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42972 - Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42971 - Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42970 - Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42969 - Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclos

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42968 - Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42916 - Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate priv

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42915 - Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42914 - Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-42913 - Concurrent execution using shared resource with improper synchronization ('race condition') in Remot

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42912 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-42911 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-42910 - Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42909 - Concurrent execution using shared resource with improper synchronization ('race condition') in Remot

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42908 - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42907 - Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42906 - Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-42905 - Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges local

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42904 - Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges o

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-42903 - Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42902 - Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges lo

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42837 - Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to e

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42836 - Concurrent execution using shared resource with improper synchronization ('race condition') in Funct

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-42835 - Improper neutralization of special elements in output used by a downstream component ('injection') i

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42829 - Improper access control in Windows Administrator Protection allows an authorized attacker to bypass

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42828 - Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to ele

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42771 - Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a craft

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.2
6.2

CVE-2026-42770 - Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key i

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-42769 - Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key upd

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-42768 - Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style at

🏢 Oracle 📅 9.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-42767 - Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a N

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-42766 - Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer derefer

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-42765 - Issue summary: When a partial-chain certificate verification is enabled together with OCSP response

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42764 - Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dere

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42599 - Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-42573 - Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DO

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-42570 - Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42567 - Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an int

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-41108 - Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-41098 - Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack

🏢 Azure 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-41092 - Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges loca

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-40409 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-40404 - Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-40376 - Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privilege

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40371 - Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises)

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-3088 - Unauthenticated users on the local network can cause the router to become unavailable by sending spe

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-38615 - DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-35188 - Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response thr

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.0
5.0

CVE-2026-34692 - Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based C

🏢 Adobe 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-34335 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-34183 - Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-34182 - Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input val

🏢 Oracle 📅 9.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-34181 - Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files th

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-34180 - Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-33828 - Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-33113 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-32193 - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku

🏢 Azure 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-28301 - A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.8
4.8

CVE-2026-26142 - Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute c

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-24181 - NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-24180 - NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffe

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-22926 - Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-0420 - An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud

🏢 Netgear 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-0419 - Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit releas

🏢 Netgear 📅 9.6.2026 📊 CVSS: 8.0
8.0

CVE-2026-0418 - Insufficient configuration management in the listed devices allows authenticated administrators conn

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0417 - Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin

🏢 Netgear 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0416 - An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an

🏢 Netgear 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0415 - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini

🏢 Netgear 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0414 - Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini

🏢 Netgear 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0413 - A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models al

🏢 Netgear 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0412 - Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band

🏢 Netgear 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0411 - An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could al

🏢 Netgear 📅 9.6.2026 📊 CVSS: 8.0
8.0

CVE-2026-0410 - Authenticated administrators connected to the local network can gain elevated access to the router

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.5
4.5

CVE-2026-0409 - A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traf

🏢 Netgear 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8045 - CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-8025 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49948 - Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability

🏢 Postgresql 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-49938 - A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2

🏢 Fortinet 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-25089 - A improper neutralization of special elements used in an os command ('os command injection') vulnera

🏢 Fortinet 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-24065 - Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerab

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-24064 - Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerab

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-10727 - An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-10523 - An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R1

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-10520 - An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versi

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 10.0
10.0

CVE-2025-67862 - An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerabili

🏢 Fortinet 📅 9.6.2026 📊 CVSS: 6.7
6.7

CVE-2026-9279 - Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an a

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-7486 - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-52907 - In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-52906 - In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.7
7.7

CVE-2026-52905 - In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-pow

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-52904 - In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device le

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-49762 - Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47901 - Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47900 - Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaSc

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47899 - The Electron preload script in Logseq exposes an API method that allows the renderer process to invo

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-46332 - In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound b

🏢 Linux 📅 9.6.2026 📊 CVSS: 8.0
8.0

CVE-2026-46330 - In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46329 - In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-46328 - In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-46327 - In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_su

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46326 - In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix

🏢 Linux 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-46325 - In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conver

🏢 Linux 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-11793 - A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c c

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-11792 - A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the cr

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.3
3.3

CVE-2026-11790 - A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-11789 - A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.9
4.9

CVE-2026-11788 - A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocati

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-11787 - A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.0
5.0

CVE-2026-11786 - A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when p

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 1.9
1.9

CVE-2026-11785 - A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handl

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46324 - In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46323 - In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skb

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46322 - In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb fai

