CVE-2017-5374: Schwachstellen-Eintrag (NVD)
Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-12 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-73289 | RustFS up to 1.0.0-beta.11 Condition string.rs eval_like privileges management
A vulnerability classified as critical was found in RustFS up to 1.0.0-beta.11. This impacts the function eval_like of the file crates/policy/src/policy/function/string.rs of the component Condition. The manipulation results in improper pri
CVE-2026-73288 | RustFS up to 1.0.0-beta.12 Object Lock objectlock_sys.rs check_object_lock_for_deletion privileges management
A vulnerability classified as problematic has been found in RustFS. This affects the function check_object_lock_for_deletion of the file crates/ecstore/src/bucket/object_lock/objectlock_sys.rs of the component Object Lock. The manipulation
CVE-2026-73263 | Prowler-Cloud Prowler up to 5.35.x Kubernetes Provider kubernetes_provider.py config.load_kube_config_from_dict deserialization
A vulnerability was found in Prowler-Cloud Prowler up to 5.35.x and classified as critical. Affected is the function config.load_kube_config_from_dict of the file prowler/providers/kubernetes/kubernetes_provider.py of the component Kubernet
CVE-2026-73287 | RustFS up to 1.0.0-beta.11 FtpsDriver driver.rs FtpsDriver::mkd improper authorization
A vulnerability described as problematic has been identified in RustFS up to 1.0.0-beta.11. The impacted element is the function FtpsDriver::mkd of the file crates/protocols/src/ftps/driver.rs of the component FtpsDriver. Executing a manipu
CVE-2026-73285 | RustFS up to 1.0.0-beta.12 IAM crates/iam/src/sys.rs maybe_merge_object_tag_conditions improper authorization
A vulnerability marked as critical has been reported in RustFS. The affected element is the function maybe_merge_object_tag_conditions of the file crates/iam/src/sys.rs of the component IAM. Performing a manipulation results in improper aut
CVE-2026-73286 | RustFS up to 1.0.0-beta.11 Condition Keys get_condition_values access control
A vulnerability labeled as critical has been found in RustFS up to 1.0.0-beta.11. Impacted is the function get_condition_values of the component Condition Keys. Such manipulation leads to improper access controls. This vulnerability is uniq
CVE-2026-73284 | RustFS up to 1.0.0-beta.10 Service Account service_account.rs AddServiceAccount target_user privileges management
A vulnerability categorized as critical has been discovered in RustFS up to 1.0.0-beta.10. This vulnerability affects the function AddServiceAccount of the file rustfs/src/admin/handlers/service_account.rs of the component Service Account.
CVE-2026-73264 | prowler-cloud Prowler up to 5.33.0 Lighthouse Providers lighthouse_providers.py base_url improper authorization
A vulnerability identified as problematic has been detected in prowler-cloud Prowler up to 5.33.0. This issue affects some unknown processing of the file api/src/backend/tasks/jobs/lighthouse_providers.py of the component Lighthouse Provide
CVE-2026-73290 | RustFS up to 1.0.0-beta.11 Policy Evaluation access.rs access control
A vulnerability was found in RustFS up to 1.0.0-beta.11. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file rustfs/src/storage/access.rs of the component Policy Evaluation. Performi
CVE-2026-73265 | RustFS up to 1.0.0-beta.10 GetObject/CopyObject/UploadPartCopy improper authorization
A vulnerability was found in RustFS up to 1.0.0-beta.10. It has been declared as problematic. Affected by this issue is the function GetObject/CopyObject/UploadPartCopy. Executing a manipulation can lead to improper authorization. This vuln
CVE-2026-90558 | irontec sngrep up to 1.8.4 stack-based overflow (EUVD-2026-76903 / Nessus ID 345447)
A vulnerability classified as critical has been found in irontec sngrep up to 1.8.4. Affected is an unknown function. This manipulation causes stack-based buffer overflow. This vulnerability is handled as CVE-2026-90558. The attack can be i
CVE-2026-90557 | Freeciv up to 3.2.5 Savegame sg_load_player_unit out-of-bounds (EUVD-2026-76902 / Nessus ID 345448)
A vulnerability described as problematic has been identified in Freeciv up to 3.2.5. This impacts the function sg_load_player_unit of the component Savegame. The manipulation results in out-of-bounds read. This vulnerability is known as CVE
