CVE-2008-2554: Schwachstellen-Eintrag (NVD)
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-14 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-69256 | FlowiseAI Flowise up to 3.1.2 CSVAgent CSVAgent.ts pandas.read_pickle customReadCSVFunc deserialization
A vulnerability, which was classified as critical, was found in FlowiseAI Flowise up to 3.1.2. Affected by this issue is the function pandas.read_pickle of the file flowise-components/nodes/agents/CSVAgent/CSVAgent.ts of the component CSVAg
CVE-2026-69255 | FlowiseAI Flowise up to 3.1.2 CSVAgent CSVAgent.ts validatePythonCodeForDataFrame os command injection
A vulnerability, which was classified as very critical, has been found in FlowiseAI Flowise up to 3.1.2. Affected by this vulnerability is the function validatePythonCodeForDataFrame of the file packages/components/nodes/agents/CSVAgent/CSV
CVE-2023-5685 | xnio NotifierState stack-based overflow (EUVD-2024-0858 / Nessus ID 211909)
A vulnerability was found in xnio and classified as critical. The impacted element is an unknown function of the component NotifierState. Such manipulation leads to stack-based buffer overflow. This vulnerability is uniquely identified as C
CVE-2026-69254 | FlowiseAI Flowise up to 3.1.2 JavaScript Code Execution utils.ts executeJavaScriptCode nodeVMOptions command injection
A vulnerability labeled as very critical has been found in FlowiseAI Flowise up to 3.1.2. This vulnerability affects the function executeJavaScriptCode of the file packages/components/src/utils.ts of the component JavaScript Code Execution.
CVE-2026-69253 | FlowiseAI Flowise up to 3.1.2 AgentAsTool/ChatflowTool/ExecuteFlow isValidURL baseURL code injection
A vulnerability identified as critical has been detected in FlowiseAI Flowise up to 3.1.2. This affects the function isValidURL of the component AgentAsTool/ChatflowTool/ExecuteFlow. This manipulation of the argument baseURL causes code inj
CVE-2026-69252 | FlowiseAI Flowise up to 3.1.2 File Management /api/v1/files getAllFiles/deleteFile path permission
A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been rated as critical. Affected by this vulnerability is the function getAllFiles/deleteFile of the file /api/v1/files of the component File Management. The manipulation of
CVE-2026-69250 | FlowiseAI Flowise up to 3.1.2 OAuth2 Token Refresh Endpoint server-side request forgery
A vulnerability, which was classified as critical, has been found in FlowiseAI Flowise up to 3.1.2. Impacted is an unknown function of the component OAuth2 Token Refresh Endpoint. The manipulation leads to server-side request forgery. This
CVE-2026-69251 | FlowiseAI Flowise/Flowise Components up to 3.1.2 Record Manager/Agent Memory MySQLrecordManager.ts additionalConfig code injection
A vulnerability, which was classified as critical, was found in FlowiseAI Flowise and Flowise Components up to 3.1.2. The affected element is an unknown function of the file packages/components/nodes/recordmanager/MySQLRecordManager/MySQLre
CVE-2026-63769 | Huginn up to 2022.08.18 ScenarioImport fetch_url server-side request forgery
A vulnerability has been found in Huginn up to 2022.08.18 and classified as problematic. Affected by this issue is the function fetch_url of the component ScenarioImport. Performing a manipulation results in server-side request forgery. Thi
<b>Windows</b> 11 Notfall-Patch: Update fixt Remote-Desktop-Fehler und mehr - WinFuture.de
Das führte dazu, dass RDP-Verbindungen abbrachen und Server während der Konfiguration nicht mehr reagierten. Das Notfall-Update sollte das fehlerhafte ... Weiterlesen
CVE-2026-90562 | langbot-app LangBot up to 4.10.10 Password Recovery entropy (CNNVD-2026-91948344)
A vulnerability classified as problematic was found in langbot-app LangBot up to 4.10.10. Affected is an unknown function of the component Password Recovery. Executing a manipulation can lead to insufficient entropy. This vulnerability is r
CVE-2020-15875 | LibreNMS up to 1.65.0 API Endpoint ajax_table.php searchPhrase sql injection (CNNVD-2026-92850483)
