Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-11 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-48081 | OpenReception appointment-booking-software up to 1.0.1 SvelteKit Button /api/public cross site scripting
A vulnerability, which was classified as problematic, was found in OpenReception appointment-booking-software up to 1.0.1. Affected is an unknown function of the file /api/public of the component SvelteKit Button Component. Executing a mani
CVE-2026-48082 | OpenReception appointment-booking-software up to 1.0.5 Bootstrap Challenge bootstrap-challenge tunnelId/clientPublicKey/emailHash allocation of resources
A vulnerability described as critical has been identified in OpenReception appointment-booking-software up to 1.0.5. The affected element is an unknown function of the file /api/tenants/{id}/appointments/bootstrap-challenge of the component
CVE-2026-48079 | OpenReception Appointment Booking Software up to 1.0.1 Logout /logout SessionService.revokeSession improper authentication
A vulnerability marked as critical has been reported in OpenReception Appointment Booking Software up to 1.0.1. Impacted is the function SessionService.revokeSession of the file /logout of the component Logout Handler. The manipulation lead
CVE-2026-48078 | OpenReception Appointment Booking Software up to 1.0.4 Schedule Endpoint schedule ID information disclosure
A vulnerability categorized as problematic has been discovered in OpenReception Appointment Booking Software up to 1.0.4. This affects an unknown part of the file /api/tenants/{id}/schedule of the component Schedule Endpoint. Such manipulat
CVE-2026-48083 | OpenReception appointment-booking-software up to 1.0.1 /api/log neutralization for logs
A vulnerability was found in OpenReception appointment-booking-software up to 1.0.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/log. The manipulation results in improper out
CVE-2026-48077 | open-reception appointment-booking-software up to 1.0.x GET {appointmentId} appointmentId improper authorization
A vulnerability, which was classified as problematic, has been found in open-reception appointment-booking-software up to 1.0.x. The affected element is an unknown function of the file /api/tenants/{id}/appointments/{appointmentId} of the c
CVE-2026-48080 | OpenReception appointment-booking-software up to 1.0.1 Tenant API Endpoint docker-compose.prod.yml improper authorization
A vulnerability, which was classified as problematic, was found in OpenReception appointment-booking-software up to 1.0.1. The impacted element is an unknown function of the file docker-compose.prod.yml of the component Tenant API Endpoint.
CVE-2026-48074 | OpenReception Appointment Booking up to 1.0.5 StaffService.deleteStaffMember privileges management
A vulnerability described as problematic has been identified in OpenReception Appointment Booking up to 1.0.5. This vulnerability affects the function StaffService.deleteStaffMember. Executing a manipulation can lead to improper privilege m
CVE-2026-48075 | OpenReception appointment-booking-software up to 1.0.4 add-to-tunnel tunnelId/emailHash improper authorization
A vulnerability classified as critical has been found in OpenReception appointment-booking-software up to 1.0.4. This issue affects some unknown processing of the component add-to-tunnel. The manipulation of the argument tunnelId/emailHash
CVE-2026-48076 | OpenReception appointment-booking-software up to 1.0.1 New Client Flow /api/public/channels createNewClientWithAppointment channelId information disclosure
A vulnerability marked as problematic has been reported in OpenReception appointment-booking-software up to 1.0.1. Affected is the function createNewClientWithAppointment of the file /api/public/channels of the component New Client Flow. Th
CVE-2026-48071 | open-reception appointment-booking-software up to 1.0.3 throttle service emailHash denial of service
A vulnerability marked as problematic has been reported in open-reception appointment-booking-software up to 1.0.3. This affects an unknown part of the component throttle service. Performing a manipulation of the argument emailHash results
CVE-2026-84869 | ConnectWise ScreenConnect Client privileges management (EUVD-2026-74053)
A vulnerability was found in ConnectWise ScreenConnect. It has been rated as critical. This vulnerability affects unknown code of the component Client. The manipulation leads to improper privilege management. This vulnerability is uniquely
CVE-2026-59310 | VMware vCenter Syslog server path traversal
A vulnerability, which was classified as very critical, has been found in VMware vCenter. This vulnerability affects unknown code of the component Syslog server. This manipulation causes path traversal. This vulnerability is registered as C
CVE-2026-42018 | JFrog Artifactory up to 7.146.7 information disclosure
A vulnerability described as problematic has been identified in JFrog Artifactory up to 7.146.7. The affected element is an unknown function. The manipulation results in information disclosure. This vulnerability is reported as CVE-2026-420
CVE-2026-72774 | n8n-io n8n prior 1.123.67/2.31.5/2.32.1 HTTP Request Node authorization
A vulnerability was found in n8n-io n8n. It has been rated as critical. Affected is an unknown function of the component HTTP Request Node. Performing a manipulation results in authorization bypass. This vulnerability is identified as CVE-2
