CVE-2018-10248: Schwachstellen-Eintrag (NVD)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-12 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-0298 | Palo Alto Networks GlobalProtect App Pre-Logon Access Provider channel accessible (EUVD-2026-57712)
A vulnerability, which was classified as very critical, has been found in Palo Alto Networks GlobalProtect App. This issue affects some unknown processing of the component Pre-Logon Access Provider. The manipulation leads to channel accessi
CVE-2026-0296 | Palo Alto Networks GlobalProtect App certificate validation (EUVD-2026-57710)
A vulnerability classified as problematic was found in Palo Alto Networks GlobalProtect App. This vulnerability affects unknown code. Executing a manipulation can lead to improper certificate validation. This vulnerability is handled as CVE
CVE-2026-0297 | Palo Alto Networks GlobalProtect buffer overflow (EUVD-2026-57711)
A vulnerability marked as very critical has been reported in Palo Alto Networks GlobalProtect. Affected by this vulnerability is an unknown functionality. This manipulation causes buffer overflow. This vulnerability appears as CVE-2026-0297
CVE-2026-73493 | http4s http4s-blaze-server up to 0.23.17/1.0.0-M41 WebSocket resource consumption
A vulnerability was found in http4s http4s-blaze-server up to 0.23.17/1.0.0-M41 and classified as problematic. This impacts an unknown function of the component WebSocket. Such manipulation leads to resource consumption. This vulnerability
CVE-2026-19003 | MongoDB BI Connector ODBC Driver up to 1.4.8 File/Folder Selection buffer overflow
A vulnerability categorized as critical has been discovered in MongoDB BI Connector ODBC Driver up to 1.4.8. This affects an unknown part of the component File/Folder Selection Handler. The manipulation results in buffer overflow. This vuln
CVE-2026-19004 | MongoDB BI Connector ODBC Driver up to 1.4.8 information disclosure
A vulnerability was found in MongoDB BI Connector ODBC Driver up to 1.4.8. It has been declared as problematic. Impacted is an unknown function. The manipulation results in information disclosure. This vulnerability is reported as CVE-2026-
CVE-2026-19002 | MongoDB BI Connector ODBC Driver up to 1.4.8 out-of-bounds write
A vulnerability identified as very critical has been detected in MongoDB BI Connector ODBC Driver up to 1.4.8. This affects an unknown function. Performing a manipulation results in out-of-bounds write. This vulnerability is known as CVE-20
CVE-2026-66898 | Canonical LXD up to 4.0.11/5.0.3/5.21.1/6.0 Backup Import path traversal
A vulnerability was found in Canonical LXD up to 4.0.11/5.0.3/5.21.1/6.0. It has been declared as very critical. This affects an unknown part of the component Backup Import. Executing a manipulation can lead to path traversal. This vulnerab
CVE-2026-0295 | Palo Alto Networks GlobalProtect race condition (EUVD-2026-57709)
A vulnerability has been found in Palo Alto Networks GlobalProtect and classified as problematic. The affected element is an unknown function. This manipulation causes race condition. The identification of this vulnerability is CVE-2026-029
CVE-2022-43698 | OX Software OX App Suite up to 7.10.6-rev29 POP3 Account server-side request forgery (EUVD-2022-46680)
A vulnerability labeled as critical has been found in OX Software OX App Suite. Affected is an unknown function of the component POP3 Account Handler. Such manipulation leads to server-side request forgery. This vulnerability is uniquely id
CVE-2022-43697 | OX Software OX App Suite up to 7.10.6-rev29 jslob cross site scripting (EUVD-2022-46679)
A vulnerability described as problematic has been identified in OX Software OX App Suite. Affected by this issue is some unknown functionality of the component jslob. Executing a manipulation can lead to cross site scripting. The identifica
CVE-2022-43696 | OX Software OX App Suite up to 7.10.6-rev16 Upsell Ads cross site scripting (EUVD-2022-46678)
A vulnerability marked as problematic has been reported in OX Software OX App Suite. Affected by this vulnerability is an unknown functionality of the component Upsell Ads Handler. Performing a manipulation results in cross site scripting.
