CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2026-21385Hoch7.8
Memory corruption while using alignments for memory allocation.
- CVE-2026-22719Hoch8.1
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
- CVE-2026-20133Mittel6.5
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.
- CVE-2026-20128Hoch7.5
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
- CVE-2026-20127Kritisch10.0
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
- CVE-2026-20122Mittel5.4
A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
- CVE-2026-22769Kritisch10.0
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
- CVE-2026-2441Hoch8.8
Use after free in CSS in Google Chrome vor 145.0.7632.75 ermöglichte es einem Remote-Angreifer, beliebigen Code innerhalb einer Sandbox über eine speziell gestaltete HTML-Seite auszuführen. (Chromium-Sicherheitsschweregrad: Hoch)
- CVE-2026-25108Hoch8.8
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
- CVE-2025-9293Hoch8.1
Eine Schwachstelle in der Logik zur Zertifikatsvalidierung kann es Anwendungen ermöglichen, nicht vertrauenswürdige oder nicht ordnungsgemäß validierte Serveridentitäten während der TLS-Kommunikation zu akzeptieren. Ein Angreifer in einer privilegierten Netzwerkposition kann möglicherweise Datenverkehr abfangen oder manipulieren, wenn er sich innerhalb des Kommunikationskanals positionieren kann. Eine erfolgreiche Ausnutzung kann die Vertraulichkeit, Integrität und Verfügbarkeit von Anwendungsdaten beeinträchtigen.
- CVE-2026-20700Hoch7.8
Ein Problem mit Speicherbeschädigung wurde durch eine verbesserte Zustandsverwaltung behoben. Dieses Problem wurde in iOS 26.3 und iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3 behoben. Ein Angreifer mit Schreibzugriff auf den Speicher kann möglicherweise beliebigen Code ausführen. Apple ist ein Bericht bekannt, wonach dieses Problem möglicherweise in einem äußerst ausgeklügelten Angriff gegen bestimmte Zielpersonen auf iOS-Versionen vor iOS 26 ausgenutzt wurde. CVE-2025-14174 und CVE-2025-43529 wurden ebenfalls als Reaktion auf diesen Bericht veröffentlicht.
- CVE-2026-21533Hoch7.8
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
- CVE-2026-21525Mittel6.2
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
- CVE-2026-21519Hoch7.8
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-21514Hoch7.8
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-21513Hoch8.8
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21510Hoch8.8
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-1603Hoch8.6
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
- CVE-2025-68686Mittel5.9
Eine Schwachstelle zur Offenlegung sensibler Informationen gegenüber einem unbefugten Akteur [CWE-200] in Fortinet FortiOS 7.6.0 bis 7.6.1, FortiOS 7.4.0 bis 7.4.6, FortiOS 7.2 alle Versionen, FortiOS 7.0 alle Versionen, FortiOS 6.4 alle Versionen kann es einem nicht authentifizierten Remote-Angreifer ermöglichen, über manipulierte HTTP-Anfragen den für den in einigen Post-Exploit-Fällen beobachteten Symbolic-Link-Persistenzmechanismus entwickelten Patch zu umgehen. Ein Angreifer müsste das Produkt zuerst über eine andere Schwachstelle auf Dateisystemebene kompromittiert haben.
- CVE-2026-25939Kritisch9.1
FUXA ist eine webbasierte Prozessvisualisierungssoftware (SCADA/HMI/Dashboard). Von 1.2.8 bis Version 1.2.10 ermöglicht eine Authorization-Bypass-Schwachstelle in FUXA einem nicht authentifizierten Remote-Angreifer, beliebige Scheduler zu erstellen und zu ändern, wodurch verbundene ICS/SCADA-Umgebungen Folgeaktionen ausgesetzt werden. Dies wurde in FUXA Version 1.2.11 gepatcht.
This product uses the NVD API but is not endorsed or certified by the NVD.