🎯 CVE-2009-4758
📄 .md Alle CVEs anzeigen ✕

CVE-2009-4758: Schwachstellen-Eintrag (NVD)

Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .YUV file.

Klassifikation & Betroffenheit:
dicas mpegable_player 2.12
Improper Restriction of Operations within the Bounds of a Memory Buffer 🎯 High

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

🛡️ Empfohlene Mitigation: Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, many languages that perform their own memory management, such as Java and Perl, are not subject to buffer overflows. Other languages, such as Ada and C#, typically provide overflow prot…
Vollständige Definition bei MITRE ➔
🧪 Exploit-Evidenz: EDB-8568 · mpegable Player 2.12 - '.yuv' Local Stack Overflow (PoC) verified
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
Veröffentlicht:29.03.2010
Aktualisiert:16.06.2026 23:14
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
22 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 123 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.886 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-16
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

[UPDATE] [hoch] Apache Airflow: Schwachstelle ermöglicht Erlangen von Benutzerrechten

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Airflow ausnutzen, um Benutzerrechte zu erlangen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] IBM Java SDK: Schwachstelle ermöglicht Denial of Service

Ein Angreifer kann eine Schwachstelle in IBM Java SDK ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] vllm: Schwachstelle ermöglicht Denial of Service

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in vllm ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] Keycloak: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-75808 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75808 | ASUS Armoury Crate up to 6.5.7 allocation of resources (EUVD-2026-72620)

A vulnerability classified as problematic was found in ASUS Armoury Crate up to 6.5.7. The impacted element is an unknown function. The manipulation results in allocation of resources. This vulnerability is cataloged as CVE-2026-75808. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-19397 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19397 | ASUS Control Center Express Agent up to 1.7.23 missing authentication (EUVD-2026-72612)

A vulnerability described as critical has been identified in ASUS Control Center Express Agent up to 1.7.23. Impacted is an unknown function. Executing a manipulation can lead to missing authentication. This vulnerability is tracked as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-75754 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75754 | ASUS Control Center Enterprise up to 4.0.0.2 missing authentication (EUVD-2026-70865)

A vulnerability classified as very critical has been found in ASUS Control Center Enterprise up to 4.0.0.2. Affected by this issue is some unknown functionality. The manipulation leads to missing authentication. This vulnerability is listed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.5%
CVE-2026-75810 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75810 | ASUS Armoury Crate up to 6.5.7 denial of service (EUVD-2026-72618)

A vulnerability was found in ASUS Armoury Crate up to 6.5.7. It has been rated as problematic. This vulnerability affects unknown code. This manipulation causes denial of service. This vulnerability is handled as CVE-2026-75810. It is possi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-75809 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75809 | ASUS Armoury Crate up to 6.5.7 IOCTL access control (EUVD-2026-72619)

A vulnerability has been found in ASUS Armoury Crate up to 6.5.7 and classified as very critical. Affected is an unknown function of the component IOCTL. Performing a manipulation results in improper access controls. This vulnerability is r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-78428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78428 | NeuVector prior 5.6.1 SSO Login improper authentication (EUVD-2026-81412)

A vulnerability, which was classified as very critical, has been found in NeuVector prior 5.6.1. Affected by this vulnerability is an unknown functionality of the component SSO Login. This manipulation causes improper authentication. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.7%
CVE-2026-75811 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75811 | ASUS Armoury Crate up to 6.5.7 access control (EUVD-2026-72616)

A vulnerability categorized as problematic has been discovered in ASUS Armoury Crate up to 6.5.7. This issue affects some unknown processing. Such manipulation leads to improper access controls. This vulnerability is uniquely identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
10.0 CRITICAL
EPSS 94.4%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco warnt vor Zero-Day in ISE: Authentifizierung lässt sich umgehen (CVE-2026-76460)

LONDON (IT BOLTWISE) – Cisco meldet einen Zero-Day mit maximaler Kritikalität in Identity Services Engine (ISE), der bereits aktiv ausgenutzt wird. Unter der Kennung CVE-2026-76460 (CVSS 10.0) kann ein Angreifer ohne gültige Anmeldung die A

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 32.3%
CVE-2026-50610 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50610 | Acer NitroSense/PredatorSense System Monitoring privileges management (EUVD-2026-81402)

A vulnerability classified as problematic was found in Acer NitroSense and PredatorSense. Affected is an unknown function of the component System Monitoring. The manipulation results in improper privilege management. This vulnerability is k

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2026-50607 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50607 | Acer NitroSense/PredatorSense up to 1.0.19.2 System Monitoring access control (EUVD-2026-81398)