CVE-2022-43679 | ownCloud Server up to 10.11 E-Mail Message Remote Code Execution (EUVD-2022-46672)
A vulnerability was found in ownCloud Server up to 10.11. It has been rated as critical. Affected by this issue is some unknown functionality of the component E-Mail Message Handler. Performing a manipulation results in Remote Code Executio
CVE-2022-43668 | Typora up to 1.4.3 File cross site scripting (EUVD-2022-46663)
A vulnerability categorized as problematic has been discovered in Typora up to 1.4.3. This impacts an unknown function of the component File Handler. Such manipulation leads to cross site scripting. This vulnerability is listed as CVE-2022-
CVE-2022-43667 | Omron CX-Programmer up to 9.77 CXP File stack-based overflow (EUVD-2022-46662)
A vulnerability was found in Omron CX-Programmer up to 9.77 and classified as critical. This affects an unknown part of the component CXP File Handler. Such manipulation leads to stack-based buffer overflow. This vulnerability is referenced
CVE-2026-85198 | meIsle MPG Multiple Page Generator Plugin up to 4.2.1 on WordPress Shortcode sql injection
A vulnerability marked as critical has been reported in meIsle MPG Multiple Page Generator Plugin up to 4.2.1 on WordPress. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation results in sql inject
CVE-2026-90490 | lenve vhr 1.0-SNAPSHOT MailReceiver deserialization
A vulnerability has been found in lenve vhr 1.0-SNAPSHOT and classified as critical. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. This vulnerability is repor
CVE-2026-62420 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration authorization (Nessus ID 335303)
A vulnerability has been found in Canonical LXD up to 5.0.7/5.21.5/6.9 and classified as very critical. The affected element is an unknown function of the component Instance Migration. Performing a manipulation results in authorization bypa
CVE-2026-63299 | Canonical LXD up to 5.0.7/5.21.5/6.9 Volume Operations storagePoolVolumeTypePostMove authorization
A vulnerability was found in Canonical LXD up to 5.0.7/5.21.5/6.9. It has been classified as problematic. Impacted is the function storagePoolVolumeTypePostMove of the component Volume Operations. Performing a manipulation results in author
CVE-2026-18888 | MongoDB BI Connector ODBC Driver up to 1.4.8 buffer overflow (Nessus ID 343472)
A vulnerability categorized as problematic has been discovered in MongoDB BI Connector ODBC Driver up to 1.4.8. The impacted element is an unknown function. Such manipulation leads to buffer overflow. This vulnerability is traded as CVE-202
CVE-2026-19001 | MongoDB BI Connector ODBC Driver up to 1.4.8 memory corruption
A vulnerability was found in MongoDB BI Connector ODBC Driver up to 1.4.8. It has been rated as very critical. The affected element is an unknown function. This manipulation causes memory corruption. This vulnerability appears as CVE-2026-1
CVE-2026-16033 | Canonical LXD up to 4.0.11/5.0.7 Image Metadata Template path traversal (Nessus ID 335300)
A vulnerability described as very critical has been identified in Canonical LXD up to 4.0.11/5.0.7. This affects an unknown function of the component Image Metadata Template. Executing a manipulation can lead to path traversal. The identifi
CVE-2026-63294 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Symlink backup.yaml symlink
A vulnerability categorized as very critical has been discovered in Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9. Affected by this issue is some unknown functionality of the file backup.yaml of the component Symlink Handler. Executing a mani
CVE-2026-63298 | Canonical LXD up to 4.0.11/5.0.7/5.21.5 Configuration lxc.conf nvidia.driver.capabilities/nvidia.require.* neutralization
A vulnerability has been found in Canonical LXD up to 4.0.11/5.0.7/5.21.5 and classified as very critical. This issue affects some unknown processing of the file lxc.conf of the component Configuration Handler. Performing a manipulation of
CVE-2026-63297 | Canonical LXD up to 5.0.7/5.21.5 toctou
A vulnerability, which was classified as problematic, was found in Canonical LXD up to 5.0.7/5.21.5. This vulnerability affects unknown code. Such manipulation leads to time-of-check time-of-use. This vulnerability is documented as CVE-2026
