CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2026-25895Kritisch9.8
FUXA ist eine webbasierte Prozessvisualisierungssoftware (SCADA/HMI/Dashboard). Eine Path-Traversal-Schwachstelle in FUXA ermöglicht es einem nicht authentifizierten Remote-Angreifer, beliebige Dateien an beliebige Orte im Dateisystem des Servers zu schreiben. Dies betrifft FUXA bis Version 1.2.9. Dieses Problem wurde in FUXA Version 1.2.10 behoben.
- CVE-2026-1731Kritisch9.8
BeyondTrust Remote Support (RS) und bestimmte ältere Versionen von Privileged Remote Access (PRA) enthalten eine kritische Remote-Code-Execution-Schwachstelle vor der Authentifizierung. Durch das Senden speziell gestalteter Anfragen kann ein nicht authentifizierter Remote-Angreifer möglicherweise Betriebssystembefehle im Kontext des Site-Benutzers ausführen.
- CVE-2026-25725Kritisch10.0
Claude Code ist ein agentisches Coding-Tool. Vor Version 2.1.2 schützte der bubblewrap-Sandboxing-Mechanismus von Claude Code die Konfigurationsdatei .claude/settings.json nicht ordnungsgemäß, wenn sie beim Start nicht existierte. Während das übergeordnete Verzeichnis beschreibbar gemountet war und .claude/settings.local.json explizit mit Read-only-Einschränkungen geschützt war, war settings.json bei Fehlen nicht geschützt. Dies ermöglichte es bösartigem Code, der innerhalb der Sandbox ausgeführt wurde, diese Datei zu erstellen und persistente Hooks (wie SessionStart-Commands) zu injizieren, die mit Host-Privilegien ausgeführt würden, wenn Claude Code neu gestartet wurde. Dieses Problem wurde in Version 2.1.2 gepatcht.
- CVE-2026-21643Kritisch9.8
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
- CVE-2025-69981Kritisch9.8
FUXA v1.2.7 enthält eine Unrestricted File Upload-Schwachstelle im API-Endpunkt `/api/upload`. Dem Endpunkt fehlen Authentifizierungsmechanismen, sodass nicht authentifizierte Remote-Angreifer beliebige Dateien hochladen können. Dies kann ausgenutzt werden, um kritische Systemdateien (wie die SQLite-Benutzerdatenbank) zu überschreiben, um administrativen Zugriff zu erlangen, oder um bösartige Skripte hochzuladen, um beliebigen Code auszuführen.
- CVE-2025-15556Hoch7.5
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.
- CVE-2026-1340Kritisch9.8
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2026-1281Kritisch9.8
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2025-40551Kritisch9.8
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- CVE-2025-40536Hoch8.1
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
- CVE-2026-24858Kritisch9.8
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
- CVE-2026-21509Hoch7.8
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-24423Kritisch9.8
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
- CVE-2026-0770Kritisch9.8
Langflow exec_globals Einbindung von Funktionalität aus nicht vertrauenswürdiger Kontrollsphäre Remote Code Execution-Schwachstelle. Diese Schwachstelle ermöglicht es entfernten Angreifern, beliebigen Code auf betroffenen Installationen von Langflow auszuführen. Zur Ausnutzung dieser Schwachstelle ist keine Authentifizierung erforderlich. Der spezifische Fehler liegt in der Behandlung des Parameters exec_globals, der an den validate-Endpunkt übergeben wird. Das Problem resultiert aus der Einbindung einer Ressource aus einer nicht vertrauenswürdigen Kontrollsphäre. Ein Angreifer kann diese Schwachstelle ausnutzen, um Code im Kontext von root auszuführen. War ZDI-CAN-27325.
- CVE-2026-0768Kritisch9.8
Langflow Code Code Injection Remote Code Execution Schwachstelle. Diese Schwachstelle ermöglicht es Remote-Angreifern, beliebigen Code auf betroffenen Installationen von Langflow auszuführen. Zur Ausnutzung dieser Schwachstelle ist keine Authentifizierung erforderlich. Der spezifische Fehler liegt in der Verarbeitung des code-Parameters, der an den validate-Endpunkt übermittelt wird. Das Problem resultiert aus der fehlenden ordnungsgemäßen Validierung einer vom Benutzer bereitgestellten Zeichenkette vor deren Verwendung zur Ausführung von Python-Code. Ein Angreifer kann diese Schwachstelle ausnutzen, um Code im Kontext von root auszuführen. . War ZDI-CAN-27322.
- CVE-2025-9289Mittel4.7
Eine Cross-Site Scripting (XSS)-Schwachstelle wurde in einem Parameter in Omada Controllers aufgrund unsachgemäßer Eingabebereinigung festgestellt. Die Ausnutzung erfordert erweiterte Bedingungen, wie Netzwerkpositionierung oder das Emulieren einer vertrauenswürdigen Entität, sowie eine Benutzerinteraktion durch einen authentifizierten Administrator. Im Erfolgsfall könnte ein Angreifer beliebiges JavaScript im Browser des Administrators ausführen, wodurch möglicherweise sensible Informationen offengelegt und die Vertraulichkeit kompromittiert werden.
- CVE-2026-23760Kritisch9.8
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.
- CVE-2026-20045Hoch8.2
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
- CVE-2026-24061Kritisch9.8
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
- CVE-2026-21962Kritisch10.0
Schwachstelle im Produkt Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in von Oracle Fusion Middleware (Komponente: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Betroffene unterstützte Versionen sind 12.2.1.4.0, 14.1.1.0.0 und 14.1.2.0.0. Leicht ausnutzbare Schwachstelle ermöglicht einem nicht authentifizierten Angreifer mit Netzwerkzugriff über HTTP, Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in zu kompromittieren. Während sich die Schwachstelle in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in befindet, können Angriffe zusätzliche Produkte erheblich beeinträchtigen (scope change). Erfolgreiche Angriffe dieser Schwachstelle können zu unbefugtem Erstellen, Löschen oder Ändern kritischer Daten oder aller für Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in zugänglichen Daten sowie zu unbefugtem Zugriff auf kritische Daten oder vollständigem Zugriff auf alle für Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in zugänglichen Daten führen. Hinweis: Betroffene Version für Weblogic Server Proxy Plug-in for IIS ist nur 12.2.1.4.0. CVSS 3.1 Basiswert 10.0 (Auswirkungen auf Vertraulichkeit und Integrität). CVSS-Vektor: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
This product uses the NVD API but is not endorsed or certified by the NVD.