CVE-2013-7372: Schwachstellen-Eintrag (NVD)
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Architecture (JCA) in Android before 4.4 and other products, when no seed is provided by the user, uses an incorrect offset value, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging the resulting PRNG predictability, as exploited in the wild against Bitcoin wallet applications in August 2013.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-13 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Klimaanlage: Sicherheitslücke in Midea Portasplit wird geschlossen
Angreifer können die Klimaanlage Midea Portasplit ohne Anmeldung per Bluetooth steuern. Ein neues Firmware-Update korrigiert das. (Sicherheitslücke, Bluetooth) Weiterlesen
CVE-2026-87468 | Google Chrome up to 152.0.7977.82 Site Isolation improper authorization
A vulnerability labeled as critical has been found in Google Chrome. This impacts an unknown function of the component Site Isolation. The manipulation results in improper authorization. This vulnerability is cataloged as CVE-2026-87468. Th
CVE-2026-87493 | Google Chrome up to 152.0.7977.82 FileSystem authorization
A vulnerability was found in Google Chrome. It has been classified as critical. Impacted is an unknown function of the component FileSystem. Performing a manipulation results in missing authorization. This vulnerability is known as CVE-2026
CVE-2026-86808 | moltis-org moltis up to 20260818.10 vault.rs vault_unlock_handler/vault_recovery_handler missing authentication (Issue 1177)
A vulnerability classified as critical was found in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authenticatio
CVE-2026-86083 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 Legacy Expression Engine isolated-vm-bridge.ts JSON.stringify code injection
A vulnerability was found in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. It has been declared as problematic. Impacted is the function JSON.stringify of the file @n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts of the component Legacy
CVE-2026-86079 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 Elasticsearch Nodes GenericFunctions.ts path traversal (WID-SEC-2026-3165)
A vulnerability described as critical has been identified in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. The affected element is an unknown function of the file packages/nodes-base/nodes/Elastic/Elasticsearch/GenericFunctions.ts of the compone
CVE-2026-86082 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 OpenAI Chat Model Node loadModels.ts assertOpenAiCredentialAllowsUrl baseURL access control
A vulnerability marked as problematic has been reported in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. Impacted is the function assertOpenAiCredentialAllowsUrl of the file packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModel
CVE-2026-86080 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 GitHub Trigger GithubTriggerHelpers.ts improper authentication
A vulnerability identified as critical has been detected in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. This vulnerability affects unknown code of the file packages/nodes-base/nodes/Github/GithubTriggerHelpers.ts of the component GitHub Trigge
CVE-2026-73313 | XenForo up to 2.3.12 Passkey TFA Provider improper authentication
A vulnerability identified as critical has been detected in XenForo up to 2.3.12. This issue affects some unknown processing of the component Passkey TFA Provider. The manipulation leads to improper authentication. This vulnerability is doc
CVE-2026-9215 | NETGEAR XR1000/XR1000v2/XR500 cross-site request forgery (EUVD-2026-73163)
A vulnerability classified as problematic has been found in NETGEAR XR1000, XR1000v2 and XR500. This vulnerability affects unknown code. Performing a manipulation results in cross-site request forgery. This vulnerability is reported as CVE-
CVE-2026-86672 | ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf Backup example.7z information disclosure (Issue 14)
A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. It has been classified as problematic. Affected is an unknown function of the file example.7z of the component Backup Handler.
