🎯 CVE-2017-12177
📄 .md Alle CVEs anzeigen ✕

CVE-2017-12177: Schwachstellen-Eintrag (NVD)

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

Klassifikation & Betroffenheit:
debian debian_linux 8.0debian debian_linux 9.0x.org x_server *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 b96e982e3a43513549636850186ff80a82190f64 (Commit)
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 9.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:24.01.2018
Aktualisiert:17.06.2026 01:02
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
3 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 94 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.857 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-302026-09-18
≥90 %00
≥50 %00
≥10 %00
<10 %300300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
EPSS 19%
CVE-2026-72708 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72708 | SPIP up to 4.4.17 Sitemap Endpoint ecrire/req/mysql.php spip_mysql_cite annee sql injection

A vulnerability, which was classified as critical, was found in SPIP up to 4.4.17. The affected element is the function spip_mysql_cite of the file ecrire/req/mysql.php of the component Sitemap Endpoint. The manipulation of the argument ann

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.1%
CVE-2026-90533 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90533 | FlowiseAI Flowise up to 3.1.3 /api/v1/organizationuser access control

A vulnerability marked as problematic has been reported in FlowiseAI Flowise up to 3.1.3. This affects an unknown part of the file /api/v1/organizationuser. This manipulation causes improper access controls. This vulnerability is handled as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5.4%
CVE-2026-90535 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90535 | FlowiseAI Flowise up to 3.1.3 Text To Speech Abort abort chatflowId/chatId denial of service

A vulnerability categorized as problematic has been discovered in FlowiseAI Flowise up to 3.1.3. Affected is an unknown function of the file /api/v1/text-to-speech/abort of the component Text To Speech Abort. Executing a manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.4%
CVE-2026-67211 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-67211 | Apache OpenNLP up to 3.0.0-M5 opennlp-spellcheck extension SymSpellModelSerializer.create unigramCount/bigramCount allocation of resources

A vulnerability, which was classified as problematic, has been found in Apache OpenNLP up to 3.0.0-M5. This affects the function SymSpellModelSerializer.create of the component opennlp-spellcheck extension. This manipulation of the argument

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 26.2%
CVE-2026-82617 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-82617 | Apache OpenNLP up to 2.5.11/3.0.0-M5 RegexNameFinder RegexNameFinderFactory.java RegexNameFinder.find String[] resource consumption

A vulnerability, which was classified as problematic, was found in Apache OpenNLP up to 2.5.11/3.0.0-M5. This impacts the function RegexNameFinder.find of the file RegexNameFinderFactory.java of the component RegexNameFinder. Such manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 26%
CVE-2026-90534 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90534 | FlowiseAI Flowise up to 3.1.3 Credential Resolution /api/v1/node-load-method getCredentialData nodeName permission

A vulnerability was found in FlowiseAI Flowise up to 3.1.3. It has been rated as critical. This impacts the function getCredentialData of the file /api/v1/node-load-method of the component Credential Resolution. Performing a manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.2%
CVE-2026-79035 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79035 | Zeta Marketing Platform 1.0 p.rfihub.com ca cross site scripting

A vulnerability has been found in Zeta Marketing Platform 1.0 and classified as problematic. The affected element is an unknown function of the component p.rfihub.com. Performing a manipulation of the argument ca results in cross site scrip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.7%
CVE-2026-89332 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89332 | AWS Kiro IDE up to 0.8.134 Kiro Powers redirect

A vulnerability identified as problematic has been detected in AWS Kiro IDE up to 0.8.134. Affected by this vulnerability is an unknown functionality of the component Kiro Powers. This manipulation causes open redirect. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30%
CVE-2026-81910 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81910 | Concrete CMS up to 9.5.2 Theme Customizer special elements in template engine

A vulnerability labeled as problematic has been found in Concrete CMS up to 9.5.2. This impacts an unknown function of the component Theme Customizer. The manipulation results in improper neutralization of special elements used in a templat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.7%
CVE-2026-79394 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79394 | XiongMai Sofia IPC daemon up to 0608.1837 RTSP Server access control

