34,417 Entries 2,249 Sources 5 Verticals Last sync 12 minutes Live
Dashboard/Security
Sicherheit

Security

All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.

Sort: Newest Severity
CVE / GHSAItemVerticalSeverityDate
CVE-2026-29089 Source
A security vulnerability in the TimescaleDB extension for PostgreSQL allows malicious users to create custom functions that override built-in PostgreSQL functions, potentially enabling arbitrary code execution during extension upgrades.
PostgreSQL OS & platform High 05.06.2026
CVE-2026-27005 Source
Chartbrew, a web application for data visualization, contains an SQL injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL commands into connected databases, potentially reading, modifying, or deleting data.
PostgreSQL OS & platform Critical 05.06.2026
CVE-2026-26932 Source
A vulnerability in Packetbeat's PostgreSQL protocol parser allows attackers to crash the Packetbeat process by sending specially crafted network packets when PostgreSQL monitoring is enabled.
PostgreSQL OS & platform Medium 05.06.2026
CVE-2026-23984 Source
A vulnerability in Apache Superset allows authenticated users with SQLLab access to bypass read-only restrictions on PostgreSQL connections and perform unauthorized data modifications or deletions.
PostgreSQL OS & platform Medium 05.06.2026
CVE-2026-23969 Source
Apache Superset had an incomplete list of blocked SQL functions for ClickHouse database, potentially allowing attackers to execute sensitive database operations that should have been restricted.
PostgreSQL OS & platform Medium 05.06.2026
CVE-2025-67305 Source
RUCKUS Network Director appliances use identical SSH keys across all installations, allowing attackers to log in without passwords and gain complete control over the PostgreSQL database and administrative user accounts.
PostgreSQL OS & platform Critical 05.06.2026
CVE-2025-67304 Source
A vulnerability in Ruckus Network Director allows attackers to remotely access the PostgreSQL database using hardcoded credentials, enabling them to gain administrator privileges and execute arbitrary system commands.
PostgreSQL OS & platform Critical 05.06.2026
CVE-2026-2007 Source
A vulnerability in PostgreSQL allows database users to cause a buffer overflow through crafted input strings, potentially leading to privilege escalation within the database system.
affects: ≥18.0 <18.2
PostgreSQL OS & platform High 05.06.2026
CVE-2026-2006 Source
PostgreSQL databases have a vulnerability in multibyte character processing that allows database users to execute arbitrary code on the server through specially crafted queries.
affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2
PostgreSQL OS & platform High 05.06.2026
CVE-2026-2005 Source
A memory corruption flaw in PostgreSQL's encryption module allows attackers to execute arbitrary code on the database server. Older versions before the mentioned security updates are affected.
affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2
PostgreSQL OS & platform High 05.06.2026
CVE-2026-2004 Source
A vulnerability in PostgreSQL's intarray extension allows attackers to execute arbitrary code with database user privileges by exploiting unchecked inputs in a selectivity estimator function.
affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2
PostgreSQL OS & platform High 05.06.2026
CVE-2026-2003 Source
A vulnerability in PostgreSQL allows database users to read small amounts of server memory, potentially exposing confidential information stored in that memory.
affects: ≥14.0 <14.21; ≥15.0 <15.16; ≥16.0 <16.12; ≥17.0 <17.8; ≥18.0 <18.2
PostgreSQL OS & platform Medium 05.06.2026
CVE-2026-2361 Source
A vulnerability in PostgreSQL Anonymizer allows users to gain superuser privileges by creating a temporary view with malicious code, enabling them to execute arbitrary code with the highest privileges.
PostgreSQL OS & platform High 05.06.2026
CVE-2026-2360 Source
A vulnerability in the PostgreSQL Anonymizer extension allows regular users to gain superuser privileges by creating malicious operators, which is particularly problematic in PostgreSQL 14 and older versions.
PostgreSQL OS & platform High 05.06.2026
CVE-2026-44698 Source
A security vulnerability in Home Assistant Companion apps for Android and iOS allows malicious websites to steal logged-in users' access tokens and execute arbitrary code through insecure JavaScript interfaces.
Home Assistant Self-hosted apps High 05.06.2026
CVE-2026-45323 Source
A vulnerability in the MeshCore Card for Home Assistant allows attackers to execute malicious JavaScript code through node names when users view the card.