CVE-2026-90556 | Freeciv up to 3.2.5 Worklist worklist_load heap-based overflow (EUVD-2026-76901 / Nessus ID 345451)
A vulnerability marked as problematic has been reported in Freeciv up to 3.2.5. This affects the function worklist_load of the component Worklist. The manipulation leads to heap-based buffer overflow. This vulnerability is traded as CVE-202
CVE-2026-90559 | Xerial snappy-java up to 1.1.10.8 Snappy.uncompress out-of-bounds write (EUVD-2026-76904)
A vulnerability classified as problematic was found in Xerial snappy-java up to 1.1.10.8. Affected by this vulnerability is the function Snappy.uncompress. Such manipulation leads to out-of-bounds write. This vulnerability is uniquely ident
CVE-2026-90560 | luben zstd-jni up to 1.5.7-13 Dictionary Decompression ZstdDictDecompress constructor offset/length out-of-bounds (EUVD-2026-76905 / Nessus ID 345449)
A vulnerability, which was classified as critical, has been found in luben zstd-jni up to 1.5.7-13. Affected by this issue is the function ZstdDictDecompress constructor of the component Dictionary Decompression. Performing a manipulation o
CVE-2026-90616 | Flatpak up to 1.18.0 Sandbox Directory Binding link following (EUVD-2026-76911)
A vulnerability classified as problematic was found in Flatpak up to 1.18.0. The affected element is an unknown function of the component Sandbox Directory Binding. The manipulation results in link following. This vulnerability is known as
CVE-2026-90485 | IOBit Uninstaller 15.5.0.11 IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereference (EUVD-2026-76913)
A vulnerability has been found in IOBit Uninstaller 15.5.0.11 and classified as problematic. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes
CVE-2026-79300 | SEP sesam prior 5.2.0.24 improper authorization (EUVD-2026-76915)
A vulnerability was found in SEP sesam. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in improper authorization. This vulnerability is identified as CVE-2026-79300. The a
CVE-2026-90494 | restify node-restify up to 12.0.0 /lib/plugins/static.js serveStatic path traversal (EUVD-2026-76941)
A vulnerability was found in restify node-restify up to 12.0.0. It has been rated as problematic. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. This vulnerability is ha
CVE-2026-90678 | HAProxy up to 3.3.14/3.4.4/3.5-dev5 HTTP/3 Multiplexer request smuggling (EUVD-2026-76943)
A vulnerability labeled as problematic has been found in HAProxy up to 3.3.14/3.4.4/3.5-dev5. Impacted is an unknown function of the component HTTP/3 Multiplexer. Executing a manipulation can lead to http request smuggling. This vulnerabili
CVE-2026-90495 | Fengoffice Feng Office up to 3.11.13.11 Legacy API CompanyWebsite.class.php instance->findAll auth sql injection (EUVD-2026-76942)
A vulnerability categorized as critical has been discovered in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance-&gt;findAll of the file application/models/CompanyWebsite.class.php of the component Le
CVE-2026-90679 | Forgejo up to 16.0.4 ActivityPub reqsignature.go signature verification (EUVD-2026-76944)
A vulnerability marked as problematic has been reported in Forgejo up to 16.0.4. The affected element is an unknown function of the file routers/api/v1/activitypub/reqsignature.go of the component ActivityPub. The manipulation leads to impr
CVE-2025-25252 | Fortinet FortiOS up to 7.6.2 SSL VPN session expiration (FG-IR-24-487 / EUVD-2025-34237)
A vulnerability was found in Fortinet FortiOS up to 6.4.16/7.0.16/7.2.10/7.4.6/7.6.2. It has been rated as problematic. This impacts an unknown function of the component SSL VPN. Performing a manipulation results in session expiration. This
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
CVE-2022-43713 | GX XperienCentral up to 10.35.0 Interactive Forms input validation (EUVD-2022-46695)
A vulnerability labeled as critical has been found in GX XperienCentral up to 10.35.0. This affects an unknown part of the component Interactive Forms. Such manipulation leads to improper input validation. This vulnerability is referenced a
CVE-2022-43722 | Siemens SICAM PAS/SICAM PQS up to 6.x uncontrolled search path (ssa-849072 / EUVD-2022-46699)
A vulnerability classified as very critical was found in Siemens SICAM PAS and SICAM PQS up to 6.x. Affected is an unknown function. The manipulation results in uncontrolled search path. This vulnerability is cataloged as CVE-2022-43722. Th