A vulnerability described as problematic has been identified in XiongMai Sofia IPC daemon up to 0608.1837. Affected by this vulnerability is an unknown functionality of the component RTSP Server. Such manipulation leads to improper access c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 76.5%
CVE-2026-58138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

Orkes Conductor: kritische RCE-Lücke wird aktiv ausgenutzt – Update dringend

LONDON (IT BOLTWISE) – Eine kritische Sicherheitslücke in Orkes Conductor wird laut Fortinet aktiv ausgenutzt. Betroffen ist CVE-2026-58138 mit 9,8 (CVSS v3.1) bzw. 9,3 (CVSS v4) und einer unauthentifizierten Remote-Code-Execution vor der A

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 88.5%
CVE-2026-58138 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.6%
CVE-2026-88926 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-88926 | VikRentItems Flexible Rental Management System Plugin sql injection (EUVD-2026-83508)

A vulnerability has been found in VikRentItems Flexible Rental Management System Plugin up to 1.2.3 on WordPress and classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. Th

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 30.1%
CVE-2026-92099 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92099 | WPGraphQL Smart Cache Plugin up to 2.3.1 on WordPress access control (EUVD-2026-83510)

A vulnerability was found in WPGraphQL Smart Cache Plugin up to 2.3.1 on WordPress. It has been classified as problematic. This impacts an unknown function. The manipulation leads to improper access controls. This vulnerability is uniquely

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 20.1%
CVE-2026-91847 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91847 | Online Scheduling and Appointment Booking System Plugin authorization (EUVD-2026-83509)

A vulnerability was found in Online Scheduling and Appointment Booking System Plugin up to 28.1 on WordPress and classified as critical. This affects an unknown function. Executing a manipulation can lead to authorization bypass. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 2.7%
CVE-2026-92404 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92404 | MgoSync Plugin up to 2.1.6 on WordPress REST API Endpoint information disclosure (EUVD-2026-83512)

A vulnerability labeled as problematic has been found in MgoSync Plugin up to 2.1.6 on WordPress. Affected by this vulnerability is an unknown functionality of the component REST API Endpoint. Such manipulation leads to information disclosu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 19.2%
CVE-2026-92403 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92403 | Secure Custom Fields Plugin up to 6.9.3 on WordPress authorization (EUVD-2026-83511)

A vulnerability identified as problematic has been detected in Secure Custom Fields Plugin up to 6.9.3 on WordPress. Affected is an unknown function. This manipulation causes incorrect authorization. This vulnerability is tracked as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 27.8%
CVE-2026-92421 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92421 | Hydra Booking Plugin up to 1.2.2 on WordPress authorization (EUVD-2026-83514)

A vulnerability was found in Hydra Booking Plugin up to 1.2.2 on WordPress. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes authorization bypass. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 27.6%
CVE-2026-92420 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92420 | Hydra Booking Plugin up to 1.2.1 on WordPress authorization (EUVD-2026-83513)

A vulnerability was found in Hydra Booking Plugin up to 1.2.1 on WordPress. It has been declared as problematic. Affected is an unknown function. The manipulation results in authorization bypass. This vulnerability was named CVE-2026-92420.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 24.7%
CVE-2026-92430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92430 | Rede Itaú for WooCommerce Plugin up to 5.4.6 on WordPress authorization (EUVD-2026-83516)

A vulnerability described as problematic has been identified in Rede Itaú for WooCommerce Plugin up to 5.4.6 on WordPress. This affects an unknown part. Executing a manipulation can lead to missing authorization. This vulnerability is regis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 21.7%
CVE-2026-92425 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92425 | Hydra Booking Plugin up to 1.2.3 on WordPress authorization (EUVD-2026-83515)

A vulnerability marked as problematic has been reported in Hydra Booking Plugin up to 1.2.3 on WordPress. Affected by this issue is some unknown functionality. Performing a manipulation results in authorization bypass. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 31.6%
CVE-2026-92435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92435 | WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress Permission Callback authorization (EUVD-2026-83517)

A vulnerability marked as critical has been reported in WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress. This issue affects some unknown processing of the component Permission Callback. The manipulation leads to missin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
EPSS 21.2%
CVE-2026-93741 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93741 | Totolink A3002MU Hh-B20211125.1046 /boafrm/formWlWds submit-url buffer overflow (EUVD-2026-83497)

