CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-39387 - BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSO
CVE-2026-35589 - nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking
CVE-2026-35034 - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of s
CVE-2026-35033 - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenti
CVE-2026-35032 - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerabili
CVE-2026-35031 - Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerabili
CVE-2026-34454 - OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression in
CVE-2026-33414 - Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a comman
CVE-2026-33023 - libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and
CVE-2026-33021 - libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and pr
CVE-2026-40291 - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecu
CVE-2026-39907 - Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated W
CVE-2026-39906 - Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Re
CVE-2026-35196 - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Com
CVE-2026-34631 - InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that c
CVE-2026-34619 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname
CVE-2026-34602 - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/
CVE-2026-34370 - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the noteb
CVE-2026-34213 - Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and
CVE-2026-34212 - Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, i
CVE-2026-33193 - Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are v
CVE-2026-33146 - Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulner
CVE-2026-33020 - libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and pr
CVE-2026-33019 - libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and pr
CVE-2026-33018 - libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and pr
CVE-2026-27308 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption
CVE-2026-27307 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption
CVE-2026-27306 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnera
CVE-2026-27305 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname
CVE-2026-27304 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnera
CVE-2026-27282 - ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnera
CVE-2026-34161 - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored
CVE-2026-34160 - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS
CVE-2026-33715 - Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/
CVE-2026-33714 - Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Inject
CVE-2026-27287 - InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when pa
CVE-2026-25133 - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 c
CVE-2026-24893 - openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPI
CVE-2026-40683 - In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled att
CVE-2026-34630 - Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit
CVE-2026-34618 - Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability t
CVE-2026-27313 - Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit
CVE-2026-27312 - Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit
CVE-2026-27311 - Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit
CVE-2026-27310 - Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit
CVE-2026-27289 - Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when
CVE-2026-27222 - Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could
CVE-2026-5756 - Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) a
CVE-2026-5754 - Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer all
CVE-2026-5752 - Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a
CVE-2026-34629 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
CVE-2026-34628 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
CVE-2026-34627 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
CVE-2026-33829 - Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauth
CVE-2026-33827 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-33826 - Improper input validation in Windows Active Directory allows an authorized attacker to execute code
CVE-2026-33824 - Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-33120 - Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a net
CVE-2026-33116 - Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows
CVE-2026-33104 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-33101 - Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileg
CVE-2026-33100 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-33099 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-33098 - Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elev
CVE-2026-33096 - Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a networ
CVE-2026-32226 - Concurrent execution using shared resource with improper synchronization ('race condition') in .NET
CVE-2026-32225 - Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
CVE-2026-32224 - Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges
CVE-2026-32223 - Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate pr
CVE-2026-32222 - Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate pri
CVE-2026-32220 - Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized
CVE-2026-32218 - Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
CVE-2026-32217 - Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
CVE-2026-32216 - Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny
CVE-2026-32215 - Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
CVE-2026-32214 - Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to discl
CVE-2026-32212 - Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll)
CVE-2026-32203 - Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny servic
CVE-2026-32202 - Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing ov
CVE-2026-32196 - Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi
CVE-2026-32195 - Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges lo
CVE-2026-32183 - Improper neutralization of special elements used in a command ('command injection') in Windows Snipp
CVE-2026-32178 - Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoof
CVE-2026-32176 - Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
CVE-2026-32167 - Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
CVE-2026-32165 - Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges lo
CVE-2026-32164 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32163 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32162 - Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized atta
CVE-2026-32160 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32159 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32158 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32157 - Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
CVE-2026-32156 - Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
CVE-2026-32155 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-32154 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-32152 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-32151 - Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
CVE-2026-32150 - Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
CVE-2026-32149 - Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
CVE-2026-32093 - Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
CVE-2026-32090 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32089 - Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges lo
CVE-2026-32088 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32087 - Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker t
CVE-2026-32086 - Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
CVE-2026-32085 - Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows a
CVE-2026-32084 - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
CVE-2026-32083 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32082 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-32081 - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
CVE-2026-32080 - Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
CVE-2026-32079 - Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
CVE-2026-32078 - Use after free in Windows Projected File System allows an authorized attacker to elevate privileges
CVE-2026-32077 - Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an author
CVE-2026-32076 - Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate pri
CVE-2026-32075 - Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
CVE-2026-32074 - Double free in Windows Projected File System allows an authorized attacker to elevate privileges loc
CVE-2026-32073 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-32072 - Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoof
CVE-2026-32071 - Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una
CVE-2026-32070 - Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate pri
CVE-2026-32069 - Double free in Windows Projected File System allows an authorized attacker to elevate privileges loc
CVE-2026-32068 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-27931 - Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-27930 - Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-27929 - Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to