CVE-2026-86674 | ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf login.php session_start session fixiation (Issue 16)
A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. It has been declared as critical. Affected by this vulnerability is the function session_start of the file login.php. The mani
CVE-2026-86668 | aircheng-org iWebShop-5 up to 5.15 controllers/pic.php uploadFile outerSrc/selectPhoto cross site scripting
A vulnerability, which was classified as problematic, was found in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto l
CVE-2026-9216 | NETGEAR RAX30/RAX35/RAX38/RAX40/RAXE300 Management UI stack-based overflow
A vulnerability has been found in NETGEAR RAX30, RAX35, RAX38, RAX40 and RAXE300 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Management UI. This manipulation causes stack-based buf
CVE-2026-28606 | Google Android 15/16/16-qpr2/17 Pairing AdapterService.java handleBondStateChanged privileges management
A vulnerability, which was classified as very critical, has been found in Google Android 15/16/16-qpr2/17. This vulnerability affects the function handleBondStateChanged of the file AdapterService.java of the component Pairing. The manipula
CVE-2026-86074 | n8n-io n8n up to 2.37.6/2.38.1 Instance AI Credential Setup credential-utils.ts redirect (WID-SEC-2026-3165)
A vulnerability was found in n8n-io n8n up to 2.37.6/2.38.1. It has been classified as problematic. Affected is an unknown function of the file packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts of the component Instance AI C
CVE-2026-86073 | n8n-io n8n up to 2.37.6/2.38.0 OAuth Token Endpoint improper authorization
A vulnerability was found in n8n-io n8n up to 2.37.6/2.38.0. It has been classified as problematic. Impacted is an unknown function of the component OAuth Token Endpoint. This manipulation causes improper authorization. This vulnerability a
CVE-2026-73310 | XenForo up to 2.3.12 OAuth2 Token Endpoint improper authorization
A vulnerability was found in XenForo up to 2.3.12 and classified as problematic. Affected is an unknown function of the component OAuth2 Token Endpoint. The manipulation results in improper authorization. This vulnerability is identified as
CVE-2026-73309 | XenForo up to 2.3.12 OAuth2 Token Endpoint client_secret/code_verifier improper authorization
A vulnerability, which was classified as critical, was found in XenForo up to 2.3.12. This affects an unknown function of the component OAuth2 Token Endpoint. Executing a manipulation of the argument client_secret/code_verifier can lead to
CVE-2026-86804 | seakee CPA-Manager-Plus up to 1.11.10 HTTP handler.go CPAResource improper authorization
A vulnerability marked as problematic has been reported in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component
CVE-2026-80958 | Linux Kernel up to 6.18.49/7.2.3 dm-pcache cache_replay out-of-bounds
A vulnerability described as problematic has been identified in Linux Kernel up to 6.18.49/7.2.3. This vulnerability affects the function cache_replay of the component dm-pcache. Such manipulation leads to out-of-bounds read. This vulnerabi
CVE-2026-80954 | Linux Kernel up to 7.2.3 i3c i3c_device_get_supported_xfer_mode null pointer dereference
A vulnerability described as very critical has been identified in Linux Kernel up to 7.2.3. Affected by this vulnerability is the function i3c_device_get_supported_xfer_mode of the component i3c. The manipulation results in null pointer der
CVE-2026-80953 | Linux Kernel up to 6.18.49/7.2.3 i3c adi_i3c_master_probe race condition (Nessus ID 345376)
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.49/7.2.3. Affected is the function adi_i3c_master_probe of the component i3c. The manipulation leads to race condition. This vulnerability is referenced as
CVE-2026-80950 | Linux Kernel up to 6.18.49/7.2.3 I3C Driver use after free
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.49/7.2.3. This affects an unknown function of the component I3C Driver. Performing a manipulation results in use after free. This vulnerability was nam
CVE-2026-80945 | Linux Kernel up to 6.18.50/7.2.3 iaa iaa_comp_adecompress buffer overflow
A vulnerability was found in Linux Kernel up to 6.18.50/7.2.3. It has been declared as very critical. Impacted is the function iaa_comp_adecompress of the component iaa. The manipulation results in buffer overflow. This vulnerability is kno
CVE-2026-80943 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 rtlwifi rtl92du_tx_fill_desc tids out-of-bounds
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. This vulnerability affects the function rtl92du_tx_fill_desc of the component rtlwifi. Executing a manipulation of the argument tids can lead
CVE-2026-80937 | Linux Kernel up to 6.18.49/7.2.3 mt7915 mt7915_mcu_get_eeprom addr out-of-bounds write
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.49/7.2.3. This issue affects the function mt7915_mcu_get_eeprom of the component mt7915. This manipulation of the argument addr causes out-of-bounds write.