A vulnerability was found in LibreNMS up to 1.65.0. It has been declared as critical. This vulnerability affects unknown code of the file ajax_table.php of the component API Endpoint. Executing a manipulation of the argument searchPhrase ca
CVE-2026-79379 | Bestechnic BES2300 Bluetooth Audio SoC firmware up to 4.x SBC_DecodeFrames buffer overflow
A vulnerability has been found in Bestechnic BES2300 Bluetooth Audio SoC firmware up to 4.x and classified as critical. Affected by this issue is the function SBC_DecodeFrames. This manipulation causes buffer overflow. The identification of
CVE-2026-69263 | FlowiseAI Flowise up to 3.1.2 MCP Server core.ts os command injection
A vulnerability classified as critical has been found in FlowiseAI Flowise up to 3.1.2. This issue affects some unknown processing of the file packages/components/nodes/tools/MCP/core.ts of the component MCP Server. The manipulation leads t
CVE-2026-78971 | Halo up to 2.25.4 Plugin Management os command injection
A vulnerability was found in Halo up to 2.25.4. It has been classified as problematic. This affects an unknown function of the component Plugin Management. This manipulation causes os command injection. This vulnerability appears as CVE-202
CVE-2026-28659 | Google Android XR 14 Blobstore permission
A vulnerability described as problematic has been identified in Google Android XR 14. This affects an unknown function of the component Blobstore. Executing a manipulation can lead to permission issues. This vulnerability is tracked as CVE-
CVE-2026-49883 | Google Android 14/16/17 Permission Check PermissionsManager.java checkReadPermission permission
A vulnerability labeled as problematic has been found in Google Android 14/16/17. Impacted is the function checkReadPermission of the file PermissionsManager.java of the component Permission Check. The manipulation results in permission iss
CVE-2026-52307 | ClassCMS 5.6 Column Management Title cross site scripting
A vulnerability, which was classified as problematic, was found in ClassCMS 5.6. This affects an unknown part of the component Column Management. Executing a manipulation of the argument Title can lead to cross site scripting. This vulnerab
CVE-2026-79573 | L-ONE 1.0.0 Attachment GetBusinessUploadList busid/id/taskid sql injection
A vulnerability classified as critical has been found in L-ONE 1.0.0. This impacts an unknown function of the component Attachment GetBusinessUploadList. The manipulation of the argument busid/id/taskid leads to sql injection. This vulnerab
CVE-2026-79577 | fangtang7 sso-master 1.0.0 Login /cas/login improper authentication
A vulnerability classified as critical has been found in fangtang7 sso-master 1.0.0. This vulnerability affects unknown code of the file /cas/login of the component Login. This manipulation causes improper authentication. This vulnerability
CVE-2026-34223 | Siemens Desigo CC ClickOnce Client code injection
A vulnerability labeled as problematic has been found in Siemens Desigo CC ClickOnce Client, Desigo CC Flex Client, Desigo CC Installed Client and Desigo CC. This impacts an unknown function. The manipulation results in code injection. This
CVE-2026-69264 | FlowiseAI Flowise up to 3.1.2 CSVAgent validatePythonCodeForDataFrame csvFile os command injection
A vulnerability has been found in FlowiseAI Flowise up to 3.1.2 and classified as critical. Affected by this vulnerability is the function validatePythonCodeForDataFrame of the component CSVAgent. The manipulation of the argument csvFile le
CVE-2026-70472 | FlowiseAI Flowise up to 3.1.2 openai-assistants-vector-store credential permission
A vulnerability categorized as critical has been discovered in FlowiseAI Flowise up to 3.1.2. Impacted is an unknown function of the component openai-assistants-vector-store. Executing a manipulation of the argument credential can lead to p
CVE-2026-70471 | FlowiseAI Flowise up to 3.1.2 Code Execution Sandbox utils.ts vars privileges management