CVE-2026-27928 - Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feat
CVE-2026-27927 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-27926 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-27925 - Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
CVE-2026-27924 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-27923 - Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally
CVE-2026-27922 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-27921 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-27920 - Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an author
CVE-2026-27919 - Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an author
CVE-2026-27918 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-27917 - Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized atta
CVE-2026-27916 - Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
CVE-2026-27915 - Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
CVE-2026-27913 - Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security
CVE-2026-27912 - Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over
CVE-2026-27911 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-27910 - Improper handling of insufficient permissions or privileges in Windows Installer allows an authorize
CVE-2026-27908 - Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate
CVE-2026-27907 - Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized att
CVE-2026-27906 - Improper input validation in Windows Hello allows an authorized attacker to bypass a security featur
CVE-2026-27258 - DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that co
CVE-2026-26184 - Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privilege
CVE-2026-26183 - Improper access control in Windows RPC API allows an authorized attacker to elevate privileges local
CVE-2026-26182 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-26180 - Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
CVE-2026-26179 - Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26178 - Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized att
CVE-2026-26177 - Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
CVE-2026-26176 - Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized atta
CVE-2026-26175 - Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a se
CVE-2026-26174 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-26173 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-26172 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-26171 - Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a net
CVE-2026-26169 - Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information loca
CVE-2026-26168 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-26167 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-26166 - Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-26165 - Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-26163 - Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26162 - Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized at
CVE-2026-26161 - Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevat
CVE-2026-26160 - Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a
CVE-2026-26159 - Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a
CVE-2026-26156 - Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locall
CVE-2026-26154 - Improper input validation in Windows Server Update Service allows an unauthorized attacker to perfor
CVE-2026-26153 - Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate
CVE-2026-26152 - Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att
CVE-2026-26151 - Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized att
CVE-2026-25184 - Concurrent execution using shared resource with improper synchronization ('race condition') in Applo
CVE-2026-24907 - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 c
CVE-2026-24906 - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 c
CVE-2026-23670 - Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an autho
CVE-2026-23666 - Concurrent execution using shared resource with improper synchronization ('race condition') in .NET
CVE-2026-23653 - Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo
CVE-2026-20930 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
CVE-2026-20928 - Improper removal of sensitive information before storage or transfer in Windows Recovery Environment
CVE-2026-20806 - Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized at
CVE-2026-0390 - Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized atta
CVE-2026-0209 - Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies ear
CVE-2026-0207 - A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific cond
CVE-2025-70023 - An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in translo
CVE-2026-34626 - Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Impr
CVE-2026-34622 - Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Impr
CVE-2026-27291 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerabil
CVE-2026-27286 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
CVE-2026-27285 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
CVE-2026-27284 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerabili
CVE-2026-27283 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability th
CVE-2026-27238 - InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vuln
CVE-2026-22692 - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions
CVE-2026-5713 - The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "pyt
CVE-2026-4832 - CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to s
CVE-2026-38533 - An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows
CVE-2026-38532 - A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of
CVE-2026-38530 - A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of W
CVE-2026-38529 - A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Kr
CVE-2026-38528 - Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parame
CVE-2026-38527 - A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM
CVE-2026-38526 - An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul
CVE-2026-2405 - CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troublesho
CVE-2026-2404 - CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection
CVE-2026-2403 - CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Ev
CVE-2026-2402 - CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would al
CVE-2026-2401 - CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause conf
CVE-2026-2400 - CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could
CVE-2026-2399 - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability
CVE-2025-65136 - In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/ad
CVE-2025-65135 - In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists
CVE-2025-65134 - In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability
CVE-2025-65133 - A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580.
CVE-2025-65132 - alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/e
CVE-2025-63939 - Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Manag
CVE-2026-4914 - Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain l
CVE-2026-4913 - Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote auth
CVE-2026-4369 - A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete con
CVE-2026-4345 - A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Store
CVE-2026-4344 - A maliciously crafted HTML payload in a component name, when displayed during the delete confirmatio
CVE-2026-37980 - A flaw was found in Keycloak, specifically in the organization selection login page. A remote attack
CVE-2026-37602 - SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file
CVE-2026-37601 - SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file
CVE-2026-37600 - SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file
CVE-2026-37598 - SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (
CVE-2026-37597 - SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection
CVE-2026-37596 - SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection
CVE-2026-37595 - SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection
CVE-2026-37594 - SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection
CVE-2026-37593 - SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection
CVE-2026-37592 - Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/
CVE-2026-37591 - Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file
CVE-2026-37590 - SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file
CVE-2026-37589 - SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file
CVE-2026-30480 - A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-2
CVE-2025-69993 - Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bind
CVE-2025-69893 - A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed
CVE-2025-61260 - A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution th
CVE-2026-31049 - An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code
CVE-2025-8095 - The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been
CVE-2026-5307 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-2450 - .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Pri
CVE-2024-9168 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in
CVE-2026-2449 - Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.