CVE-2026-63296 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration authorization
A vulnerability, which was classified as problematic, has been found in Canonical LXD up to 5.0.7/5.21.5/6.9. This affects an unknown part of the component Instance Migration. This manipulation causes authorization bypass. This vulnerabilit
CVE-2026-63295 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Container Isolation security.idmap.isolated authorization
A vulnerability described as very critical has been identified in Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9. Affected is an unknown function of the component Container Isolation. Executing a manipulation of the argument security.idmap.iso
CVE-2026-63300 | Canonical LXD up to 5.0.7/5.21.5/6.9 Instance Migration lxd/instance_post.go instancePostMigration privileges management
A vulnerability was found in Canonical LXD up to 5.0.7/5.21.5/6.9. It has been rated as very critical. The impacted element is the function instancePostMigration of the file lxd/instance_post.go of the component Instance Migration. The mani
Update auf Chrome 153 schließt eine 0-Day-Lücke – weitere Browser sind abgesichert
In den neuen Chrome-Versionen 153.0.8010.36/37 für Windows und macOS sowie 153.0.8010.36 für Linux haben die Entwickler 230 teils kritische Schwachstellen behoben. Eine der gestopften Lücken wird laut Google bereits für Angriffe ausgenutzt.
CVE-2026-71434 | Statamic up to 5.74.2/6.24.1 unrestricted upload
A vulnerability was found in Statamic up to 5.74.2/6.24.1. It has been classified as critical. This affects an unknown function. The manipulation leads to unrestricted upload. This vulnerability is uniquely identified as CVE-2026-71434. The
CVE-2026-71435 | Statamic up to 5.74.2/6.24.1 Form Notification Email cross site scripting
A vulnerability was found in Statamic up to 5.74.2/6.24.1 and classified as problematic. Impacted is an unknown function of the component Form Notification Email. Executing a manipulation can lead to cross site scripting. This vulnerability
CVE-2026-71436 | mermaid-js Mermaid up to 10.9.7/11.16.0 XY Charts setXAxisRangeData infinite loop
A vulnerability labeled as problematic has been found in mermaid-js Mermaid up to 10.9.7/11.16.0. This affects the function setXAxisRangeData of the component XY Charts. Such manipulation leads to infinite loop. This vulnerability is refere
CVE-2026-71327 | Traefik up to 3.6.24/3.7.9 Kubernetes Gateway API Provider httproute.go race condition
A vulnerability has been found in Traefik up to 3.6.24/3.7.9 and classified as problematic. Affected by this issue is some unknown functionality of the file pkg/provider/kubernetes/gateway/httproute.go of the component Kubernetes Gateway AP
CVE-2026-64665 | Statamic up to 5.74.0/6.23.x improper authentication
A vulnerability marked as critical has been reported in Statamic up to 5.74.0/6.23.x. The affected element is an unknown function. This manipulation causes improper authentication. This vulnerability is tracked as CVE-2026-64665. The attack
CVE-2026-71324 | Traefik up to 2.11.52/3.6.23/3.7.8 Reverse Proxy improper synchronization
A vulnerability, which was classified as critical, was found in Traefik up to 2.11.52/3.6.23/3.7.8. Affected by this vulnerability is an unknown functionality of the component Reverse Proxy. The manipulation results in improper synchronizat
CVE-2026-71326 | Traefik up to 3.6.24/3.7.9 BasicAuth Middleware basic_auth.go improper authentication
A vulnerability described as critical has been identified in Traefik up to 3.6.24/3.7.9. This issue affects some unknown processing of the file pkg/middlewares/auth/basic_auth.go of the component BasicAuth Middleware. The manipulation resul
CVE-2026-71325 | Traefik up to 2.11.53/3.6.24/3.7.9 Kubernetes CRD privileges management
A vulnerability marked as problematic has been reported in Traefik up to 2.11.53/3.6.24/3.7.9. Affected by this vulnerability is an unknown functionality of the component Kubernetes CRD. The manipulation leads to improper privilege manageme
CVE-2026-83948 | Microsoft Azure CLI up to 2.2.0 command injection (Nessus ID 344810)
A vulnerability was found in Microsoft Azure CLI up to 2.2.0. It has been rated as critical. This impacts an unknown function. This manipulation causes command injection. This vulnerability appears as CVE-2026-83948. The attack may be initi
