CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-47695 - CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game.
CVE-2026-15957 - Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers fr
CVE-2026-47394 - PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw /
CVE-2026-46412 - @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with Op
CVE-2026-47871 - VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation
CVE-2026-56741 - JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3
CVE-2026-50163 - oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/u
CVE-2026-15415 - AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow en
CVE-2026-12283 - Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amaz
CVE-2026-33731 - WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook h
CVE-2026-15737 - AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for bui
CVE-2025-45870 - LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOf
CVE-2026-56454 - HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TL
CVE-2026-15895 - OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allo
CVE-2026-15738 - Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Con
CVE-2026-15643 - AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that en
CVE-2026-15508 - A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_ta
CVE-2026-53961 - Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5
CVE-2026-59897 - Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 bef
CVE-2026-55075 - Coder allows organizations to provision remote development environments via Terraform. Prior to vers
CVE-2026-14904 - AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and en
CVE-2026-56140 - Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns comp
CVE-2026-46590 - Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc compon
CVE-2026-46456 - Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs com
CVE-2026-43867 - Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc compon
CVE-2026-53360 - In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scrat
CVE-2026-54430 - liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() functio
CVE-2026-14265 - Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced
CVE-2026-13769 - Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like syst
CVE-2026-13760 - OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cd
CVE-2026-10564 - IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSRe
CVE-2026-13316 - A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and ht
CVE-2026-13762 - Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow
CVE-2026-50137 - Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or ca
CVE-2026-49991 - RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users wi
CVE-2026-57295 - A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81
CVE-2026-57294 - A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows a
CVE-2026-45135 - Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCG
CVE-2026-12958 - Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of
CVE-2026-12957 - Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all support
CVE-2026-54288 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-54289 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-54287 - Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.
CVE-2026-50557 - Angular is a development platform for building mobile and desktop web applications using TypeScript/
CVE-2026-56424 - MISP core contained multiple broken access-control flaws where authorization checks were performed a
CVE-2026-12047 - HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and
CVE-2025-10560 - Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret materi
CVE-2026-12530 - Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock Agent
CVE-2026-8176 - The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab
CVE-2026-12043 - Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library m
CVE-2026-45062 - FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the
CVE-2026-11417 - OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.
CVE-2026-7542 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in vers
CVE-2026-11393 - Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI be
CVE-2026-11401 - An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon
CVE-2026-11400 - An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amaz
CVE-2026-10843 - A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator
CVE-2026-49204 - Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking as
CVE-2026-10722 - A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of
CVE-2026-4035 - A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment v
CVE-2026-10177 - A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function reque
CVE-2026-44698 - Home Assistant is open source home automation software that puts local control and privacy first. Pr
CVE-2026-48522 - PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argu
CVE-2026-47074 - Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCa
CVE-2026-46119 - In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds
CVE-2026-46116 - In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_s
CVE-2026-42790 - Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key m
CVE-2026-42789 - Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_
CVE-2026-49017 - In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processin
CVE-2026-9496 - Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (Do
CVE-2026-39965 - TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypas
CVE-2026-9133 - Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug
CVE-2026-5946 - Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS i
CVE-2026-6394 - The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is
CVE-2026-42526 - In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-ama
CVE-2026-47358 - Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL re
CVE-2026-8507 - Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When pa
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.