CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-52759 - Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary p
CVE-2026-52758 - Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user
CVE-2026-52757 - Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::me
CVE-2026-52756 - Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that ac
CVE-2026-52755 - Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that
CVE-2026-52754 - Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authen
CVE-2026-52753 - Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allo
CVE-2026-52752 - Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails t
CVE-2026-52751 - Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RM
CVE-2026-52750 - Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows
CVE-2026-49498 - Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of Pos
CVE-2026-49497 - Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to
CVE-2026-49496 - Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd
CVE-2026-49495 - Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.pa
CVE-2026-49069 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
CVE-2025-71330 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
CVE-2025-71329 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
CVE-2024-58350 - Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined
CVE-2026-24067 - Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.p
CVE-2026-24066 - Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.p
CVE-2026-11859 - An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canaryto
CVE-2026-3018 - The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscrib
CVE-2026-11853 - Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. De
CVE-2026-11852 - Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Fi
CVE-2025-6254 - The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,
CVE-2026-9019 - The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[p
CVE-2026-8853 - The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' para
CVE-2026-8613 - The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
CVE-2026-10721 - Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Pe
CVE-2026-9067 - The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilit
CVE-2026-9060 - The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings bef
CVE-2026-8071 - The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize
CVE-2026-3326 - The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before usi
CVE-2026-29116 - A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker
CVE-2026-29115 - A vulnerability has been found in some Dahua products could allow an authenticated remote attacker t
CVE-2026-29114 - A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root c
CVE-2026-11815 - An attacker who intercepts and tampers with traffic between the client application and the API Gatew
CVE-2026-10846 - NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolv
CVE-2026-26241 - A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can
CVE-2026-26240 - A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can
CVE-2026-11837 - A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The
CVE-2025-8444 - The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for Wo
CVE-2026-26239 - A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gai
CVE-2026-26237 - A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can
CVE-2026-24724 - An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote att
CVE-2026-24720 - An allocation of resources without limits or throttling vulnerability has been reported to affect Fi
CVE-2026-24719 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2026-24717 - A path traversal vulnerability has been reported to affect several QNAP operating system versions. I
CVE-2026-24716 - A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
CVE-2026-22899 - A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote att
CVE-2026-22893 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-66281 - A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
CVE-2025-66280 - An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating s
CVE-2025-66279 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-66273 - A command injection vulnerability has been reported to affect several QNAP operating system versions
CVE-2025-62851 - A path traversal vulnerability has been reported to affect License Center. If a local attacker gains
CVE-2025-62850 - A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system v
CVE-2025-66276 - QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.
CVE-2025-59382 - QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the followin
CVE-2025-58468 - A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. T
CVE-2026-46532 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5
CVE-2026-45542 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5
CVE-2026-45541 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5
CVE-2026-45329 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0,
CVE-2026-45328 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0,
CVE-2026-45160 - ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5
CVE-2026-46546 - Frappe Learning Management System (LMS) is a learning system that helps users structure their conten
CVE-2026-44634 - SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version
CVE-2026-53675 - BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API
CVE-2026-53674 - BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention reso
CVE-2026-53673 - BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST AP
CVE-2026-47838 - SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN val
CVE-2026-46545 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46543 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46542 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46541 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46540 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46539 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-46518 - OpenEMR is a free and open source electronic health records and medical practice management applicat
CVE-2026-46517 - LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1
CVE-2026-46491 - SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp mod
CVE-2026-46432 - LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.1
CVE-2026-46411 - FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, autho
CVE-2026-45782 - Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before versi
CVE-2026-44716 - Pipecat is an open-source Python framework for building real-time voice and multimodal conversationa
CVE-2026-44505 - Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus
CVE-2026-41837 - Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-param
CVE-2026-41732 - JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning t
CVE-2026-41731 - JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust
CVE-2026-41730 - Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentia
CVE-2026-41729 - Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when proces
CVE-2026-41728 - Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-
CVE-2026-41727 - Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value
CVE-2026-41726 - When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou
CVE-2026-41721 - Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if
CVE-2026-41719 - A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passe
CVE-2026-41717 - Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability.
