🎯 CVE-2018-10248 MEDIUM 6.5 🔥 EPSS 2%
📄 .md Alle CVEs anzeigen ✕

CVE-2018-10248: Schwachstellen-Eintrag (NVD)

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.

Klassifikation & Betroffenheit:
wuzhicms wuzhicms 4.1.0
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 6.5
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Erforderlich
S · Scope Unverändert
C · Vertraulichkeit Keine
I · Integrität Hoch
A · Verfügbarkeit Keine
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Veröffentlicht:20.04.2018
Aktualisiert:17.06.2026 01:33
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 174 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.535 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-12
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 51
Microsoft 6
WordPress 1
Google 1
Apache 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 25.4%
CVE-2026-0298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-0298 | Palo Alto Networks GlobalProtect App Pre-Logon Access Provider channel accessible (EUVD-2026-57712)

A vulnerability, which was classified as very critical, has been found in Palo Alto Networks GlobalProtect App. This issue affects some unknown processing of the component Pre-Logon Access Provider. The manipulation leads to channel accessi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-0296 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-0296 | Palo Alto Networks GlobalProtect App certificate validation (EUVD-2026-57710)

A vulnerability classified as problematic was found in Palo Alto Networks GlobalProtect App. This vulnerability affects unknown code. Executing a manipulation can lead to improper certificate validation. This vulnerability is handled as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-0297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-0297 | Palo Alto Networks GlobalProtect buffer overflow (EUVD-2026-57711)

A vulnerability marked as very critical has been reported in Palo Alto Networks GlobalProtect. Affected by this vulnerability is an unknown functionality. This manipulation causes buffer overflow. This vulnerability appears as CVE-2026-0297

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-73493 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73493 | http4s http4s-blaze-server up to 0.23.17/1.0.0-M41 WebSocket resource consumption

A vulnerability was found in http4s http4s-blaze-server up to 0.23.17/1.0.0-M41 and classified as problematic. This impacts an unknown function of the component WebSocket. Such manipulation leads to resource consumption. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.2%
CVE-2026-19003 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19003 | MongoDB BI Connector ODBC Driver up to 1.4.8 File/Folder Selection buffer overflow

A vulnerability categorized as critical has been discovered in MongoDB BI Connector ODBC Driver up to 1.4.8. This affects an unknown part of the component File/Folder Selection Handler. The manipulation results in buffer overflow. This vuln

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-2026-19004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19004 | MongoDB BI Connector ODBC Driver up to 1.4.8 information disclosure

A vulnerability was found in MongoDB BI Connector ODBC Driver up to 1.4.8. It has been declared as problematic. Impacted is an unknown function. The manipulation results in information disclosure. This vulnerability is reported as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-19002 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19002 | MongoDB BI Connector ODBC Driver up to 1.4.8 out-of-bounds write

A vulnerability identified as very critical has been detected in MongoDB BI Connector ODBC Driver up to 1.4.8. This affects an unknown function. Performing a manipulation results in out-of-bounds write. This vulnerability is known as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2026-66898 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66898 | Canonical LXD up to 4.0.11/5.0.3/5.21.1/6.0 Backup Import path traversal

A vulnerability was found in Canonical LXD up to 4.0.11/5.0.3/5.21.1/6.0. It has been declared as very critical. This affects an unknown part of the component Backup Import. Executing a manipulation can lead to path traversal. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-0295 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-0295 | Palo Alto Networks GlobalProtect race condition (EUVD-2026-57709)

A vulnerability has been found in Palo Alto Networks GlobalProtect and classified as problematic. The affected element is an unknown function. This manipulation causes race condition. The identification of this vulnerability is CVE-2026-029

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18%
CVE-2022-43698 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43698 | OX Software OX App Suite up to 7.10.6-rev29 POP3 Account server-side request forgery (EUVD-2022-46680)

A vulnerability labeled as critical has been found in OX Software OX App Suite. Affected is an unknown function of the component POP3 Account Handler. Such manipulation leads to server-side request forgery. This vulnerability is uniquely id

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2022-43697 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43697 | OX Software OX App Suite up to 7.10.6-rev29 jslob cross site scripting (EUVD-2022-46679)