CVE-2026-80952 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 i3c i3c_master_unregister_i3c_devs information disclosure
A vulnerability described as problematic has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function i3c_master_unregister_i3c_devs of the component i3c. Executing a manipulation can lead to information discl
CVE-2026-80955 | Linux Kernel up to 6.18.49/7.2.3 dm-pcache kset_replay seg_gen use after free
A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. This impacts the function kset_replay of the component dm-pcache. The manipulation of the argument seg_gen leads to use after free. This vulnera
CVE-2026-80947 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 rtl8xxxu rtl8xxxu_rx_urb_work use after free
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Impacted is the function rtl8xxxu_rx_urb_work of the component rtl8xxxu. This manipulation causes use after free. The identification
USN-8750-1: FFmpeg vulnerabilities
Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-12706) Xingha
USN-8750-1: FFmpeg vulnerabilities
Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-12706) Xingha
CVE-2026-80980 | Linux Kernel up to 6.18.49/7.2.3 SMC Connection smc_cdc_msg_validate race condition (Nessus ID 345372)
A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. This affects the function smc_cdc_msg_validate of the component SMC Connection. Such manipulation leads to race condition. This vulnerability is tr
CVE-2026-89629 | Linux Kernel up to 6.18.49/7.2.3 HID/corsair-void out-of-bounds (Nessus ID 345373)
A vulnerability classified as problematic has been found in Linux Kernel up to 6.18.49/7.2.3. Affected by this issue is some unknown functionality of the component HID/corsair-void. Performing a manipulation results in out-of-bounds read. T
CVE-2026-89542 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SUNRPC gss_krb5_unwrap_v2 out-of-bounds (Nessus ID 345375)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function gss_krb5_unwrap_v2 of the component SUNRPC. Executing a manipulation can lead to out-of-bounds read. Th
CVE-2026-89651 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Ceph handle_session out-of-bounds (Nessus ID 345379)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The impacted element is the function handle_session of the component Ceph. The manipulation leads to out-of-bounds read. This vulnerability i
CVE-2026-89665 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NFSv2 Decoder fs/nfs/nfs2xdr.c svcxdr_decode_sattr useconds integer overflow (Nessus ID 345378)
A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Impacted is the function svcxdr_decode_sattr of the file fs/nfs/nfs2xdr.c of the component NFSv2 Decoder. Executing a manipulation
CVE-2026-89585 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 charlcd charlcd.c charlcd_init use after free (Nessus ID 345377)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. Impacted is the function charlcd_init of the file charlcd.c of the component charlcd. Performing a manipulation results in use after
CVE-2026-80997 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 IPA Modem TX Queue ipa_start_xmit race condition (Nessus ID 345381)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function ipa_start_xmit of the component IPA Modem TX Queue. This manipulation causes race condition. This vuln
CVE-2026-89732 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 f_fs ffs_ep0_read locking (Nessus ID 345380)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. The impacted element is the function ffs_ep0_read of the component f_fs. The manipulation leads to improper locking. This vulnerability i
CVE-2026-80991 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ravb ravb_ptp_interrupt use after free (Nessus ID 345383)
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This issue affects the function ravb_ptp_interrupt of the component ravb. This manipulation causes use after free. The identificati
CVE-2026-89266 | nothings stb_vorbis up to 1.22 start_decoder heap-based overflow (Nessus ID 345382)
A vulnerability has been found in nothings stb_vorbis up to 1.22 and classified as critical. Affected by this issue is the function start_decoder. Performing a manipulation results in heap-based buffer overflow. This vulnerability is catalo
CVE-2026-80932 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Vsock Virtio virtio_vsock_remove use after free
A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This vulnerability affects the function virtio_vsock_remove of the component Vsock Virtio. This manipulation causes use after free. Thi