CVE-2026-41716 - Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strin
CVE-2026-41714 - Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://
CVE-2026-41711 - Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading
CVE-2026-41706 - Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication reque
CVE-2026-41701 - Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are pr
CVE-2026-41697 - Spring Data Relational does not properly escape binding values of externally-controlled input when u
CVE-2026-41696 - Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding
CVE-2026-41695 - Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion
CVE-2026-41694 - Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and Lo
CVE-2026-41008 - Spring Security Authorization Server's authorization endpoint performs insufficient validation of th
CVE-2026-41003 - An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code o
CVE-2026-40993 - An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataReposi
CVE-2026-40991 - When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API acc
CVE-2026-40988 - An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Lo
CVE-2026-9754 - An authenticated user with the read role may read limited amounts of uninitialized stack memory via
CVE-2026-9753 - The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff con
CVE-2026-9752 - An authorized user could trigger a server crash by running a query with a 2dsphere index on a field
CVE-2026-9751 - The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new
CVE-2026-9750 - An authenticated user can cause a MongoDB server to crash or return incorrect results by creating do
CVE-2026-9749 - This issue can occur when running an aggregation pipeline that uses the internal $exchange stage con
CVE-2026-9748 - The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this docume
CVE-2026-9747 - Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb serv
CVE-2026-9746 - When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hit
CVE-2026-9743 - In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing
CVE-2026-9742 - When OIDC authentication is enabled in configuration, clients may set specific values in the "mechan
CVE-2026-9741 - A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (
CVE-2026-9740 - A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash th
CVE-2026-9735 - MongoDB server may log authentication parameters, including credentials, to the server log during SA
CVE-2026-46433 - lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/da
CVE-2026-46374 - SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated
CVE-2026-46373 - SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated
CVE-2026-44963 - A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain
CVE-2026-10238 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47905 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontr
CVE-2026-47904 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontr
CVE-2026-47903 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Imprope
CVE-2026-47902 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontr
CVE-2026-34713 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontr
CVE-2026-34712 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Imprope
CVE-2026-34711 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer
CVE-2026-34657 - CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Imprope
CVE-2026-34417 - OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attack
CVE-2026-25860 - OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image up
CVE-2026-48303 - Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Auth
CVE-2026-48292 - Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability
CVE-2026-48291 - Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability
CVE-2026-47961 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read
CVE-2026-47960 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML Exter
CVE-2026-47959 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer
CVE-2026-47955 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47952 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer O
CVE-2026-47938 - Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Req
CVE-2026-47937 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Searc
CVE-2026-47933 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS)
CVE-2026-47932 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname
CVE-2026-47931 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera
CVE-2026-47930 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera
CVE-2026-47929 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerabi
CVE-2026-47928 - ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera
CVE-2026-47926 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read
CVE-2026-47925 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow o
CVE-2026-47924 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47923 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read
CVE-2026-47921 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47920 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47919 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47918 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47917 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47916 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47915 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47914 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47913 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47912 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vuln
CVE-2026-47911 - Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds writ
CVE-2026-34416 - OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attack
CVE-2026-25557 - Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulner
CVE-2026-11799 - UXSS in Focus for iOS / Klar Webkit navigation. This vulnerability was fixed in Focus for iOS 151.3.
CVE-2025-71319 - image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
CVE-2026-6445 - A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose s
CVE-2026-6444 - A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged us
CVE-2026-48306 - Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerabilit
CVE-2026-48305 - Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerabilit
CVE-2026-47910 - Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerabili
CVE-2026-47909 - Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerabi
CVE-2026-47908 - Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vul
CVE-2026-47907 - Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerabili
CVE-2026-47906 - Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party
CVE-2026-47106 - Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site s
CVE-2026-34710 - Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerabilit
CVE-2026-34709 - Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerabilit
CVE-2026-32856 - Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-sit
CVE-2026-11824 - SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text searc
CVE-2026-11822 - SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extensi
CVE-2026-8863 - Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker wit
CVE-2026-40639 - Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated at
CVE-2026-39170 - SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/sem
CVE-2026-39169 - SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
CVE-2026-36823 - Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow
CVE-2026-36822 - Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow
CVE-2026-36821 - Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow
CVE-2026-36820 - Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow
CVE-2026-36819 - Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow
CVE-2026-36818 - Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow
CVE-2026-36817 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36816 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36815 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36813 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36811 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36810 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36809 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36808 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36807 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36806 - Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflo
CVE-2026-36805 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple buffer ove
CVE-2026-36803 - Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow i
CVE-2026-36802 - Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow i
CVE-2026-36801 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow i
CVE-2026-36800 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow i
CVE-2026-36799 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow i
CVE-2026-36798 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack over
CVE-2026-36797 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in
CVE-2026-36796 - Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in
CVE-2026-36794 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36793 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36792 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36791 - Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to contain a stack overflow in
CVE-2026-36784 - Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain
CVE-2026-36783 - Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain
CVE-2026-36779 - Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain
CVE-2026-36778 - Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain
CVE-2026-36777 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36773 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36772 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36771 - Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain
CVE-2026-36770 - Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered to contain a stack over
CVE-2026-36728 - A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of Fasta
CVE-2026-36727 - An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows
CVE-2026-36726 - An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars
CVE-2026-36725 - A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of F
CVE-2026-36724 - An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows aut
CVE-2026-36723 - An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows
CVE-2026-36722 - An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookc
CVE-2026-36721 - A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3
CVE-2026-36720 - Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from use
CVE-2026-36719 - An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows
CVE-2026-30141 - An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function
CVE-2026-10045 - Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121,
CVE-2025-55659 - A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box
CVE-2025-55658 - GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_he
CVE-2025-55657 - A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Bo
CVE-2025-55651 - A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPA
CVE-2025-52293 - A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of G
CVE-2025-52292 - A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attack
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.