A vulnerability labeled as very critical has been found in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in bu

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.1%
CVE-2026-65381 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65381 | Apple macOS up to 15.7/26/26.6 Entitlement Verification sandbox

A vulnerability was found in Apple macOS up to 15.7/26/26.6 and classified as critical. This affects an unknown function of the component Entitlement Verification. Such manipulation leads to sandbox issue. This vulnerability is uniquely ide

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.9%
CVE-2026-65377 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65377 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.7/27/15.8 memory corruption

A vulnerability, which was classified as very critical, has been found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Impacted is an unknown function. The manipulation leads to memory corruption. This vulnerability is traded as CV

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.9%
CVE-2026-65376 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65376 | Apple macOS up to 15.7/26/26.6 out-of-bounds

A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. This issue affects some unknown processing. Executing a manipulation can lead to out-of-bounds read. This vulnerability appears as CVE-2026-65376. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.3%
CVE-2026-65375 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65375 | Apple macOS up to 15.7/26/26.5 improper authentication

A vulnerability classified as problematic has been found in Apple macOS up to 15.7/26/26.5. This vulnerability affects unknown code. Performing a manipulation results in improper authentication. This vulnerability is reported as CVE-2026-65

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.9%
CVE-2026-65369 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65369 | Apple macOS up to 15.7/26/26.6 Gatekeeper state issue

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as very critical. The impacted element is an unknown function of the component Gatekeeper. Such manipulation leads to state issue. This vulnerability is refer

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5.6%
CVE-2026-65371 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-65371 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS Kernel information disclosure

A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this vulnerability is an unknown functionality of the component Kernel. The manipulation results in information discl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 22.9%
CVE-2026-65360 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65360 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior 26.7/15.8/27 race condition

A vulnerability classified as problematic was found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this issue is some unknown functionality. Such manipulation leads to race condition. This vulnerability is traded as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 4.9%
CVE-2026-65361 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65361 | Apple macOS up to 15.7/26/26.6 information disclosure

A vulnerability, which was classified as problematic, was found in Apple macOS up to 15.7/26/26.6. This vulnerability affects unknown code. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.4%
CVE-2026-65359 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65359 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.7/27/15.8/Golden Gate 27/Tahoe 26.7 out-of-bounds

A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. It has been classified as problematic. This vulnerability affects unknown code. The manipulation leads to out-of-bounds read. This vulnerability is reference

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.2%
CVE-2026-65358 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65358 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior 27 race condition

A vulnerability classified as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected by this vulnerability is an unknown functionality. This manipulation causes race condition. This vulnerability appear

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.4%
CVE-2026-65378 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65378 | Apple macOS up to 15.7/26/26.6 privileges management

A vulnerability, which was classified as problematic, was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. The manipulation results in improper privilege management. This vulnerability is known as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.5%
CVE-2026-65357 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65357 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS up to 26.5 memory corruption

A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS up to 26.5 and classified as very critical. This affects an unknown part. Executing a manipulation can lead to memory corruption. The identification of this v

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.5%
CVE-2022-44431 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44431 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47374)

A vulnerability, which was classified as problematic, has been found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. This affects an unknown function of the component WL

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.2%
CVE-2022-44429 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44429 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47372)

A vulnerability classified as problematic has been found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. The affected element is an unknown function of the component WLA

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.6%
CVE-2022-44428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44428 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47371)

A vulnerability described as problematic has been identified in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. Impacted is an unknown function of the component WLAN Driver

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 6.1%
CVE-2022-44430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44430 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47373)

A vulnerability classified as problematic was found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. The impacted element is an unknown function of the component WLAN Dri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 3.3%
CVE-2022-44427 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44427 | Unisoc S8000 WLAN Driver denial of service (EUVD-2022-47370)

A vulnerability marked as problematic has been reported in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. This issue affects some unknown processing of the component WLAN

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.5%
CVE-2026-77179 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)

submitted by /u/natcoba [link] [comments] Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 86.1%
CVE-2025-39682 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabiliti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 27.5%
CVE-2026-65348 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65348 | Apple iOS/iPadOS/macOS prior 26.7/27/15.8 permission

