CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-64887 - Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic
CVE-2026-39925 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34492 - External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipu
CVE-2026-27871 - Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 all
CVE-2026-19910 - PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnera
CVE-2026-19909 - PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnera
CVE-2026-19908 - PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ
CVE-2026-18554 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
CVE-2026-18178 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitra
CVE-2026-17227 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit
CVE-2026-17209 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitr
CVE-2026-17186 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL command
CVE-2026-17184 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due t
CVE-2026-17182 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and ob
CVE-2026-17181 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary loc
CVE-2026-17179 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial
CVE-2026-17177 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du
CVE-2026-17175 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
CVE-2026-17173 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
CVE-2026-17081 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to
CVE-2026-17079 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit
CVE-2026-16915 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
CVE-2026-16905 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
CVE-2026-16879 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit
CVE-2026-16708 - IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information
CVE-2026-73679 - ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module th
CVE-2026-73678 - MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution
CVE-2026-50029 - js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a ke
CVE-2026-50027 - mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes
CVE-2026-49457 - erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not au
CVE-2026-45699 - Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.
CVE-2026-19188 - A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gate
CVE-2026-18403 - LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Cent
CVE-2025-7639 - The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Opera
CVE-2026-73850 - Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vul
CVE-2026-73849 - Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r
CVE-2026-73847 - Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on t
CVE-2026-63361 - LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerab
CVE-2026-49282 - Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name(
CVE-2026-49263 - Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend a
CVE-2026-19847 - A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the functi
CVE-2026-19846 - A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s
CVE-2026-19682 - A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker
CVE-2026-19681 - An authenticated command injection vulnerability exists in Security Center related to file upload pr
CVE-2026-19680 - A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut
CVE-2026-19679 - An input validation vulnerability exists in Security Center's file upload handling, where insufficie
CVE-2026-19639 - An improper access control vulnerability exists where an authenticated non-administrative applicatio
CVE-2026-19636 - An issue was identified in which CSRF tokens were generated using a predictable method, potentially
CVE-2026-19635 - A local privilege escalation vulnerability exists in Security Center. An attacker with write access
CVE-2026-19631 - A SQL injection vulnerability exists in Security Center that could allow an authenticated administra
CVE-2026-19629 - A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu
CVE-2026-12366 - Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an
CVE-2026-12365 - A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling o
CVE-2026-12364 - The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was
CVE-2026-12363 - The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does
CVE-2026-73846 - CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams
CVE-2026-73845 - CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_qu
CVE-2026-73844 - CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect
CVE-2026-73107 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49989 - CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can
CVE-2026-49986 - The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to vers
CVE-2026-49826 - Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker
CVE-2026-47766 - crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's defau
CVE-2026-47192 - kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, ka
CVE-2026-47191 - kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git c
CVE-2026-46603 - VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing
CVE-2026-46439 - compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a
CVE-2026-46380 - compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a
CVE-2026-19845 - A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function s
CVE-2026-19844 - A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the func
CVE-2026-19841 - A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /e
CVE-2026-19839 - A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue aff
CVE-2026-19838 - A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects
CVE-2026-19628 - A command injection vulnerability exists in Tenable Security Center. An authenticated administrator
CVE-2026-19626 - A remote code execution vulnerability exists in Tenable Security Center's report generation function
CVE-2023-7347 - Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-57472 - Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Director
CVE-2026-57471 - Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Director
CVE-2026-57469 - Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the we
CVE-2026-53970 - ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby
CVE-2026-19884 - In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integra
CVE-2026-19837 - A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the fi
CVE-2026-19836 - A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some un
CVE-2026-19835 - A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an u
CVE-2026-19834 - A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the
CVE-2026-16772 - In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to
CVE-2026-13198 - Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper
CVE-2026-13197 - Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper
CVE-2026-13196 - Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image ma
CVE-2026-13002 - A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An at
CVE-2026-63143 - Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privil
CVE-2026-63142 - Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with ac
CVE-2026-56820 - Netty is a network application framework for development of protocol servers and clients. In version
CVE-2026-56819 - Netty is a network application framework for development of protocol servers and clients. In version
CVE-2026-56817 - Netty is a network application framework for development of protocol servers and clients. In version
CVE-2026-16517 - A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_z
CVE-2026-16486 - A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an u
CVE-2026-16485 - A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by
CVE-2026-8989 - Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 rec
CVE-2026-8988 - Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permit
CVE-2026-8987 - Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set
CVE-2026-8986 - Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when proce
CVE-2026-8985 - Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /te
CVE-2026-8984 - Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via
CVE-2026-65319 - Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allow
CVE-2026-65318 - Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerab
CVE-2026-65317 - Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined wi
CVE-2026-65316 - XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authent
CVE-2026-65315 - Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata
CVE-2026-65314 - Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that a
CVE-2026-63141 - Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Co
CVE-2026-56816 - Netty is a network application framework for development of protocol servers and clients. Prior to 4
CVE-2026-56746 - Netty is a network application framework for development of protocol servers and clients. Versions 4
CVE-2026-56745 - Netty is a network application framework for development of protocol servers and clients. In version
CVE-2026-55851 - Netty is a network application framework for development of protocol servers and clients. In version
CVE-2026-47731 - The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS
CVE-2026-47709 - libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the
CVE-2026-47254 - libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sa
CVE-2026-47251 - libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8
CVE-2026-47178 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a cra
CVE-2026-43947 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unaut
CVE-2026-43946 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an autho
CVE-2026-43945 - FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.
