CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-4096 - IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper valid
CVE-2026-3341 - IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (
CVE-2026-11839 - Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies
CVE-2024-45636 - IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read
CVE-2026-8406 - openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging modu
CVE-2026-6338 - A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.
CVE-2026-53723 - Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service de
CVE-2026-53661 - Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up t
CVE-2026-38581 - SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attacker
CVE-2026-11816 - Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction ut
CVE-2026-10847 - A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS.
CVE-2026-7852 - Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allo
CVE-2026-49214 - guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did
CVE-2026-48998 - guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 cont
CVE-2026-11956 - A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of th
CVE-2026-11561 - Improper neutralization of special elements used in an expression language statement ('expression la
CVE-2026-9694 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.1
CVE-2026-9204 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.
CVE-2026-8589 - GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11
CVE-2026-8464 - Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an
CVE-2026-7250 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.
CVE-2026-6976 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.1
CVE-2026-6552 - Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does no
CVE-2026-6277 - GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 b
CVE-2026-6269 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.
CVE-2026-53912 - Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-
CVE-2026-53423 - Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4
CVE-2026-4764 - A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Googl
CVE-2026-3553 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.1
CVE-2026-1500 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.
CVE-2026-10733 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.1
CVE-2026-10087 - GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 b
CVE-2023-32959 - Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectl
CVE-2023-25969 - Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows E
CVE-2022-47150 - Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cro
CVE-2022-45813 - Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Inco
CVE-2026-5497 - vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attac
CVE-2026-53911 - Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input
CVE-2026-11850 - An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins
CVE-2025-7064 - Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freela
CVE-2022-44630 - Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel all
CVE-2022-42479 - Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Prop
CVE-2026-53901 - Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path.
CVE-2024-32110 - Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Reque
CVE-2023-40200 - Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase
CVE-2023-33999 - Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i
CVE-2026-41856 - The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly re
CVE-2026-41700 - Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Si
CVE-2026-41699 - Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated G
CVE-2026-41001 - Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis
CVE-2026-41000 - Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestDa
CVE-2026-40999 - When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate o
CVE-2026-40998 - Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code p
CVE-2026-40997 - Several Spring WS integration paths with Spring Security could surface detailed account state (for e
CVE-2026-40996 - Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J'
CVE-2026-40995 - X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presente
CVE-2026-40994 - Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that i
CVE-2026-40992 - Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set t
CVE-2026-40987 - A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client file
CVE-2026-40986 - Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when
CVE-2026-10795 - The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication B
CVE-2026-40985 - Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Uni
CVE-2026-35273 - Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Upda
CVE-2026-2827 - The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum
CVE-2026-53465 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53464 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53463 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53462 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53461 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-53460 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-52726 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-50223 - Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low
CVE-2026-49219 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-49218 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48994 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48734 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48733 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-48724 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-47734 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-47712 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-47342 - A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o
CVE-2026-47213 - Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la
CVE-2026-47166 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-47165 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46703 - Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la
CVE-2026-46695 - Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la
CVE-2026-46693 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46692 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46645 - SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_look
CVE-2026-46559 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46557 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46521 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-44693 - Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior
CVE-2026-42568 - Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnera
CVE-2026-42563 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0
CVE-2026-42558 - Xibo is an open source digital signage platform with a web content management system and Windows dis
CVE-2026-42305 - Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting wit
CVE-2024-21944 - Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker wit
CVE-2026-53742 - Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes with
CVE-2026-53741 - Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript s
CVE-2026-53740 - Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Edit
CVE-2026-53739 - Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicat
CVE-2026-53738 - Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in t
CVE-2026-53737 - Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the
CVE-2026-53736 - Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicat
CVE-2026-53634 - Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before
CVE-2026-50131 - Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify pre
CVE-2026-48110 - Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several r
CVE-2026-48108 - Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, ru
CVE-2026-48107 - Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the ru
CVE-2026-48011 - Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able
CVE-2026-46705 - Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, th
CVE-2026-46702 - Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH
CVE-2026-46689 - Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to a
CVE-2026-46679 - libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three co
CVE-2026-46673 - Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capac
CVE-2026-46669 - OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior t
CVE-2026-46668 - SpiceDB is an open source database system for creating and managing security-critical application pe
CVE-2026-46654 - Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker con
CVE-2026-46625 - JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-
CVE-2026-46523 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46522 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-46520 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45783 - libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauth
CVE-2026-45664 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45624 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45384 - bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files
CVE-2026-45380 - bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files
CVE-2026-45359 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45358 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-45031 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-44692 - Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sha
CVE-2026-42542 - TDengine is an open source, time-series database optimized for Internet of Things devices. In versio
CVE-2026-42462 - Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to v
CVE-2026-42326 - ImageMagick is free and open-source software used for editing and manipulating digital images. Prior
CVE-2026-2049 - GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi
CVE-2026-11604 - An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.