Home Assistant Self-hosted apps Critical 05.06.2026
CVE-2021-47942 Source
A security vulnerability in Home Assistant Community Store allows attackers to access sensitive files without authentication and thereby gain administrator privileges.
affects: <1.10.0
Home Assistant Self-hosted apps High 05.06.2026
CVE-2026-40602 Source
A vulnerability in the Home Assistant command-line tool allowed users to access Python internals and execute arbitrary code through Jinja2 templates without restrictions, extending beyond the intended template usage.
affects: <1.0.0
Home Assistant Self-hosted apps Medium 05.06.2026
CVE-2026-34205 Source
Home Assistant apps using host network mode expose unprotected interfaces to the local network, allowing other devices to access them without authentication.
Home Assistant Self-hosted apps Critical 05.06.2026
CVE-2026-33045 Source
A vulnerability in Home Assistant home automation software allows cross-site scripting attacks through the mobile phone remaining charge time sensor, enabling attackers to execute malicious code in web browsers.
affects: ≥2025.2.0 <2026.1.0
Home Assistant Self-hosted apps Medium 05.06.2026
CVE-2026-33044 Source
A security vulnerability in Home Assistant home automation software allows authenticated users to inject malicious code into device names, which then executes in other users' browsers when they hover over map points on the dashboard.
affects: ≥2020.02 <2026.1.0
Home Assistant Self-hosted apps Medium 05.06.2026
CVE-2026-32112 Source
A vulnerability in the Home Assistant MCP Server OAuth feature allows attackers to execute malicious JavaScript code in the server administrator's browser when they open a crafted link.
affects: <7.0.0
Home Assistant Self-hosted apps Medium 05.06.2026
CVE-2026-32111 Source
A vulnerability in Home Assistant MCP Server software allows attackers to submit arbitrary URLs and explore internal networks because no URL validation is performed.
affects: <7.0.0
Home Assistant Self-hosted apps Medium 05.06.2026
CVE-2026-25199 Source
A security vulnerability in the Proxmox extension for Apache CloudStack allows attackers to access and fully control virtual machines belonging to other users because an editable setting is not properly validated against tenant ownership.
Proxmox VE OS & platform Critical 05.06.2026
CVE-2026-45810 Source
A security flaw in Nextcloud Server allows authenticated users to read all file comments, including those they should not normally have access to.
affects: ≥31.0.0 <31.0.12; ≥32.0.0 <32.0.3; ≥21.0.0 <21.0.9.20; ≥22.0.0 <22.2.10.35; ≥23.0.0 <23.0.12.31; ≥24.0.0 <24.0.12.30; ≥25.0.0 <25.0.13.25; ≥26.0.0 <26.0.13.22
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45722 Source
A security flaw in Nextcloud's Tables app allows users with app access to perform limited SQL injection attacks to gradually extract database information or cause delays.
Nextcloud Self-hosted apps High 05.06.2026
CVE-2026-45691 Source
A security flaw in Nextcloud Server allows attackers to bypass two-factor authentication by misusing a session cookie as an access token, thereby gaining full read and write access to files.
affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥29.0.0 <29.0.16.16; ≥30.0.0 <30.0.17.9; ≥31.0.0 <31.0.14.5
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45690 Source
A security flaw in Nextcloud Server allows attackers to bypass two-factor authentication if they know a user's password. Certain versions of the cloud collaboration service are affected, enabling unauthorized access to protected areas.
affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥29.0.0 <29.0.16.16; ≥30.0.0 <30.0.17.9; ≥31.0.0 <31.0.14.5
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45545 Source
A security flaw in Nextcloud's Tables app allows authenticated users to inject malicious SQL commands into the database, enabling them to extract or modify data.
Nextcloud Self-hosted apps High 05.06.2026
CVE-2026-45544 Source
A vulnerability in Nextcloud Tables allows users with read-only permissions to view filter criteria that should normally remain hidden from them.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45543 Source
In the Nextcloud platform, removed collaborators can still access uploaded files from forms even after their permissions were revoked. This allows unauthorized read access to sensitive user files.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45286 Source
A security vulnerability in Nextcloud allows authenticated users to enumerate other users on the same instance through the Calendar app, bypassing sharing restrictions that should prevent this disclosure.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45285 Source
Nextcloud automatically creates hidden public links when folders are shared with Teams containing external email members. These invisible links grant full access to shared data without authentication and can be exploited by attackers.
affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45284 Source
A vulnerability in Nextcloud allowed deleted LDAP users to continue logging in through OIDC authentication even after their accounts were removed.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45283 Source
A vulnerability in Nextcloud's file locking feature allows authenticated users to lock or unlock other users' files and view their lock tokens, enabling unauthorized access to files belonging to other users.
affects: ≥32.0.0 <32.0.2; ≥33.0.0 <33.0.1; ≥31.0.0 <31.0.14.4
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45282 Source
A security vulnerability in Nextcloud allows authenticated users to bypass password protection or download restrictions and access file attachments from link shares when they know the share token.
affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥27.0.0 <27.1.11.5; ≥28.0.0 <28.0.14.17; ≥29.0.0 <29.0.16.16; ≥30.0.0 <30.0.17.9; ≥31.0.0 <31.0.14.5
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45281 Source
A vulnerability in Nextcloud Server allows authenticated users to access and modify other users' calendars if they know the other user's URL due to improper authorization controls.
affects: ≥32.0.0 <32.0.9; ≥33.0.0 <33.0.3; ≥21.0.0 <21.0.9.23; ≥22.0.0 <22.2.10.39; ≥23.0.0 <23.0.12.35; ≥24.0.0 <24.0.12.34; ≥25.0.0 <25.0.13.29; ≥26.0.0 <26.0.13.26
Nextcloud Self-hosted apps High 05.06.2026
CVE-2026-45279 Source
A security vulnerability in Nextcloud Server allows regular users to copy arbitrary files into their own directory when a specific template configuration is used.
affects: ≥31.0.0 <31.0.14; ≥32.0.0 <32.0.4; ≥28.0.0 <28.0.14.15; ≥29.0.0 <29.0.17.12; ≥30.0.0 <30.0.17.7
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45278 Source
A vulnerability in Nextcloud allows attackers to create malicious links that can redirect users to external websites when logging in via OIDC authentication.
Nextcloud Self-hosted apps Low 05.06.2026
CVE-2026-45277 Source
A vulnerability in Nextcloud allows authenticated users to discover whether arbitrary files are linked to specific approval workflows, potentially exposing information about files they shouldn't have access to.
Nextcloud Self-hosted apps Low 05.06.2026
CVE-2026-45275 Source
A vulnerability in Nextcloud's Approval app allows users without sharing permissions to force the system to share files with approvers, enabling unauthorized distribution of restricted content.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45267 Source
A security flaw in Nextcloud allowed users to view form submissions from other users without proper authorization, potentially leading to unauthorized access to sensitive data.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45266 Source
A vulnerability in Nextcloud allows low-privileged users to mute other participants' microphones in calls when no High-performance Backend is installed.
Nextcloud Self-hosted apps Low 05.06.2026
CVE-2026-45264 Source
In Nextcloud versions between 17.0.0 and 21.0.4, users with read and create permissions can rename files in team folders even though they lack update permissions.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45159 Source
In Nextcloud, malicious users with access to an encrypted file drop link can also upload files to other encrypted folders of the owner, even though they shouldn't have permission to do so.
Nextcloud Self-hosted apps Low 05.06.2026
CVE-2026-45157 Source
A security vulnerability in Nextcloud allows malicious users with access to a file share to also view temporary partial files during ongoing uploads by exploiting the share token.
Nextcloud Self-hosted apps Medium 05.06.2026
CVE-2026-45156 Source
A security flaw in Nextcloud's User OIDC feature allowed malicious ID4me authorities to impersonate any user due to missing signature verification checks.
Nextcloud Self-hosted apps High 05.06.2026
CVE-2026-45155 Source
A security flaw in Nextcloud Server allows adding unknown circles to other circles by their ID without proper access verification. This could be exploited to track memberships if the circle ID is obtained through other means.
Nextcloud Self-hosted apps Low 05.06.2026
CVE-2026-45154 Source
A vulnerability in Nextcloud allowed guests with read-only access to shared collectives to view deleted pages from the trash, even though they shouldn't have permission to access them.
Nextcloud Self-hosted apps Low 05.06.2026
CVE-2026-45153 Source
A security flaw in the Nextcloud Files Android app allowed bypassing the PIN lock by using the back button after unlocking the phone, potentially granting unauthorized access to files.
Nextcloud Self-hosted apps Medium 05.06.2026