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-46321 - In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame r

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-46320 - In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths i

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-46319 - In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release

🏢 Linux 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-46318 - In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hu

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-46317 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmu

🏢 Linux 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-46316 - In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the

🏢 Linux 📅 9.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-2638 - A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 thro

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-11764 - When creating an export of all reusable media, the secrets of connected gift cards were included in

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2017-20251 - WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that al

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2017-20250 - Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2017-20249 - Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attack

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20248 - Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attack

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2017-20247 - WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthen

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20246 - KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenti

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20245 - Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthent

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20244 - Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthent

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2017-20243 - WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerab

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2016-20065 - Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unaut

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2016-20064 - WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.2
6.2

CVE-2016-20063 - Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated user

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2016-20062 - Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthent

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-49742 - Backend users with file download permissions were able to download files from the fallback storage o

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-49741 - Backend users with write access to the form_definition database table were able to directly create,

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-49740 - TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-49738 - The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix compa

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47352 - Authenticated backend users were able to retrieve file metadata via several Backend API routes witho

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47351 - Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without prope

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47350 - Backend users were able to move records to a different page without having edit permissions on the s

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47349 - Backend users with access to the Recycler module were able to restore soft-deleted records on pages

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47348 - Editors with access to create or modify page content were able to include HTML markup in page titles

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47347 - Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to op

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47346 - Backend users with file write permissions were able to upload form definition files with mixed-case

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47343 - Non-privileged backend users with file mount access were able to perform write operations (move, del

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-11607 - Backend users with access to the Form Framework were able to use files not ending in .form.yaml as f

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-52902 - A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directiv

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.7
4.7

CVE-2026-4058 - The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registrat

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46749 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected ap

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-46748 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected sy

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-46747 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected ap

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-46746 - A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-41031 - A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Bui

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.7
8.7

CVE-2026-24349 - A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-10731 - SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ fun

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 0.0
0.0

CVE-2025-40808 - A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2025-10263 - Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Co

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-8677 - The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8599 - The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for Word

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8365 - The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Executi

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-7542 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in vers

🏢 Aws 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-6899 - Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.6
5.6

CVE-2026-49818 - The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destinat

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-46315 - In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid i

🏢 Linux 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-34905 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This iss

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-34033 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach

🏢 Apache 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-34031 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-33582 - Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-28262 - Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Acces

🏢 Dell 📅 9.6.2026 📊 CVSS: 6.0
6.0

CVE-2026-25699 - Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. T

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-25688 - Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects

🏢 Apache 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-11616 - The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in v

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2009-10007 - Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixatio

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-9698 - DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-5068 - A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host du

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 7.6
7.6

CVE-2026-44083 - An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagi

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-41986 - Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 2.4
2.4

CVE-2026-41985 - UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.1
5.1

CVE-2026-41984 - UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerab

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.2
5.2

CVE-2026-41983 - Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of thi

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-41982 - Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerabilit

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-41981 - Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnera

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-41977 - DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affe

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.0
5.0

CVE-2026-41976 - Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vul

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.6
6.6

CVE-2026-41974 - Permission control vulnerability in service notifications. Impact: Successful exploitation of this v

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 3.6
3.6

CVE-2026-41973 - Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-41972 - Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability m

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2025-62858 - A buffer overflow vulnerability has been reported to affect several QNAP operating system versions.

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-8981 - The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_h

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 3.5
3.5

CVE-2026-5067 - A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket u

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-4986 - The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal we

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-41539 - A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-11572 - Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command In

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-9662 - The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all v

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-9185 - The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Control

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-8977 - The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8940 - The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8910 - The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-8909 - The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8907 - The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-8904 - The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8902 - The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-8895 - The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8883 - The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Script

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8882 - The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8880 - The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8841 - The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-8499 - The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-7662 - The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '

🏢 Wordpress 📅 9.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-41980 - Permission control vulnerability in the file preview module. Impact: Successful exploitation of this

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-41979 - Permission control vulnerability in the print module. Impact: Successful exploitation of this vulner

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-41978 - Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulner

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 4.4
4.4

CVE-2026-41975 - Permission management vulnerability in the network management module. Impact: Successful exploitatio

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-41855 - In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon

🏢 Sonstige 📅 9.6.2026 📊 CVSS: 8.1
8.1
«« « Zurück Seite 87 von 105 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.