A vulnerability described as problematic has been identified in OX Software OX App Suite. Affected by this issue is some unknown functionality of the component jslob. Executing a manipulation can lead to cross site scripting. The identifica

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.9%
CVE-2022-43696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43696 | OX Software OX App Suite up to 7.10.6-rev16 Upsell Ads cross site scripting (EUVD-2022-46678)

A vulnerability marked as problematic has been reported in OX Software OX App Suite. Affected by this vulnerability is an unknown functionality of the component Upsell Ads Handler. Performing a manipulation results in cross site scripting.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 73.2%
CVE-2022-43679 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43679 | ownCloud Server up to 10.11 E-Mail Message Remote Code Execution (EUVD-2022-46672)

A vulnerability was found in ownCloud Server up to 10.11. It has been rated as critical. Affected by this issue is some unknown functionality of the component E-Mail Message Handler. Performing a manipulation results in Remote Code Executio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2022-43668 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43668 | Typora up to 1.4.3 File cross site scripting (EUVD-2022-46663)

A vulnerability categorized as problematic has been discovered in Typora up to 1.4.3. This impacts an unknown function of the component File Handler. Such manipulation leads to cross site scripting. This vulnerability is listed as CVE-2022-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2022-43667 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43667 | Omron CX-Programmer up to 9.77 CXP File stack-based overflow (EUVD-2022-46662)

A vulnerability was found in Omron CX-Programmer up to 9.77 and classified as critical. This affects an unknown part of the component CXP File Handler. Such manipulation leads to stack-based buffer overflow. This vulnerability is referenced

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 23.9%
CVE-2026-85198 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-85198 | meIsle MPG Multiple Page Generator Plugin up to 4.2.1 on WordPress Shortcode sql injection

A vulnerability marked as critical has been reported in meIsle MPG Multiple Page Generator Plugin up to 4.2.1 on WordPress. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation results in sql inject

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 29.6%
CVE-2026-90490 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90490 | lenve vhr 1.0-SNAPSHOT MailReceiver deserialization

A vulnerability has been found in lenve vhr 1.0-SNAPSHOT and classified as critical. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. This vulnerability is repor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.1%
CVE-2026-62420 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62420 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration authorization (Nessus ID 335303)

A vulnerability has been found in Canonical LXD up to 5.0.7/5.21.5/6.9 and classified as very critical. The affected element is an unknown function of the component Instance Migration. Performing a manipulation results in authorization bypa

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.5%
CVE-2026-63299 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63299 | Canonical LXD up to 5.0.7/5.21.5/6.9 Volume Operations storagePoolVolumeTypePostMove authorization

A vulnerability was found in Canonical LXD up to 5.0.7/5.21.5/6.9. It has been classified as problematic. Impacted is the function storagePoolVolumeTypePostMove of the component Volume Operations. Performing a manipulation results in author

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-18888 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18888 | MongoDB BI Connector ODBC Driver up to 1.4.8 buffer overflow (Nessus ID 343472)

A vulnerability categorized as problematic has been discovered in MongoDB BI Connector ODBC Driver up to 1.4.8. The impacted element is an unknown function. Such manipulation leads to buffer overflow. This vulnerability is traded as CVE-202

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-19001 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19001 | MongoDB BI Connector ODBC Driver up to 1.4.8 memory corruption

A vulnerability was found in MongoDB BI Connector ODBC Driver up to 1.4.8. It has been rated as very critical. The affected element is an unknown function. This manipulation causes memory corruption. This vulnerability appears as CVE-2026-1

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2026-16033 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-16033 | Canonical LXD up to 4.0.11/5.0.7 Image Metadata Template path traversal (Nessus ID 335300)

A vulnerability described as very critical has been identified in Canonical LXD up to 4.0.11/5.0.7. This affects an unknown function of the component Image Metadata Template. Executing a manipulation can lead to path traversal. The identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-63294 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63294 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Symlink backup.yaml symlink

A vulnerability categorized as very critical has been discovered in Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9. Affected by this issue is some unknown functionality of the file backup.yaml of the component Symlink Handler. Executing a mani

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2026-63298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63298 | Canonical LXD up to 4.0.11/5.0.7/5.21.5 Configuration lxc.conf nvidia.driver.capabilities/nvidia.require.* neutralization