A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been declared as critical. This vulnerability affects unknown code of the file packages/components/src/utils.ts of the component Code Execution Sandbox. Such manipulation of
CVE-2023-25500 | Vaadin Flow RPC Response information disclosure
A vulnerability classified as problematic has been found in Vaadin Flow. This vulnerability affects unknown code of the component RPC Response Handler. This manipulation causes information disclosure. This vulnerability is tracked as CVE-20
CVE-2022-29567 | Vaadin up to 14.8.9/22.0.14/23.0.8/23.1.0.alpha4 TreeGrid Object::toString information disclosure
A vulnerability, which was classified as problematic, has been found in Vaadin up to 14.8.9/22.0.14/23.0.8/23.1.0.alpha4. This impacts the function Object::toString of the component TreeGrid. Performing a manipulation results in information
CVE-2026-79389 | Trueview T18161 S 6.0.23.4 MQTT Command Processing authentication replay
A vulnerability has been found in Trueview T18161 S 6.0.23.4 and classified as critical. This vulnerability affects unknown code of the component MQTT Command Processing. Performing a manipulation results in authentication bypass by capture
CVE-2026-75439 | Free5GC 4.2.2 UPF denial of service
A vulnerability categorized as critical has been discovered in Free5GC 4.2.2. This affects an unknown function of the component UPF. Such manipulation leads to denial of service. This vulnerability is documented as CVE-2026-75439. The attac
CVE-2026-71620 | ApiAdmin 5.0.1 unrestricted upload
A vulnerability classified as critical has been found in ApiAdmin 5.0.1. The impacted element is an unknown function. Performing a manipulation results in unrestricted upload. This vulnerability was named CVE-2026-71620. The attack may be i
CVE-2026-78849 | Netgate pfSense CE/pfSense Plus captive_portal_status.widget.php cross site scripting
A vulnerability was found in Netgate pfSense CE and pfSense Plus and classified as problematic. Impacted is an unknown function of the file captive_portal_status.widget.php. Such manipulation leads to cross site scripting. This vulnerabilit
CVE-2026-33967 | Samsung Exynos Camera Driver out-of-bounds (EUVD-2026-77172)
A vulnerability was found in Samsung Exynos. It has been rated as critical. Impacted is an unknown function of the component Camera Driver. This manipulation causes out-of-bounds read. This vulnerability is registered as CVE-2026-33967. The
CVE-2026-33960 | Samsung Exynos Wi-Fi Interface ioctl out-of-bounds write (EUVD-2026-77161)
A vulnerability has been found in Samsung Exynos and classified as critical. Affected by this issue is the function ioctl of the component Wi-Fi Interface. Performing a manipulation results in out-of-bounds write. This vulnerability is iden
CVE-2026-23792 | Samsung Exynos NR RRC input validation (EUVD-2026-77156)
A vulnerability marked as critical has been reported in Samsung Exynos. The affected element is an unknown function of the component NR RRC. Performing a manipulation results in improper input validation. This vulnerability is known as CVE-
CVE-2026-90602 | Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0 Studio Components ImageStudio.js renderHistory cross site scripting (Issue 309 / EUVD-2026-77131)
A vulnerability marked as problematic has been reported in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This m
CVE-2026-57579 | AlchemyCMS Alchemy CMS up to 7.4.14/8.0.14/8.1.13/8.2.5 PageTreeSerializer pages_controller.rb PagesController#nested elements improper authorization (EUVD-2026-77637)
A vulnerability labeled as problematic has been found in AlchemyCMS Alchemy CMS up to 7.4.14/8.0.14/8.1.13/8.2.5. This issue affects the function Api::PagesController#nested of the file app/controllers/alchemy/api/pages_controller.rb of the
CVE-2026-23787 | Samsung Exynos Exynos DRM HDR driver use after free (EUVD-2026-77143)
