Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-29089 Source A security vulnerability in the TimescaleDB extension for PostgreSQL allows malicious users to create custom functions that override built-in PostgreSQL functions, potentially enabling arbitrary code execution during extension upgrades. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-27005 Source Chartbrew, a web application for data visualization, contains an SQL injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL commands into connected databases, potentially reading, modifying, or deleting data. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-26932 Source A vulnerability in Packetbeat's PostgreSQL protocol parser allows attackers to crash the Packetbeat process by sending specially crafted network packets when PostgreSQL monitoring is enabled. |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2026-23984 Source A vulnerability in Apache Superset allows authenticated users with SQLLab access to bypass read-only restrictions on PostgreSQL connections and perform unauthorized data modifications or deletions. |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2026-23969 Source Apache Superset had an incomplete list of blocked SQL functions for ClickHouse database, potentially allowing attackers to execute sensitive database operations that should have been restricted. |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2025-67305 Source RUCKUS Network Director appliances use identical SSH keys across all installations, allowing attackers to log in without passwords and gain complete control over the PostgreSQL database and administrative user accounts. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2025-67304 Source A vulnerability in Ruckus Network Director allows attackers to remotely access the PostgreSQL database using hardcoded credentials, enabling them to gain administrator privileges and execute arbitrary system commands. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-2007 Source A vulnerability in PostgreSQL allows database users to cause a buffer overflow through crafted input strings, potentially leading to privilege escalation within the database system. affects: ≥18.0 <18.2 |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-2006 Source PostgreSQL databases have a vulnerability in multibyte character processing that allows database users to execute arbitrary code on the server through specially crafted queries. affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2 |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-2005 Source A memory corruption flaw in PostgreSQL's encryption module allows attackers to execute arbitrary code on the database server. Older versions before the mentioned security updates are affected. affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2 |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-2004 Source A vulnerability in PostgreSQL's intarray extension allows attackers to execute arbitrary code with database user privileges by exploiting unchecked inputs in a selectivity estimator function. affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2 |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-2003 Source A vulnerability in PostgreSQL allows database users to read small amounts of server memory, potentially exposing confidential information stored in that memory. affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2 |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2026-2361 Source A vulnerability in PostgreSQL Anonymizer allows users to gain superuser privileges by creating a temporary view with malicious code, enabling them to execute arbitrary code with the highest privileges. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-2360 Source A vulnerability in the PostgreSQL Anonymizer extension allows regular users to gain superuser privileges by creating malicious operators, which is particularly problematic in PostgreSQL 14 and older versions. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-44698 Source A security vulnerability in Home Assistant Companion apps for Android and iOS allows malicious websites to steal logged-in users' access tokens and execute arbitrary code through insecure JavaScript interfaces. |
Home Assistant | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-45323 Source A vulnerability in the MeshCore Card for Home Assistant allows attackers to execute malicious JavaScript code through node names when users view the card. |
Home Assistant | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2021-47942 Source A security vulnerability in Home Assistant Community Store allows attackers to access sensitive files without authentication and thereby gain administrator privileges. affects: <1.10.0 |
Home Assistant | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-40602 Source A vulnerability in the Home Assistant command-line tool allowed users to access Python internals and execute arbitrary code through Jinja2 templates without restrictions, extending beyond the intended template usage. affects: <1.0.0 |
Home Assistant | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-34205 Source Home Assistant apps using host network mode expose unprotected interfaces to the local network, allowing other devices to access them without authentication. |
Home Assistant | Self-hosted apps | Critical | 05.06.2026 |
| CVE-2026-33045 Source A vulnerability in Home Assistant home automation software allows cross-site scripting attacks through the mobile phone remaining charge time sensor, enabling attackers to execute malicious code in web browsers. affects: ≥2025.2.0 <2026.1.0 |
Home Assistant | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-33044 Source A security vulnerability in Home Assistant home automation software allows authenticated users to inject malicious code into device names, which then executes in other users' browsers when they hover over map points on the dashboard. affects: ≥2020.02 <2026.1.0 |
Home Assistant | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-32112 Source A vulnerability in the Home Assistant MCP Server OAuth feature allows attackers to execute malicious JavaScript code in the server administrator's browser when they open a crafted link. affects: <7.0.0 |
Home Assistant | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-32111 Source A vulnerability in Home Assistant MCP Server software allows attackers to submit arbitrary URLs and explore internal networks because no URL validation is performed. affects: <7.0.0 |
Home Assistant | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-25199 Source A security vulnerability in the Proxmox extension for Apache CloudStack allows attackers to access and fully control virtual machines belonging to other users because an editable setting is not properly validated against tenant ownership. |
Proxmox VE | OS & platform | Critical | 05.06.2026 |