CVE-2026-87776 | compression up to 1.8.1 resource consumption (Nessus ID 344814)
A vulnerability classified as problematic was found in compression up to 1.8.1. This vulnerability affects unknown code. Such manipulation leads to resource consumption. This vulnerability is documented as CVE-2026-87776. The attack can be
CVE-2026-79591 | libxls 1.6.3 xls_getCSS use after free (Nessus ID 344813)
A vulnerability was found in libxls 1.6.3. It has been rated as critical. Affected by this issue is the function xls_getCSS. The manipulation leads to use after free. This vulnerability is uniquely identified as CVE-2026-79591. The attack i
CVE-2026-79592 | libxls 1.6.3 xls_dumpSummary out-of-bounds (Nessus ID 344812)
A vulnerability, which was classified as problematic, has been found in libxls 1.6.3. The affected element is the function xls_dumpSummary. The manipulation leads to out-of-bounds read. This vulnerability is documented as CVE-2026-79592. Th
CVE-2026-69522 | Microsoft Visual Studio up to Visual Studio 2026 buffer overflow (Nessus ID 344819 / WID-SEC-2026-3242)
A vulnerability described as critical has been identified in Microsoft Visual Studio. This impacts an unknown function. The manipulation results in buffer overflow. This vulnerability was named CVE-2026-69522. The attack may be performed fr
CVE-2026-66304 | Microsoft Skype for Business Server 2015 CU13/2019 CU8/Subscription Edition CU1 server-side request forgery (Nessus ID 344822)
A vulnerability was found in Microsoft Skype for Business Server 2015 CU13/2019 CU8/Subscription Edition CU1. It has been classified as problematic. This affects an unknown part. This manipulation causes server-side request forgery. This vu
CVE-2026-62886 | Microsoft .NET/Visual Studio up to 18.8 integer overflow (Nessus ID 344819 / WID-SEC-2026-2761)
A vulnerability was found in Microsoft .NET and Visual Studio 10.0/8.0/9.0/17.14/18.8 and classified as problematic. This affects an unknown function. Such manipulation leads to integer overflow. This vulnerability is documented as CVE-2026
CVE-2026-77490 | Microsoft Edge up to 151.0.4129.86 cross site scripting (Nessus ID 344898)
A vulnerability described as problematic has been identified in Microsoft Edge. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability is handled as CVE-2026-77490. The attack
CVE-2026-87491 | Google Chrome up to 152.0.7977.82 V8 out-of-bounds write (Nessus ID 344899)
A vulnerability has been found in Google Chrome and classified as critical. This vulnerability affects unknown code of the component V8. This manipulation causes out-of-bounds write. This vulnerability appears as CVE-2026-87491. The attack
CVE-2026-84939 | Apache FreeMarker path traversal (Nessus ID 344903)
A vulnerability has been found in Apache FreeMarker and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal. This vulnerability is listed as CVE-2026-84939. The attack
CVE-2026-89259 | gohugoio Hugo up to 0.164.x Build Process hugo.toml permission (Nessus ID 344902)
A vulnerability was found in gohugoio Hugo up to 0.164.x. It has been declared as critical. This impacts an unknown function of the file hugo.toml of the component Build Process. Such manipulation leads to permission issues. This vulnerabil
CVE-2026-73077 | Vim up to 9.2.0838 Filetype Plugins runtime/ftplugin/sh.vim fnameescape os command injection (Nessus ID 341579 / WID-SEC-2026-2513)
A vulnerability was found in Vim up to 9.2.0838. It has been classified as problematic. The impacted element is the function fnameescape of the file runtime/ftplugin/sh.vim of the component Filetype Plugins. Performing a manipulation result
CVE-2026-73087 | amir20 Dozzle up to 10.6.14 SSRF Guard webhook.go isBlockedIP server-side request forgery
A vulnerability was found in amir20 Dozzle up to 10.6.14. It has been declared as critical. The affected element is the function isBlockedIP of the file internal/notification/dispatcher/webhook.go of the component SSRF Guard. Such manipulat
CVE-2026-73086 | ai nanoid up to 3.3.11/5.1.10 Fill Pool index.js size integer overflow
A vulnerability was found in ai nanoid up to 3.3.11/5.1.10. It has been classified as critical. Impacted is the function nanoid of the file index.js of the component Fill Pool. This manipulation of the argument size causes integer overflow.