A vulnerability has been found in Canonical LXD up to 4.0.11/5.0.7/5.21.5 and classified as very critical. This issue affects some unknown processing of the file lxc.conf of the component Configuration Handler. Performing a manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.8%
CVE-2026-63297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63297 | Canonical LXD up to 5.0.7/5.21.5 toctou

A vulnerability, which was classified as problematic, was found in Canonical LXD up to 5.0.7/5.21.5. This vulnerability affects unknown code. Such manipulation leads to time-of-check time-of-use. This vulnerability is documented as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-63296 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63296 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration authorization

A vulnerability, which was classified as problematic, has been found in Canonical LXD up to 5.0.7/5.21.5/6.9. This affects an unknown part of the component Instance Migration. This manipulation causes authorization bypass. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-63295 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63295 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Container Isolation security.idmap.isolated authorization

A vulnerability described as very critical has been identified in Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9. Affected is an unknown function of the component Container Isolation. Executing a manipulation of the argument security.idmap.iso

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-63300 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63300 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration lxd/instance_post.go instancePostMigration privileges management

A vulnerability was found in Canonical LXD up to 5.0.7/5.21.5/6.9. It has been rated as very critical. The impacted element is the function instancePostMigration of the file lxd/instance_post.go of the component Instance Migration. The mani

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Update auf Chrome 153 schließt eine 0-Day-Lücke – weitere Browser sind abgesichert

In den neuen Chrome-Versionen 153.0.8010.36/37 für Windows und macOS sowie 153.0.8010.36 für Linux haben die Entwickler 230 teils kritische Schwachstellen behoben. Eine der gestopften Lücken wird laut Google bereits für Angriffe ausgenutzt.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 18.7%
CVE-2026-71434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71434 | Statamic up to 5.74.2/6.24.1 unrestricted upload

A vulnerability was found in Statamic up to 5.74.2/6.24.1. It has been classified as critical. This affects an unknown function. The manipulation leads to unrestricted upload. This vulnerability is uniquely identified as CVE-2026-71434. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-71435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71435 | Statamic up to 5.74.2/6.24.1 Form Notification Email cross site scripting

A vulnerability was found in Statamic up to 5.74.2/6.24.1 and classified as problematic. Impacted is an unknown function of the component Form Notification Email. Executing a manipulation can lead to cross site scripting. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.9%
CVE-2026-71436 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71436 | mermaid-js Mermaid up to 10.9.7/11.16.0 XY Charts setXAxisRangeData infinite loop

A vulnerability labeled as problematic has been found in mermaid-js Mermaid up to 10.9.7/11.16.0. This affects the function setXAxisRangeData of the component XY Charts. Such manipulation leads to infinite loop. This vulnerability is refere

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.1%
CVE-2026-71327 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71327 | Traefik up to 3.6.24/3.7.9 Kubernetes Gateway API Provider httproute.go race condition

A vulnerability has been found in Traefik up to 3.6.24/3.7.9 and classified as problematic. Affected by this issue is some unknown functionality of the file pkg/provider/kubernetes/gateway/httproute.go of the component Kubernetes Gateway AP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.6%
CVE-2026-64665 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64665 | Statamic up to 5.74.0/6.23.x improper authentication

A vulnerability marked as critical has been reported in Statamic up to 5.74.0/6.23.x. The affected element is an unknown function. This manipulation causes improper authentication. This vulnerability is tracked as CVE-2026-64665. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.9%
CVE-2026-71324 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71324 | Traefik up to 2.11.52/3.6.23/3.7.8 Reverse Proxy improper synchronization

A vulnerability, which was classified as critical, was found in Traefik up to 2.11.52/3.6.23/3.7.8. Affected by this vulnerability is an unknown functionality of the component Reverse Proxy. The manipulation results in improper synchronizat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.1%
CVE-2026-71326 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71326 | Traefik up to 3.6.24/3.7.9 BasicAuth Middleware basic_auth.go improper authentication