A vulnerability labeled as critical has been found in Apple iOS, iPadOS and macOS. This affects an unknown function. Executing a manipulation can lead to permission issues. This vulnerability is registered as CVE-2026-65348. The attack need

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.1%
CVE-2026-65354 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65354 | Apple iOS/iPadOS/macOS up to 26 sandbox

A vulnerability described as very critical has been identified in Apple iOS, iPadOS and macOS up to 26. Affected is an unknown function. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-65354. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20%
CVE-2026-43785 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43785 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 27 privileges management

A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.4%
CVE-2026-43790 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-43790 | Apple macOS up to 15.7/26/26.6 Kernel memory corruption

A vulnerability categorized as very critical has been discovered in Apple macOS up to 15.7/26/26.6. Affected by this vulnerability is an unknown functionality of the component Kernel. Executing a manipulation can lead to memory corruption.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 26.2%
CVE-2026-65345 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65345 | Apple iOS/iPadOS/macOS prior 26.7/27/15.8 permission

A vulnerability identified as problematic has been detected in Apple iOS, iPadOS and macOS. The impacted element is an unknown function. Performing a manipulation results in permission issues. This vulnerability is cataloged as CVE-2026-653

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.2%
CVE-2026-65344 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65344 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 26.7/27/15.8 out-of-bounds write

A vulnerability categorized as very critical has been discovered in Apple iOS, iPadOS, macOS, tvOS and visionOS. The affected element is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.9%
CVE-2026-65342 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65342 | Apple macOS up to 15.7/26/26.6 permission

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. Impacted is an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2026-65342. The attack is restr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.6%
CVE-2026-43791 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43791 | Apple macOS up to 15.7/26/26.6 information disclosure

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to information disclosure. This vulnerability is track

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27%
CVE-2026-43808 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43808 | Apple iPadOS/iOS/macOS/tvOS/watchOS up to 26.5 use after free

A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS and watchOS up to 26.5. It has been rated as very critical. This affects an unknown part. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-43808.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 6%
CVE-2026-43787 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43787 | Apple macOS up to 15.7/26/26.6 information disclosure

A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-2026-43787

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.9%
CVE-2026-43789 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43789 | Apple macOS up to 15.7/26/26.6 Sandbox privileges management

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Sandbox. Performing a manipulation results in improper privilege ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.4%
CVE-2026-43696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43696 | Apple macOS up to 26 improper authorization

A vulnerability marked as problematic has been reported in Apple macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026-43696. A

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.2%
CVE-2026-43674 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43674 | Apple iOS/iPadOS up to 26 improper authentication

A vulnerability was found in Apple iOS and iPadOS up to 26. It has been classified as problematic. Affected is an unknown function. This manipulation causes improper authentication. This vulnerability is registered as CVE-2026-43674. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.5%
CVE-2026-43762 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43762 | Apple iOS/iPadOS/macOS/visionOS up to 26.5 information disclosure

A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS up to 26.5. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.7%
CVE-2026-43737 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43737 | Apple iOS/iPadOS/macOS/tvOS/watchOS prior 26.7/27/15.8 improper authorization

A vulnerability, which was classified as problematic, was found in Apple iOS, iPadOS, macOS, tvOS and watchOS. Impacted is an unknown function. Executing a manipulation can lead to improper authorization. The identification of this vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.7%
CVE-2026-43702 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43702 | Apple iPadOS/iOS/macOS/tvOS/watchOS Video File memory corruption

A vulnerability, which was classified as very critical, has been found in Apple iPadOS, iOS, macOS, tvOS and watchOS. This issue affects some unknown processing of the component Video File Handler. Performing a manipulation results in memor

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.8%
CVE-2026-43719 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43719 | Apple macOS up to 15.7/26/26.6 SMB use after free

A vulnerability classified as very critical has been found in Apple macOS up to 15.7/26/26.6. This affects an unknown part of the component SMB Handler. This manipulation causes use after free. This vulnerability is handled as CVE-2026-4371

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.6%
CVE-2026-43695 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43695 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior prior iOS 27 improper authorization

A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected is an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.