A vulnerability has been found in Samsung Exynos and classified as problematic. This impacts an unknown function of the component Exynos DRM HDR driver. This manipulation causes use after free. This vulnerability is tracked as CVE-2026-2378
CVE-2026-90597 | itsourcecode Sales and Inventory System 1.0 /pages/sup_edit1.php ID sql injection (EUVD-2026-77127)
A vulnerability was found in itsourcecode Sales and Inventory System 1.0. It has been declared as critical. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql inje
CVE-2026-71807 | RuoYi-Cloud-Plus up to 2.6.2 ruoyi-workflow module FlwTaskController taskId privileges management (EUVD-2026-75208)
A vulnerability classified as critical has been found in RuoYi-Cloud-Plus up to 2.6.2. Affected by this issue is some unknown functionality of the file FlwTaskController of the component ruoyi-workflow module. The manipulation of the argume
CVE-2026-71802 | REBUILD 4.4.3 Announcement Preview html/text cross site scripting (EUVD-2026-75161)
A vulnerability was found in REBUILD 4.4.3 and classified as problematic. This vulnerability affects the function html/text of the component Announcement Preview. Such manipulation leads to cross site scripting. This vulnerability is listed
CVE-2026-77827 | Maono Link up to 4.0.79 C:\ProgramData\Maono privileges management (EUVD-2026-74191)
A vulnerability categorized as problematic has been discovered in Maono Link up to 4.0.79. This impacts an unknown function of the file C:\ProgramData\Maono. Executing a manipulation can lead to improper privilege management. This vulnerabi
CVE-2026-90804 | GNU Binutils 2.47 Eh Frame Section bfd/elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflow (Bug 34445 / EUVD-2026-77642)
A vulnerability was found in GNU Binutils 2.47. It has been rated as problematic. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a
CVE-2026-90584 | TooTallNate Java-WebSocket up to 1.6.1 Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resources (Issue 1508 / EUVD-2026-77090)
A vulnerability labeled as problematic has been found in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Execut
CVE-2026-89514 | Linux Kernel up to 6.18.50/7.2.3 fnic fnic_fcoe_process_vlan_resp deadlock (Nessus ID 345332)
A vulnerability classified as critical was found in Linux Kernel up to 6.18.50/7.2.3. This impacts the function fnic_fcoe_process_vlan_resp of the component fnic. The manipulation results in deadlock. This vulnerability is identified as CVE
CVE-2026-89616 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NTFS3 fs/ntfs3 ni_read_frame uninitialized pointer (Nessus ID 345333)
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This issue affects the function ni_read_frame of the file fs/ntfs3 of the component NTFS3. The manipulation results in uninitialized pointer.
CVE-2026-80981 | Linux Kernel up to 6.18.49/7.2.3 net/smc smc_llc.c smc_llc_srv_add_link use after free (Nessus ID 345334)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.49/7.2.3. This affects the function smc_llc_srv_add_link of the file smc_llc.c of the component net/smc. The manipulation leads to use after f
CVE-2026-89606 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ecryptfs ecryptfs_parse_tag_70_packet buffer overflow (Nessus ID 345336)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. Impacted is the function ecryptfs_parse_tag_70_packet of the component ecryptfs. This manipulation causes buffer overflow. This vuln
CVE-2026-89713 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NFSD nfsd_setattr toctou (Nessus ID 345335)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been declared as problematic. This vulnerability affects the function nfsd_setattr of the component NFSD. Such manipulation leads to time-of-check time-of-use. T
CVE-2026-89615 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ntfs3 fs/ntfs3 check_dp_table memory corruption (Nessus ID 345338)
A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected is the function check_dp_table of the file fs/ntfs3 of the component ntfs3. The manipulation results in memory corruption.