A vulnerability described as critical has been identified in Traefik up to 3.6.24/3.7.9. This issue affects some unknown processing of the file pkg/middlewares/auth/basic_auth.go of the component BasicAuth Middleware. The manipulation resul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.1%
CVE-2026-71325 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71325 | Traefik up to 2.11.53/3.6.24/3.7.9 Kubernetes CRD privileges management

A vulnerability marked as problematic has been reported in Traefik up to 2.11.53/3.6.24/3.7.9. Affected by this vulnerability is an unknown functionality of the component Kubernetes CRD. The manipulation leads to improper privilege manageme

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.8%
CVE-2026-83948 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-83948 | Microsoft Azure CLI up to 2.2.0 command injection (Nessus ID 344810)

A vulnerability was found in Microsoft Azure CLI up to 2.2.0. It has been rated as critical. This impacts an unknown function. This manipulation causes command injection. This vulnerability appears as CVE-2026-83948. The attack may be initi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 24.1%
CVE-2026-87776 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87776 | compression up to 1.8.1 resource consumption (Nessus ID 344814)

A vulnerability classified as problematic was found in compression up to 1.8.1. This vulnerability affects unknown code. Such manipulation leads to resource consumption. This vulnerability is documented as CVE-2026-87776. The attack can be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.4%
CVE-2026-79591 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79591 | libxls 1.6.3 xls_getCSS use after free (Nessus ID 344813)

A vulnerability was found in libxls 1.6.3. It has been rated as critical. Affected by this issue is the function xls_getCSS. The manipulation leads to use after free. This vulnerability is uniquely identified as CVE-2026-79591. The attack i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-79592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79592 | libxls 1.6.3 xls_dumpSummary out-of-bounds (Nessus ID 344812)

A vulnerability, which was classified as problematic, has been found in libxls 1.6.3. The affected element is the function xls_dumpSummary. The manipulation leads to out-of-bounds read. This vulnerability is documented as CVE-2026-79592. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-69522 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69522 | Microsoft Visual Studio up to Visual Studio 2026 buffer overflow (Nessus ID 344819 / WID-SEC-2026-3242)

A vulnerability described as critical has been identified in Microsoft Visual Studio. This impacts an unknown function. The manipulation results in buffer overflow. This vulnerability was named CVE-2026-69522. The attack may be performed fr

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 24.4%
CVE-2026-66304 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-66304 | Microsoft Skype for Business Server 2015 CU13/2019 CU8/Subscription Edition CU1 server-side request forgery (Nessus ID 344822)

A vulnerability was found in Microsoft Skype for Business Server 2015 CU13/2019 CU8/Subscription Edition CU1. It has been classified as problematic. This affects an unknown part. This manipulation causes server-side request forgery. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-62886 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62886 | Microsoft .NET/Visual Studio up to 18.8 integer overflow (Nessus ID 344819 / WID-SEC-2026-2761)

A vulnerability was found in Microsoft .NET and Visual Studio 10.0/8.0/9.0/17.14/18.8 and classified as problematic. This affects an unknown function. Such manipulation leads to integer overflow. This vulnerability is documented as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 31.2%
CVE-2026-77490 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-77490 | Microsoft Edge up to 151.0.4129.86 cross site scripting (Nessus ID 344898)

A vulnerability described as problematic has been identified in Microsoft Edge. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability is handled as CVE-2026-77490. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.1%
CVE-2026-87491 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87491 | Google Chrome up to 152.0.7977.82 V8 out-of-bounds write (Nessus ID 344899)

A vulnerability has been found in Google Chrome and classified as critical. This vulnerability affects unknown code of the component V8. This manipulation causes out-of-bounds write. This vulnerability appears as CVE-2026-87491. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24%
CVE-2026-84939 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-84939 | Apache FreeMarker path traversal (Nessus ID 344903)

A vulnerability has been found in Apache FreeMarker and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal. This vulnerability is listed as CVE-2026-84939. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30%
CVE-2026-89259 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89259 | gohugoio Hugo up to 0.164.x Build Process hugo.toml permission (Nessus ID 344902)

A vulnerability was found in gohugoio Hugo up to 0.164.x. It has been declared as critical. This impacts an unknown function of the file hugo.toml of the component Build Process. Such manipulation leads to permission issues. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-73077 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73077 | Vim up to 9.2.0838 Filetype Plugins runtime/ftplugin/sh.vim fnameescape os command injection (Nessus ID 341579 / WID-SEC-2026-2513)