CVE-2026-80936 | Linux Kernel up to 6.18.49/7.2.3 mt7925 kernel/workqueue.c mt792x_stop use after free
A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. This vulnerability affects the function mt792x_stop of the file kernel/workqueue.c of the component mt7925. The manipulation results in use after f
CVE-2026-80933 | Linux Kernel up to 6.18.49/7.2.3 mt7996 buffer overflow
A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been rated as very critical. Affected by this vulnerability is an unknown functionality of the component mt7996. Performing a manipulation results in buffer overflow. Thi
CVE-2026-80931 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 w1 w1_f19_i2c_master_transfer buffer overflow
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been declared as very critical. Affected is the function w1_f19_i2c_master_transfer of the component w1. Such manipulation leads to buffer overflow. This vulnera
CVE-2026-80928 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 smack smack_file_send_sigiotask use after free
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This affects the function smack_file_send_sigiotask of the component smack. The manipulation results in use after free. This vulnerabili
CVE-2026-80929 | Linux Kernel up to 6.18.49/7.2.3 sysctl pid_table_root_permissions privileges management
A vulnerability described as very critical has been identified in Linux Kernel up to 6.18.49/7.2.3. This affects the function pid_table_root_permissions of the component sysctl. The manipulation results in improper privilege management. Thi
CVE-2026-79742 | IBM Langflow OSS up to 1.11.5 code injection
A vulnerability has been found in IBM Langflow OSS up to 1.11.5 and classified as critical. This vulnerability affects unknown code. The manipulation leads to code injection. This vulnerability is documented as CVE-2026-79742. The attack ca
CVE-2026-80926 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 ksmbd smb2_oplock_break_noti use after free
A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This issue affects the function smb2_oplock_break_noti of the component ksmbd. The manipulation leads to use after free. This vulnerabil
CVE-2026-52295 | FFmpeg 7.0 libavformat-iamf_writer.c buffer overflow
A vulnerability was found in FFmpeg 7.0. It has been classified as problematic. Impacted is an unknown function of the file libavformat/iamf_writer.c of the component libavformat-iamf_writer.c. The manipulation leads to buffer overflow. Thi
CVE-2026-89610 | Linux Kernel NTFS memory corruption (Nessus ID 345384)
A vulnerability identified as very critical has been detected in Linux Kernel. The impacted element is an unknown function of the component NTFS. Performing a manipulation results in memory corruption. This vulnerability is known as CVE-202
CVE-2026-79515 | Nothings stb stbtt_GetGlyphShape out-of-bounds (31c1ad3 / Nessus ID 345385)
A vulnerability classified as problematic has been found in Nothings stb. This impacts the function stbtt_GetGlyphShape. Performing a manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-79515. The attack may be
CVE-2026-89734 | Linux Kernel up to 6.18.49/7.2.3 UVC uvcg_video_init null pointer dereference (Nessus ID 345386)
A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. Impacted is the function uvcg_video_init of the component UVC. This manipulation causes null pointer dereference. This vulnerability appears as
CVE-2026-89473 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 bq25890 bq25890_fw_probe denial of service (Nessus ID 345387)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. Affected by this issue is the function bq25890_fw_probe of the component bq25890. Such manipulation leads to denial of service. This vulnerab
CVE-2019-9494 | hostapd/wpa_supplicant up to 2.7 SAE information disclosure (SA_19_16 / Nessus ID 345520)
A vulnerability identified as problematic has been detected in hostapd and wpa_supplicant up to 2.7. This affects an unknown function of the component SAE. This manipulation causes information disclosure. This vulnerability is handled as CV
USN-8749-1: CivetWeb vulnerabilities
It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.0
USN-8749-1: CivetWeb vulnerabilities
It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.0
Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity
... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen
DSA-6496-1 nginx - security update
Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code. CVE-2026-42533 A heap buffer overfl