CVE-2026-10143 - kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handl
CVE-2026-10142 - kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that a
CVE-2026-0274 - An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Corte
CVE-2026-0273 - A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated ad
CVE-2026-0272 - A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated
CVE-2026-0271 - A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux
CVE-2026-0270 - A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux
CVE-2026-0269 - A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS®
CVE-2026-0268 - A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to
CVE-2026-0267 - An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a
CVE-2026-0266 - A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a maliciou
CVE-2022-48575 - A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed
CVE-2022-26758 - A malicious application may cause unexpected changes in memory shared between processes. A memory co
CVE-2026-6893 - A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability
CVE-2026-50127 - Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_
CVE-2026-46683 - Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Pr
CVE-2026-46643 - Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Pr
CVE-2026-46529 - Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A si
CVE-2026-45106 - Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview ren
CVE-2026-1220 - Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit
CVE-2026-50639 - Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric inject
CVE-2026-50638 - Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injec
CVE-2026-50637 - Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injectio
CVE-2026-11626 - CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalat
CVE-2026-10740 - Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an un
CVE-2026-9151 - An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. A
CVE-2026-50570 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50569 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50568 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50567 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50566 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50565 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50564 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50563 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-50545 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49824 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49823 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49822 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-49821 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-48556 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46642 - draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a cra
CVE-2026-46618 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-46617 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-46614 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-46612 - Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of
CVE-2026-45062 - FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the
CVE-2026-20260 - In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthent
CVE-2026-20259 - In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4
CVE-2026-20258 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20257 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20256 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20255 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20254 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20253 - In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated use
CVE-2026-20252 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform ve
CVE-2026-20251 - In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versio
CVE-2026-11596 - In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionali
CVE-2026-11417 - OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.
CVE-2026-46616 - Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in
CVE-2026-46609 - Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are abl
CVE-2026-53698 - Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentI
CVE-2026-53694 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in
CVE-2026-53693 - A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several clie
CVE-2026-49760 - Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Ov
CVE-2026-49759 - Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated re
CVE-2026-48860 - Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) all
CVE-2026-48859 - Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows
CVE-2026-48858 - Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP
CVE-2026-48856 - Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Em
CVE-2026-48855 - Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftp
CVE-2026-48096 - OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when it
CVE-2026-46558 - Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace
CVE-2026-46497 - Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0
CVE-2026-45569 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45567 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45566 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45565 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-25700 - Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affect
CVE-2026-9045 - During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessori
CVE-2026-8637 - A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client appl
CVE-2026-8335 - A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated
CVE-2026-7516 - A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets
CVE-2026-6090 - A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow
CVE-2026-53689 - libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow
CVE-2026-53476 - A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local
CVE-2026-53475 - A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Sec
CVE-2026-53474 - A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerabil
CVE-2026-53473 - A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent w
CVE-2026-53471 - A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for
CVE-2026-53470 - A flaw was found in migration-planner. An authenticated attacker could exploit an improper access co
CVE-2026-53469 - A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sendi
CVE-2026-45564 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45563 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45561 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45560 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45559 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45558 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45556 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45552 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45550 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-45549 - Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8
CVE-2026-11884 - A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definiti
CVE-2025-10238 - During an internal security assessment, a potential out-of-bounds write vulnerability was discovered
CVE-2025-10237 - During an internal security assessment, a potential vulnerability was discovered in some ThinkPad em
CVE-2026-9758 - Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untru
CVE-2026-53442 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml sub
CVE-2026-53441 - Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not
CVE-2026-53440 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the
CVE-2026-53439 - Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with
CVE-2026-53438 - A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers wi
CVE-2026-53437 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after l
CVE-2026-53436 - Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after l
CVE-2026-53435 - In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.