Ausgenutzt & nachgewiesen — die Weaponization-Front
Nur Schwachstellen mit Exploit-Nachweis: CISA-KEV, aktive Ausnutzung und Proof-of-Concepts — die Reihenfolge, in der Angreifer wirklich arbeiten.
🆕 KEV-Neuzugänge (7 Tage)
CVE-2026-107817 | MariaDB up to 13.0.1 mysql_json plugin out-of-bounds (Nessus ID 364534)
A vulnerability identified as problematic has been detected in MariaDB up to 13.0.1. Affected by this issue is some unknown functionality of the component mysql_json plugin. Performing a manipulation results in out-of-bounds read. This vuln
CVE-2026-98383 | Linux Kernel up to 7.3-rc4 BPF bpf_skb_pull_data/bpf_lwt_seg6_adjust_srh use after free (EUVD-2026-95538 / Nessus ID 364536)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.3-rc4. The impacted element is the function bpf_skb_pull_data/bpf_lwt_seg6_adjust_srh of the component BPF. The manipulation results in use after free.
CVE-2026-108106 | Xerial snappy-java prior 1.1.10.9 Decompression Snappy.uncompress allocation of resources (Nessus ID 364535)
A vulnerability identified as problematic has been detected in Xerial snappy-java. This vulnerability affects the function Snappy.uncompress of the component Decompression. Performing a manipulation results in allocation of resources. This
CVE-2026-98380 | Linux Kernel up to 7.3-rc4 net/sched net/sched/act_api.c tcf_action_delete/tcf_idr_delete_index null pointer dereference (EUVD-2026-95535 / Nessus ID 364537)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.3-rc4. Affected by this issue is the function tcf_action_delete/tcf_idr_delete_index of the file net/sched/act_api.c of the component net/sched. The m
CVE-2026-108104 | xerial snappy-java 1.1.10.9 SnappyFramedInputStream buffer overflow (Nessus ID 364538)
A vulnerability identified as critical has been detected in xerial snappy-java 1.1.10.9. Affected by this vulnerability is the function SnappyFramedInputStream. This manipulation causes buffer overflow. This vulnerability is handled as CVE-
CVE-2026-106429 | MongoDB libmongocrypt up to 1.20.4 Kms Endpoint integer underflow (Nessus ID 364539)
A vulnerability marked as problematic has been reported in MongoDB libmongocrypt up to 1.20.4. This impacts an unknown function of the component Kms Endpoint. Performing a manipulation results in integer underflow. This vulnerability is kno
CVE-2026-98376 | Linux Kernel BPF percpu_array_map_gen_lookup pptrs out-of-bounds (EUVD-2026-95531 / Nessus ID 364540)
A vulnerability, which was classified as very critical, has been found in Linux Kernel. Affected by this vulnerability is the function percpu_array_map_gen_lookup of the component BPF. The manipulation of the argument pptrs leads to out-of-
CVE-2026-107822 | MariaDB up to 13.0.1 Acl Cache privileges management (Nessus ID 364541)
A vulnerability labeled as very critical has been found in MariaDB up to 13.0.1. This affects an unknown part of the component Acl Cache. Executing a manipulation can lead to improper privilege management. This vulnerability appears as CVE-
CVE-2023-4630 | GitLab Project Import information disclosure (Issue 415117 / EUVD-2023-54483)
A vulnerability described as problematic has been identified in GitLab. Impacted is an unknown function of the component Project Import Handler. Executing a manipulation can lead to information disclosure. This vulnerability appears as CVE-
CVE-2023-5963 | GitLab Enterprise Edition prior 16.3.6/16.4.2/16.5.1 Advanced Search denial of service (Issue 42346 / EUVD-2023-58234)
A vulnerability categorized as problematic has been discovered in GitLab Enterprise Edition. Impacted is an unknown function of the component Advanced Search. Executing a manipulation can lead to denial of service. This vulnerability is han
CVE-2023-5831 | GitLab Community Edition/Enterprise Edition prior 16.3.6/16.4.2/16.5.1 Feature Flag information disclosure (Issue 428919 / EUVD-2023-58114)
A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition. This vulnerability affects unknown code of the component Feature Flag Handler. Performing a manipulation results in information
CVE-2026-96648 | Supsystic Data Tables Generator by Supsystic Plugin up to 1.15.1 on WordPress Table Cell Data updateRows data cross site scripting (EUVD-2026-96053)
A vulnerability was found in Supsystic Data Tables Generator by Supsystic Plugin up to 1.15.1 on WordPress. It has been rated as problematic. The affected element is the function updateRows of the component Table Cell Data Handler. This man
🔥 Aktiv ausgenutzt (CISA KEV)
Hackers Exploit Two AhsayCBS Zero-Day Flaws to Gain SYSTEM Access on Backup Servers
Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed backup servers without authentication and execute commands with SYSTEM privileges. Observed attacks have deployed web sh
CVE-2026-88779 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
CVE-2026-104286 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow
CVE-2026-102490 | Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service processes began running as root and executed files that were owned and writable by the zammad account before dropping their identity to that account. An attacker holding that foothold could have escalated within seconds, because
Zammad packages built with packager.io (DEB and RPM) could have allowed a local attacker who already had file system write privileges as the unprivileged zammad service account to escalate to full root privileges on the host. Service proces
CVE-2026-102489 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underl
CVE-2026-76504 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerabilit
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due
CVE-2026-86950 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execut
CVE-2026-88772 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.
CVE-2026-88771 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1
CVE-2026-87902 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are me
CVE-2026-94127 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unau
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Author
CVE-2026-93616 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Gesamte Liste mit Filtern: CVE-Radar KEV-Ansicht ↗