A vulnerability was found in Acer NitroSense and PredatorSense up to 1.0.19.2. It has been classified as critical. Affected by this issue is some unknown functionality of the component System Monitoring. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-86320 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86320 | Red Hat flatpak-builder Hooks os command injection (EUVD-2026-81387)

A vulnerability, which was classified as problematic, was found in Red Hat flatpak-builder. This impacts an unknown function of the component Hooks. The manipulation results in os command injection. This vulnerability was named CVE-2026-863

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.2%
CVE-2026-1880 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-1880 | ASUS DriverHub prior 1.0.6.12 toctou (EUVD-2026-23155)

A vulnerability described as critical has been identified in ASUS DriverHub. This vulnerability affects unknown code. Such manipulation leads to time-of-check time-of-use. This vulnerability is documented as CVE-2026-1880. The attack needs

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS 94.4%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Access

Cisco has released security updates for a critical authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that attackers are actively exploiting in the wild. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 30.4%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 22.6%
CVE-2026-85596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85596 | Traefik Labs up to 3.7.10 Kubernetes Ingress NGINX Provider improper authentication

A vulnerability classified as critical has been found in Traefik Labs Traefik up to 3.7.10. Affected by this vulnerability is an unknown functionality of the component Kubernetes Ingress NGINX Provider. This manipulation causes improper aut

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-81205 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81205 | Drupal LDAP Active Directory Integration up to 2.2.0 ldap injection

A vulnerability, which was classified as critical, was found in Drupal LDAP Active Directory Integration up to 2.2.0. Impacted is an unknown function. The manipulation results in ldap injection. This vulnerability is identified as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-85594 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85594 | Traefik Labs up to 3.7.12 Kubernetes Ingress Provider privileges management

A vulnerability has been found in Traefik Labs Traefik up to 3.7.12 and classified as problematic. Affected by this issue is some unknown functionality of the component Kubernetes Ingress Provider. Performing a manipulation results in impro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-85173 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85173 | n8n-io n8n up to 2.36.1 Insights API projectId improper authorization

A vulnerability marked as problematic has been reported in n8n-io n8n up to 2.36.1. This affects an unknown function of the component Insights API. This manipulation of the argument projectId causes improper authorization. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-85171 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85171 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Strapi/SeaTable/Mailcheck nodes missing encryption

A vulnerability, which was classified as problematic, was found in n8n-io n8n. Affected is an unknown function of the component Strapi/SeaTable/Mailcheck nodes. Executing a manipulation can lead to missing encryption of sensitive data. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.9%
CVE-2026-85172 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85172 | n8n-io n8n up to 2.34.0 Request Helper legacy request helper function uri/url server-side request forgery

A vulnerability identified as critical has been detected in n8n-io n8n up to 2.34.0. The affected element is the function legacy request helper function of the component Request Helper. The manipulation of the argument uri/url leads to serv

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-85168 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85168 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Git node command injection

A vulnerability classified as critical has been found in n8n-io n8n. The impacted element is an unknown function of the component Git node. This manipulation causes command injection. This vulnerability appears as CVE-2026-85168. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-15315 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Sicherheitslücke in der TP-Link-Tapo-C200-Kamera lässt Angreifer ins Haus spähen

Cybersicherheit Cybersicherheit TP-Link Tapo C200 IP-Kameras CVE-2026-15315 IoT-Schwachstelle Videoüberwachung. Inhaltsverzeichnis. 1.Was die ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-81165 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81165 | Drupal Blazy Module up to 3.0.18 improper authorization

A vulnerability was found in Drupal Blazy Module up to 3.0.18. It has been declared as problematic. This impacts an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability is registered as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-59318 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59318 | VMware Spring AI up to 1.0.9/1.1.8/2.0.0 Tool Call privileges management

A vulnerability, which was classified as critical, was found in VMware Spring AI up to 1.0.9/1.1.8/2.0.0. Impacted is an unknown function of the component Tool Call Handler. Executing a manipulation can lead to improper privilege management

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-73478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73478 | Drupal Diff Plugin up to 2.0.1/2.1.1 improper authorization (CNNVD-2026-98018514)

A vulnerability has been found in Drupal Diff Plugin up to 2.0.1/2.1.1 and classified as problematic. This impacts an unknown function. Performing a manipulation results in improper authorization. This vulnerability is identified as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2026-73477 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73477 | Drupal Quick Tabs Plugin up to 4.3.0 improper authorization

A vulnerability, which was classified as critical, was found in Drupal Quick Tabs Plugin up to 4.3.0. This affects an unknown function. Such manipulation leads to improper authorization. This vulnerability is referenced as CVE-2026-73477. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-81201 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81201 | Drupal Monster Menus up to 9.5.2 cross site scripting