CVE-2026-89590 | Linux Kernel up to 6.18.49/7.2.3 accel rocket drivers/staging/rocket.c rocket_job_run release of resource (Nessus ID 345337)
A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. Impacted is the function rocket_job_run of the file drivers/staging/rocket.c of the component accel rocket. Performing a manipulation results in
CVE-2026-89589 | Linux Kernel up to 6.18.49/7.2.3 CXL CPER Work Locks /apei/ghes cxl_cper_post_event deadlock (Nessus ID 345339)
A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been classified as problematic. The affected element is the function cxl_cper_post_event of the file /apei/ghes of the component CXL CPER Work Locks. This manipulation ca
CVE-2026-75171 | HubCore 14.1.1 HUBCOREID session cookie handling privileges management
A vulnerability, which was classified as critical, has been found in HubCore 14.1.1. The affected element is an unknown function of the component HUBCOREID session cookie handling. The manipulation leads to improper privilege management. Th
CVE-2021-36081 | Tesseract OCS 5.0.0-alpha-20201231 Call one_ell_conflict use after free
A vulnerability identified as critical has been detected in Tesseract OCS 5.0.0-alpha-20201231. The affected element is the function one_ell_conflict of the component Call Handler. This manipulation causes use after free. This vulnerability
CVE-2022-38266 | Leptonica 1.79.0 JPEG File denial of service (Issue 3498)
A vulnerability described as problematic has been identified in Leptonica 1.79.0. Affected is an unknown function of the component JPEG File Handler. Such manipulation leads to denial of service. This vulnerability is uniquely identified as
CVE-2026-75167 | MBS-Solutions Firmware V6_00_05 /cgi-bin/wwwugw.cgi ugw-usr-edit access control
A vulnerability described as very critical has been identified in MBS-Solutions Firmware V6_00_05. This vulnerability affects the function ugw-usr-edit of the file /cgi-bin/wwwugw.cgi. Such manipulation leads to improper access controls. Th
CVE-2026-75429 | PowerJob up to 5.1.2 Transport Layer /friend/process privileges management
A vulnerability described as critical has been identified in PowerJob up to 5.1.2. The impacted element is an unknown function of the file /friend/process of the component Transport Layer. Such manipulation leads to improper privilege manag
CVE-2022-35497 | Trimble TM4WEB 21.4.0.4 External Document Viewer Endpoint cross site scripting
A vulnerability has been found in Trimble TM4WEB 21.4.0.4 and classified as problematic. This vulnerability affects unknown code of the component External Document Viewer Endpoint. This manipulation causes cross site scripting. This vulnera
CVE-2026-25470 | ACPT Custom Post Types Plugin up to 2.0.47 on WordPress code injection
A vulnerability was found in ACPT Custom Post Types Plugin up to 2.0.47 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to code injection. This vulnerabi
CVE-2022-42917 | FRRouting up to 4.4 /etc/frr toctou (WID-SEC-2026-3339)
A vulnerability classified as problematic was found in FRRouting up to 4.4. The affected element is an unknown function of the file /etc/frr. Executing a manipulation can lead to time-of-check time-of-use. The identification of this vulnera
CVE-2026-18495 | Red Hat libtiff tiff2pdf buffer overflow (WID-SEC-2026-3338)
A vulnerability marked as critical has been reported in Red Hat libtiff. This issue affects some unknown processing of the component tiff2pdf. Performing a manipulation results in buffer overflow. This vulnerability was named CVE-2026-18495
CVE-2025-64031 | libarchive up to 3.8.1 gzip writer archive_write_add_filter_gzip.c archive_compressor_gzip_open original-filename buffer overflow (WID-SEC-2026-3340)
A vulnerability was found in libarchive up to 3.8.1. It has been declared as problematic. Affected by this issue is the function archive_compressor_gzip_open of the file archive_write_add_filter_gzip.c of the component gzip writer. Executin