CVE-2026-16484 - A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vuln
CVE-2026-10680 - The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/
CVE-2026-10679 - The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock
CVE-2026-10678 - The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes
CVE-2026-10677 - The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy
CVE-2026-10675 - In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_rec
CVE-2026-10674 - The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFI
CVE-2026-8983 - Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that
CVE-2026-8982 - Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. T
CVE-2026-65058 - Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign
CVE-2026-65057 - Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticat
CVE-2026-65056 - mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to
CVE-2026-65055 - Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to
CVE-2026-65054 - MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to e
CVE-2026-64881 - The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow int
CVE-2026-64822 - djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPassword
CVE-2026-64821 - djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that al
CVE-2026-63764 - LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vuln
CVE-2026-63358 - FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the
CVE-2026-63139 - Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Al
CVE-2026-63092 - kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerabili
CVE-2026-63080 - Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backe
CVE-2026-56147 - Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized inform
CVE-2026-52476 - SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive informa
CVE-2026-52475 - Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive
CVE-2026-52474 - An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUti
CVE-2026-52472 - SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the
CVE-2026-52470 - SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via t
CVE-2026-52469 - SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via t
CVE-2026-47714 - libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline
CVE-2026-47708 - MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3,
CVE-2026-47697 - Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organi
CVE-2026-47690 - MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions o
CVE-2026-47689 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47688 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47687 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47685 - FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version
CVE-2026-47237 - Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clust
CVE-2026-47143 - Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer de
CVE-2026-46556 - FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.
CVE-2026-45383 - libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a
CVE-2026-45382 - libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decode
CVE-2026-44879 - A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authe
CVE-2026-44878 - A vulnerability in the web-based management interface of an ECOS device could allow a highly privile
CVE-2026-30633 - Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc
CVE-2026-30631 - An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11
CVE-2026-16318 - The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n
CVE-2026-16317 - Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an
CVE-2026-12139 - Tanium addressed an information disclosure vulnerability in Connect.
CVE-2026-11925 - Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Ta
CVE-2026-65069 - Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file an
CVE-2026-65068 - Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file an
CVE-2026-65067 - Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and ope
CVE-2026-65066 - Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and
CVE-2026-65065 - Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file
CVE-2026-65064 - Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and op
CVE-2026-65063 - Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and
CVE-2026-65062 - Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and
CVE-2026-65061 - Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and ope
CVE-2026-64880 - Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL que
CVE-2026-64879 - A filename supplied during file upload is not properly sanitized before being used in system command
CVE-2026-64878 - Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument
CVE-2026-64617 - Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and ope
CVE-2026-64616 - Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and op
CVE-2026-64615 - Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open
CVE-2026-64614 - Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open
CVE-2026-64613 - Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and ope
CVE-2026-59147 - Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an
CVE-2026-59146 - Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unv
CVE-2026-59145 - Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot,
CVE-2026-59144 - Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalida
CVE-2026-59143 - Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalid
CVE-2026-56852 - A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
CVE-2026-56146 - Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytic
CVE-2026-50759 - An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /stat
CVE-2026-50758 - Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to
CVE-2026-50757 - Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to e
CVE-2026-50756 - An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat
CVE-2026-50755 - An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat
CVE-2026-49092 - Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized in
CVE-2026-47671 - Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0,
CVE-2026-47667 - CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the
CVE-2026-46600 - Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the messa
CVE-2026-46403 - Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `
CVE-2026-42397 - Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of ser
CVE-2026-30632 - Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the c
CVE-2026-64877 - An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access
CVE-2026-63454 - An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln
CVE-2026-63453 - Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitati
CVE-2026-59142 - Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated a
CVE-2026-59141 - Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated no
CVE-2026-59140 - Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated no
CVE-2026-59139 - Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated ar
CVE-2026-55082 - DHIS2 is a flexible information system for data capture, management, validation, analytics and visua
CVE-2026-55081 - DHIS2 is a flexible information system for data capture, management, validation, analytics and visua
CVE-2026-16441 - In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superc
CVE-2026-12548 - A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an intege
CVE-2026-12547 - SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority
CVE-2016-20096 - Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnera
CVE-2026-56581 - HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorize
CVE-2026-56580 - HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow a
CVE-2026-56578 - HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit kn
CVE-2026-56577 - HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise t
CVE-2026-47657 - HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing aut
CVE-2026-47425 - Rattler is a library that provides common functionality used within the conda ecosystem. Prior to ve
CVE-2026-47419 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47418 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47417 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47416 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47415 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47414 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47413 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47412 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47411 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-44880 - A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploi
CVE-2026-21579 - This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8
CVE-2026-21577 - This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.
CVE-2026-21575 - This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sou
CVE-2026-16493 - A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's conc
CVE-2026-16439 - In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer un
CVE-2026-16243 - In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if t
CVE-2026-47410 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47409 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47408 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47407 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to versio
CVE-2026-47406 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
CVE-2026-47405 - PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.