A vulnerability described as problematic has been identified in Drupal Monster Menus up to 9.5.2. This issue affects some unknown processing. Executing a manipulation can lead to cross site scripting. This vulnerability is handled as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-81166 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81166 | Drupal Digital Signage Framework up to 2.6.1 access control

A vulnerability was found in Drupal Digital Signage Framework up to 2.6.1. It has been rated as critical. Affected is an unknown function. The manipulation leads to improper access controls. This vulnerability is documented as CVE-2026-8116

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2026-81159 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81159 | Drupal Commerce CyberSource Plugin up to 1.9.x excessive authentication

A vulnerability has been found in Drupal Commerce CyberSource Plugin up to 1.9.x and classified as problematic. The affected element is an unknown function. This manipulation causes improper restriction of excessive authentication attempts.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-56100 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-56100 | SpringBlade up to 3.5.0 Authentication Filter privileges management

A vulnerability classified as critical was found in SpringBlade up to 3.5.0. This vulnerability affects unknown code of the component Authentication Filter. Such manipulation leads to improper privilege management. This vulnerability is uni

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-59308 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59308 | Spring AI 2.0.0 Semantic Cache access control

A vulnerability has been found in Spring AI 2.0.0 and classified as critical. The affected element is an unknown function of the component Semantic Cache. The manipulation leads to improper access controls. This vulnerability is listed as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-90894 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs

A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed &quot;ParaShells,&quot; could let any local account on a Mac escalate to full root control of the host machine, according to researchers at JF

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Linux-Entwickler gibt auf: Geheime Sicherheitslücke gemeldet

Andy Nguyen beendet sein PS5-Linux-Projekt, nachdem KI-gestützte Modder eine geheim gehaltene Sicherheitslücke an Sony meldeten. Der Sicherheitsforscher Andy Nguyen, bekannt unter dem Namen TheFlow0, hat sein Projekt PS5 Linux nach eigenen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Update schnell installieren: Pixel-Sicherheitslücke wird bereits aktiv ausgenutzt

Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. weiterlesen auf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.1 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61591 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.4 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 djust-org

CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.1 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-61597 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 31.2%
CVE-2026-92599 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 hapijs

CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in

joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 26%
CVE-2026-92598 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92598 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addres

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 30.7%
CVE-2026-92597 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92597 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as [email protected](x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registr

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.0 MEDIUM
🇪🇺 EUVD
EPSS 4.5%
CVE-2026-92595 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 nodemailer

CVE-2026-92595 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key, callback)`. Because `shared.resolveContent()` normalizes the missing `options` argument to an empty object, the message-level flags copied into `mai

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 26.7%
CVE-2026-92596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92596 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a sing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 19.3%
CVE-2026-92594 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 craftcms

CVE-2026-92594 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding on

Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are ga

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 23.4%
CVE-2026-92593 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92593 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on a single element type can mint a token over attacker-controlled

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
🇪🇺 EUVD
EPSS 31.2%
CVE-2026-92591 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 craftcms

CVE-2026-92591 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action accepts a site name, serializes it through Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker who obtained

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 29%
CVE-2026-92592 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92592 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie vi

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.1 MEDIUM
🇪🇺 EUVD
EPSS 2.8%
CVE-2026-92590 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92590 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScr

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.3%
CVE-2026-92589 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92589 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.9 MEDIUM
🇪🇺 EUVD
EPSS 6.9%
CVE-2026-92588 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
🧪 n8n-io

CVE-2026-92588 | n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a project admin) could therefore reference files belonging to projects they have no access to and push a deletion of t

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.6%
CVE-2026-92587 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 n8n-io

CVE-2026-92587 | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical UR

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git wal

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4%
CVE-2026-92585 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 WWBN

CVE-2026-92585 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.php endpoint with APIName parameters.

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can sub

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 2.6%
CVE-2026-92586 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 WWBN

CVE-2026-92586 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests to the comment API endpoint with arbitrary video IDs to write comments on videos they cannot watch.

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 6.8%
CVE-2026-92584 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92584 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings verbatim) directly into the `app` column of the videos_statistics table without invoking the sanitizing setter setApp(); normalizeApp() only truncat

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's Us

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 32.5%
CVE-2026-92582 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92582 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are never validated and are read from $_REQUEST, so an attacker can supply them in the query string of a cross-site

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['b

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
🇪🇺 EUVD
EPSS 5.9%
CVE-2026-92583 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92583 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency.

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurre

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.5%
CVE-2026-92581 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 WWBN

CVE-2026-92581 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.