| CVE-2026-45810 Source A security flaw in Nextcloud Server allows authenticated users to read all file comments, including those they should not normally have access to. affects: ≥31.0.0 <31.0.12; ≥32.0.0 <32.0.3; ≥21.0.0 <21.0.9.20; ≥22.0.0 <22.2.10.35; ≥23.0.0 <23.0.12.31; ≥24.0.0 <24.0.12.30; ≥25.0.0 <25.0.13.25; ≥26.0.0 <26.0.13.22 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45722 Source A security flaw in Nextcloud's Tables app allows users with app access to perform limited SQL injection attacks to gradually extract database information or cause delays. |
Nextcloud | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-45691 Source A security flaw in Nextcloud Server allows attackers to bypass two-factor authentication by misusing a session cookie as an access token, thereby gaining full read and write access to files. affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥29.0.0 <29.0.16.16; ≥30.0.0 <30.0.17.9; ≥31.0.0 <31.0.14.5 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45690 Source A security flaw in Nextcloud Server allows attackers to bypass two-factor authentication if they know a user's password. Certain versions of the cloud collaboration service are affected, enabling unauthorized access to protected areas. affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥29.0.0 <29.0.16.16; ≥30.0.0 <30.0.17.9; ≥31.0.0 <31.0.14.5 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45545 Source A security flaw in Nextcloud's Tables app allows authenticated users to inject malicious SQL commands into the database, enabling them to extract or modify data. |
Nextcloud | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-45544 Source A vulnerability in Nextcloud Tables allows users with read-only permissions to view filter criteria that should normally remain hidden from them. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45543 Source In the Nextcloud platform, removed collaborators can still access uploaded files from forms even after their permissions were revoked. This allows unauthorized read access to sensitive user files. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45286 Source A security vulnerability in Nextcloud allows authenticated users to enumerate other users on the same instance through the Calendar app, bypassing sharing restrictions that should prevent this disclosure. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45285 Source Nextcloud automatically creates hidden public links when folders are shared with Teams containing external email members. These invisible links grant full access to shared data without authentication and can be exploited by attackers. affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45284 Source A vulnerability in Nextcloud allowed deleted LDAP users to continue logging in through OIDC authentication even after their accounts were removed. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45283 Source A vulnerability in Nextcloud's file locking feature allows authenticated users to lock or unlock other users' files and view their lock tokens, enabling unauthorized access to files belonging to other users. affects: ≥32.0.0 <32.0.2; ≥33.0.0 <33.0.1; ≥31.0.0 <31.0.14.4 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45282 Source A security vulnerability in Nextcloud allows authenticated users to bypass password protection or download restrictions and access file attachments from link shares when they know the share token. affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥27.0.0 <27.1.11.5; ≥28.0.0 <28.0.14.17; ≥29.0.0 <29.0.16.16; ≥30.0.0 <30.0.17.9; ≥31.0.0 <31.0.14.5 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45281 Source A vulnerability in Nextcloud Server allows authenticated users to access and modify other users' calendars if they know the other user's URL due to improper authorization controls. affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥21.0.0 <21.0.9.23; ≥22.0.0 <22.2.10.39; ≥23.0.0 <23.0.12.35; ≥24.0.0 <24.0.12.34; ≥25.0.0 <25.0.13.29; ≥26.0.0 <26.0.13.26 |
Nextcloud | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-45279 Source A security vulnerability in Nextcloud Server allows regular users to copy arbitrary files into their own directory when a specific template configuration is used. affects: ≥31.0.0 <31.0.14; ≥32.0.0 <32.0.4; ≥28.0.0 <28.0.14.15; ≥29.0.0 <29.0.17.12; ≥30.0.0 <30.0.17.7 |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45278 Source A vulnerability in Nextcloud allows attackers to create malicious links that can redirect users to external websites when logging in via OIDC authentication. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-45277 Source A vulnerability in Nextcloud allows authenticated users to discover whether arbitrary files are linked to specific approval workflows, potentially exposing information about files they shouldn't have access to. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-45275 Source A vulnerability in Nextcloud's Approval app allows users without sharing permissions to force the system to share files with approvers, enabling unauthorized distribution of restricted content. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45267 Source A security flaw in Nextcloud allowed users to view form submissions from other users without proper authorization, potentially leading to unauthorized access to sensitive data. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45266 Source A vulnerability in Nextcloud allows low-privileged users to mute other participants' microphones in calls when no High-performance Backend is installed. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-45264 Source In Nextcloud versions between 17.0.0 and 21.0.4, users with read and create permissions can rename files in team folders even though they lack update permissions. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45159 Source In Nextcloud, malicious users with access to an encrypted file drop link can also upload files to other encrypted folders of the owner, even though they shouldn't have permission to do so. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-45157 Source A security vulnerability in Nextcloud allows malicious users with access to a file share to also view temporary partial files during ongoing uploads by exploiting the share token. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |
| CVE-2026-45156 Source A security flaw in Nextcloud's User OIDC feature allowed malicious ID4me authorities to impersonate any user due to missing signature verification checks. |
Nextcloud | Self-hosted apps | High | 05.06.2026 |
| CVE-2026-45155 Source A security flaw in Nextcloud Server allows adding unknown circles to other circles by their ID without proper access verification. This could be exploited to track memberships if the circle ID is obtained through other means. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-45154 Source A vulnerability in Nextcloud allowed guests with read-only access to shared collectives to view deleted pages from the trash, even though they shouldn't have permission to access them. |
Nextcloud | Self-hosted apps | Low | 05.06.2026 |
| CVE-2026-45153 Source A security flaw in the Nextcloud Files Android app allowed bypassing the PIN lock by using the back button after unlocking the phone, potentially granting unauthorized access to files. |
Nextcloud | Self-hosted apps | Medium | 05.06.2026 |