A vulnerability was found in Vim up to 9.2.0838. It has been classified as problematic. The impacted element is the function fnameescape of the file runtime/ftplugin/sh.vim of the component Filetype Plugins. Performing a manipulation result

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-73087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73087 | amir20 Dozzle up to 10.6.14 SSRF Guard webhook.go isBlockedIP server-side request forgery

A vulnerability was found in amir20 Dozzle up to 10.6.14. It has been declared as critical. The affected element is the function isBlockedIP of the file internal/notification/dispatcher/webhook.go of the component SSRF Guard. Such manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-73086 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73086 | ai nanoid up to 3.3.11/5.1.10 Fill Pool index.js size integer overflow

A vulnerability was found in ai nanoid up to 3.3.11/5.1.10. It has been classified as critical. Impacted is the function nanoid of the file index.js of the component Fill Pool. This manipulation of the argument size causes integer overflow.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-73085 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73085 | advplyr Audiobookshelf up to 2.35.x TokenManager TokenManager.js jwtAuthCheck improper authentication

A vulnerability categorized as critical has been discovered in advplyr Audiobookshelf up to 2.35.x. Impacted is the function jwtAuthCheck of the file server/auth/TokenManager.js of the component TokenManager. Such manipulation leads to impr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-73084 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73084 | Activepieces up to 0.82.x OAuth Callback Endpoint code cross site scripting (CNNVD-2026-99290535)

A vulnerability was found in Activepieces up to 0.82.x. It has been rated as problematic. This issue affects some unknown processing of the component OAuth Callback Endpoint. This manipulation of the argument code causes cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-73083 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73083 | Activepieces up to 0.79.x Sandbox importFresh privileges management

A vulnerability was found in Activepieces up to 0.79.x. It has been declared as critical. This vulnerability affects the function importFresh of the component Sandbox. The manipulation results in improper privilege management. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-73081 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73081 | Activepieces up to 0.79.x Code Compilation Pipeline os command injection

A vulnerability was found in Activepieces up to 0.79.x and classified as critical. Affected by this issue is some unknown functionality of the component Code Compilation Pipeline. Executing a manipulation can lead to os command injection. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.6%
CVE-2026-73082 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73082 | Activepieces up to 0.81.x Validate Agent MCP Tool server-side request forgery

A vulnerability was found in Activepieces up to 0.81.x. It has been classified as critical. This affects an unknown part of the component Validate Agent MCP Tool. The manipulation leads to server-side request forgery. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-47704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47704 | baptisteArno Typebot up to 3.16.x Webhook Resume access control

A vulnerability identified as problematic has been detected in baptisteArno Typebot up to 3.16.x. Affected by this vulnerability is an unknown functionality of the component Webhook Resume Handler. This manipulation causes improper access c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-48483 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48483 | baptisteArno Typebot up to 3.16.x WhatsApp Status Forwarding server-side request forgery

A vulnerability labeled as critical has been found in baptisteArno Typebot up to 3.16.x. Affected by this issue is some unknown functionality of the component WhatsApp Status Forwarding. Such manipulation leads to server-side request forger

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-73078 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73078 | Vim up to 9.2.0839 Netrw Plugin netrwPlugin.vim s:NetrwBookmarkMenu/s:NetrwTgtMenu/netrw#MakeTgt os command injection (Nessus ID 341579 / WID-SEC-2026-2513)

A vulnerability, which was classified as problematic, has been found in Vim up to 9.2.0839. This vulnerability affects the function s:NetrwBookmarkMenu/s:NetrwTgtMenu/netrw#MakeTgt of the file runtime/plugin/netrwPlugin.vim of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-73080 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73080 | SeaweedFS up to 4.23 gRPC Remote Storage volume_grpc_remote.go VolumeServer.FetchAndWriteNeedle server-side request forgery

A vulnerability was found in SeaweedFS up to 4.23. It has been declared as problematic. This affects the function VolumeServer.FetchAndWriteNeedle of the file weed/server/volume_grpc_remote.go of the component gRPC Remote Storage. Executing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.