CVE-2026-73085 | advplyr Audiobookshelf up to 2.35.x TokenManager TokenManager.js jwtAuthCheck improper authentication
A vulnerability categorized as critical has been discovered in advplyr Audiobookshelf up to 2.35.x. Impacted is the function jwtAuthCheck of the file server/auth/TokenManager.js of the component TokenManager. Such manipulation leads to impr
CVE-2026-73084 | Activepieces up to 0.82.x OAuth Callback Endpoint code cross site scripting (CNNVD-2026-99290535)
A vulnerability was found in Activepieces up to 0.82.x. It has been rated as problematic. This issue affects some unknown processing of the component OAuth Callback Endpoint. This manipulation of the argument code causes cross site scriptin
CVE-2026-73083 | Activepieces up to 0.79.x Sandbox importFresh privileges management
A vulnerability was found in Activepieces up to 0.79.x. It has been declared as critical. This vulnerability affects the function importFresh of the component Sandbox. The manipulation results in improper privilege management. This vulnerab
CVE-2026-73081 | Activepieces up to 0.79.x Code Compilation Pipeline os command injection
A vulnerability was found in Activepieces up to 0.79.x and classified as critical. Affected by this issue is some unknown functionality of the component Code Compilation Pipeline. Executing a manipulation can lead to os command injection. T
CVE-2026-73082 | Activepieces up to 0.81.x Validate Agent MCP Tool server-side request forgery
A vulnerability was found in Activepieces up to 0.81.x. It has been classified as critical. This affects an unknown part of the component Validate Agent MCP Tool. The manipulation leads to server-side request forgery. This vulnerability is
CVE-2026-47704 | baptisteArno Typebot up to 3.16.x Webhook Resume access control
A vulnerability identified as problematic has been detected in baptisteArno Typebot up to 3.16.x. Affected by this vulnerability is an unknown functionality of the component Webhook Resume Handler. This manipulation causes improper access c
CVE-2026-48483 | baptisteArno Typebot up to 3.16.x WhatsApp Status Forwarding server-side request forgery
A vulnerability labeled as critical has been found in baptisteArno Typebot up to 3.16.x. Affected by this issue is some unknown functionality of the component WhatsApp Status Forwarding. Such manipulation leads to server-side request forger
CVE-2026-73078 | Vim up to 9.2.0839 Netrw Plugin netrwPlugin.vim s:NetrwBookmarkMenu/s:NetrwTgtMenu/netrw#MakeTgt os command injection (Nessus ID 341579 / WID-SEC-2026-2513)
A vulnerability, which was classified as problematic, has been found in Vim up to 9.2.0839. This vulnerability affects the function s:NetrwBookmarkMenu/s:NetrwTgtMenu/netrw#MakeTgt of the file runtime/plugin/netrwPlugin.vim of the component
CVE-2026-73080 | SeaweedFS up to 4.23 gRPC Remote Storage volume_grpc_remote.go VolumeServer.FetchAndWriteNeedle server-side request forgery
A vulnerability was found in SeaweedFS up to 4.23. It has been declared as problematic. This affects the function VolumeServer.FetchAndWriteNeedle of the file weed/server/volume_grpc_remote.go of the component gRPC Remote Storage. Executing