CVE-2022-43711 | GX XperienCentral up to 10.33.0 Interactive Forms eval cross site scripting (EUVD-2022-46693)
A vulnerability marked as problematic has been reported in GX XperienCentral up to 10.33.0. This vulnerability affects the function eval of the component Interactive Forms. Performing a manipulation results in cross site scripting. This vul
CVE-2022-43712 | GX XperienCentral up to 10.36.0 POST Request /web/mvc access control (EUVD-2022-46694)
A vulnerability, which was classified as critical, has been found in GX XperienCentral up to 10.36.0. This issue affects some unknown processing of the file /web/mvc of the component POST Request Handler. The manipulation leads to improper
CVE-2022-43710 | GX XperienCentral up to 10.33.0 Interactive Forms cross-site request forgery (EUVD-2022-46692)
A vulnerability identified as problematic has been detected in GX XperienCentral up to 10.33.0. Affected by this issue is some unknown functionality of the component Interactive Forms. This manipulation causes cross-site request forgery. Th
CVE-2022-43709 | MyBB 1.8.31 Users sql injection (GHSA-ggp5-454p-867v / EUVD-2022-46691)
A vulnerability described as critical has been identified in MyBB 1.8.31. This affects an unknown part of the component Users Module. The manipulation results in sql injection. This vulnerability was named CVE-2022-43709. The attack may be
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
CVE-2026-89696 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd nfsd4_putfh null pointer dereference (Nessus ID 345430)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. This affects the function nfsd4_putfh of the component nfsd. Such manipulation leads to null pointer dereference. This vulnerability is liste
CVE-2026-80996 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 L2TP exceptional condition (Nessus ID 345431)
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects an unknown function of the component L2TP. The manipulation results in handling of exceptional conditions. This vulnerability is
CVE-2026-89481 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme-tcp nvme_tcp_handle_r2t information disclosure (Nessus ID 345433)
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function nvme_tcp_handle_r2t of the component nvme-tcp. The manipulation results in information disc
CVE-2026-89739 | Linux Kernel up to 6.18.49/7.2.3 dwc3 dwc3_gadget_free_endpoints use after free (Nessus ID 345432)
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.49/7.2.3. Affected by this issue is the function dwc3_gadget_free_endpoints of the component dwc3. Performing a manipulation results in use after free.
CVE-2026-89584 | Linux Kernel up to 7.2.3 block stack-based overflow (Nessus ID 345434)
A vulnerability was found in Linux Kernel up to 7.2.3. It has been declared as very critical. This issue affects some unknown processing of the component block. Such manipulation leads to stack-based buffer overflow. This vulnerability is l
CVE-2026-90473 | msgpack msgpack-java up to 0.9.12 MessageUnpacker MessageUnpacker.skipValue integer overflow (Nessus ID 345452)
A vulnerability was found in msgpack msgpack-java up to 0.9.12. It has been classified as problematic. This issue affects the function MessageUnpacker.skipValue of the component MessageUnpacker. The manipulation leads to integer overflow. T
CVE-2026-90472 | msgpack msgpack-java up to 0.9.12 MessageUnpacker.unpackValue stack-based overflow (Nessus ID 345450)
A vulnerability has been found in msgpack msgpack-java up to 0.9.12 and classified as problematic. This affects the function MessageUnpacker.unpackValue. Performing a manipulation results in stack-based buffer overflow. This vulnerability i
Sogou Input Method: Chinesische <b>Hacker</b> nutzen CVE-2026-51990 - Börse Express
UNC3569 nutzte CVE-2026-51990 gegen Sogou-Nutzer. Tencent schloss die kritische Lücke im April mit Version 16.3.0.3498. Weiterlesen
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep
Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots
Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker in close physical proximity to run unauthorized code on the device or pull data stored on it, simply
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV
CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On