CVE-2026-72764 | n8n-io n8n prior 1.123.67/2.31.5/2.32.1 JavaScript Task Runner privileges management
A vulnerability marked as critical has been reported in n8n-io n8n. Affected by this vulnerability is an unknown functionality of the component JavaScript Task Runner. The manipulation leads to improper privilege management. This vulnerabil
CVE-2026-72921 | SeaweedFS up to 4.23 Authorization Check filer_server_handlers.go strings.HasPrefix improper authorization (EUVD-2026-56159)
A vulnerability classified as very critical has been found in SeaweedFS up to 4.23. This vulnerability affects the function strings.HasPrefix of the file weed/server/filer_server_handlers.go of the component Authorization Check. Performing
CVE-2026-72920 | SeaweedFS up to 4.23 Filer improper authentication
A vulnerability described as critical has been identified in SeaweedFS up to 4.23. This affects an unknown part of the component Filer. Such manipulation leads to improper authentication. This vulnerability is listed as CVE-2026-72920. The
CVE-2026-47702 | BaptisteArno Typebot 3.16.1 sql injection
A vulnerability marked as critical has been reported in BaptisteArno Typebot 3.16.1. Affected by this issue is some unknown functionality. This manipulation causes sql injection. This vulnerability is tracked as CVE-2026-47702. The attack i
CVE-2026-48056 | truelockmc Streambert up to 2.4.x IPC handler run-download input validation
A vulnerability categorized as critical has been discovered in truelockmc Streambert up to 2.4.x. This impacts the function run-download of the component IPC handler. Executing a manipulation can lead to improper input validation. The ident
CVE-2026-46670 | YesWiki up to 4.6.3 FormManager::create sql injection
A vulnerability, which was classified as critical, was found in YesWiki up to 4.6.3. This vulnerability affects the function FormManager::create. Executing a manipulation can lead to sql injection. This vulnerability appears as CVE-2026-466
CVE-2026-48046 | truelockmc Streambert up to 2.4.x Auto-Update code download
A vulnerability classified as critical was found in truelockmc Streambert up to 2.4.x. Affected by this issue is some unknown functionality of the component Auto-Update. Such manipulation leads to download of code without integrity check. T
CVE-2026-50064 | Siemens Solid Edge prior 225.0 Update 15/226.0 Update 7 PSM File out-of-bounds write
A vulnerability labeled as problematic has been found in Siemens Solid Edge. Impacted is an unknown function of the component PSM File Handler. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-50064.
CVE-2026-72772 | n8n-io n8n up to 2.31.4/2.32.0 Token Exchange Embed Login feature improper authentication
A vulnerability marked as critical has been reported in n8n-io n8n up to 2.31.4/2.32.0. This vulnerability affects unknown code of the component Token Exchange Embed Login feature. This manipulation causes improper authentication. This vuln
CVE-2026-72767 | n8n-io n8n Git node behavioral workflow
A vulnerability identified as critical has been detected in n8n-io n8n. Affected by this issue is some unknown functionality of the component Git node. The manipulation leads to enforcement of behavioral workflow. This vulnerability is list
CVE-2026-72769 | n8n-io n8n prior 1.123.67/2.31.5/2.32.1 VM expression engine prototype pollution
A vulnerability was found in n8n-io n8n. It has been declared as critical. This impacts an unknown function of the component VM expression engine. Such manipulation leads to improperly controlled modification of object prototype attributes.
CVE-2026-72762 | n8n-io n8n Edit Image Node format file inclusion
A vulnerability was found in n8n-io n8n and classified as critical. The impacted element is an unknown function of the component Edit Image Node. The manipulation of the argument format results in file inclusion. This vulnerability was name
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV
CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security &amp; Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
Critical ConfigServer Security & Firewall Flaw Lets Remote Attackers Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands on vulnerable servers. Tracked as CVE-2026-65638, the flaw affects CSF versions 14.00 thro
Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz R
Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz R
Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 to bypass authentication, escalate privileges, and seize administrative control of exposed instances. The a
Cisco warnt: Ausnutzung von FMC-Sicherheitslücken ermöglicht Qilin-Ransomware
LONDON (IT BOLTWISE) – Cisco meldet, dass Angreifende zwei kürzlich gepatchte Schwachstellen im Secure Firewall Management Center (FMC) nutzen, um erst Credentials zu stehlen und anschließend Qilin-Ransomware auszurollen. Besonders kritisch
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added th
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Google fixes the seventh actively exploited Chrome zero-day of 2026
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already expl
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
N-able issues patch for zero-day flaw
Security researchers warned the company of unusual threat activity in a recently patched N-able environment. Weiterlesen
Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b