🎯 CVE-2019-16518
📄 .md Alle CVEs anzeigen ✕

CVE-2019-16518: Schwachstellen-Eintrag (NVD)

An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.

Klassifikation & Betroffenheit:
vandyvape swell_kit_mod_firmware 2.0.2
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 4.3
AV · Angriffsvektor Benachbart
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Keine
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Veröffentlicht:23.09.2019
Aktualisiert:17.06.2026 02:22
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
4 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 105 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.868 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-17
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
8.2 HIGH
EPSS 29%
CVE-2022-44345 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44345 | Sanitization Management System 1.0 view_quote ID sql injection (EUVD-2022-47290)

A vulnerability has been found in Sanitization Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-sms/admin/?page=quotes/view_quote. The manipulation of the argument ID leads to sql in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.7%
CVE-2022-44343 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44343 | ZhongBangKeJi CRMEB 4.4.4 information disclosure (EUVD-2022-47288)

A vulnerability was found in ZhongBangKeJi CRMEB 4.4.4. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2022-44343.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2022-44321 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44321 | PicoC 3.2.2 lex.c LexSkipComment heap-based overflow (Issue 37 / EUVD-2022-47266)

A vulnerability was found in PicoC 3.2.2. It has been classified as critical. Affected is the function LexSkipComment of the file lex.c. The manipulation leads to heap-based buffer overflow. This vulnerability is listed as CVE-2022-44321. T

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2022-44320 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44320 | PicoC 3.2.2 expression.c ExpressionCoerceFP heap-based overflow (Issue 37 / EUVD-2022-47265)

A vulnerability marked as critical has been reported in PicoC 3.2.2. This affects the function ExpressionCoerceFP of the file expression.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is known as CVE-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2025-35973 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-35973 | Intel Processors Kernel/Hypervisor privileges management (Nessus ID 346889)

A vulnerability was found in Intel Processors. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Kernel/Hypervisor. This manipulation causes improper privilege management. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 2.3%
CVE-2026-20917 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-20917 | Intel Processors Hypervisor/Kernel information disclosure (Nessus ID 346889)

A vulnerability was found in Intel Processors. It has been classified as problematic. This affects an unknown part of the component Hypervisor/Kernel. The manipulation leads to information disclosure. This vulnerability is traded as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.1%
CVE-2025-31936 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31936 | Intel Xeon 6 processors SMM/TDX privileges management (Nessus ID 346889 / WID-SEC-2026-2772)

A vulnerability marked as problematic has been reported in Intel Xeon 6 processors. Impacted is an unknown function of the component SMM/TDX. The manipulation leads to improper privilege management. This vulnerability is uniquely identified

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2025-31938 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-31938 | Intel Xeon 6 Scalable processors TDX access control (Nessus ID 346889)

A vulnerability was found in Intel Xeon 6 Scalable processors. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component TDX. The manipulation results in improper access controls. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2026-70351 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-70351 | Microsoft WebP Image Extension prior 1.2.31.0 integer overflow (Nessus ID 346896)

A vulnerability marked as critical has been reported in Microsoft WebP Image Extension. Affected by this vulnerability is an unknown functionality. This manipulation causes integer overflow. This vulnerability appears as CVE-2026-70351. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 25%
CVE-2026-15913 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15913 | Fortra GoAnywhere MFT up to 7.10.1 path traversal (EUVD-2026-75175 / Nessus ID 346899)

A vulnerability classified as problematic was found in Fortra GoAnywhere MFT up to 7.10.1. This affects an unknown part. The manipulation results in path traversal. This vulnerability was named CVE-2026-15913. The attack may be performed fr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-84386 💻 Lokal 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2026-84386 | Fortinet FortiClientWindows up to 7.2.15/7.4.7 access control (Nessus ID 346901)

A vulnerability marked as problematic has been reported in Fortinet FortiClientWindows up to 7.2.15/7.4.7. This affects an unknown function. The manipulation leads to improper access controls. This vulnerability is referenced as CVE-2026-84

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2022-44319 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44319 | PicoC 3.2.2 cstdlib/string.c StdioBasePrintf heap-based overflow (Issue 37 / EUVD-2022-47264)

A vulnerability was found in PicoC 3.2.2 and classified as critical. This impacts the function StdioBasePrintf in the library cstdlib/string.c. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is tracked a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.2%
CVE-2022-44318 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44318 | PicoC 3.2.2 cstdlib/string.c StringStrcat heap-based overflow (Issue 37 / EUVD-2022-47263)

A vulnerability has been found in PicoC 3.2.2 and classified as critical. This affects the function StringStrcat in the library cstdlib/string.c. Performing a manipulation results in heap-based buffer overflow. This vulnerability is identif

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2022-44316 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44316 | PicoC 3.2.2 lex.c LexGetStringConstant heap-based overflow (Issue 37 / EUVD-2022-47261)

A vulnerability, which was classified as critical, has been found in PicoC 3.2.2. The affected element is the function LexGetStringConstant of the file lex.c. This manipulation causes heap-based buffer overflow. The identification of this v

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.9%
CVE-2022-44317 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44317 | PicoC 3.2.2 cstdlib/stdio.c StdioOutPutc heap-based overflow (Issue 37 / EUVD-2022-47262)

A vulnerability, which was classified as critical, was found in PicoC 3.2.2. The impacted element is the function StdioOutPutc in the library cstdlib/stdio.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is refe

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-89813 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89813 | Linux Kernel up to 7.2.4 KIQ ring drm/amdgpu amdgpu_device_pre_asic_reset race condition (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4 and classified as critical. Affected by this issue is the function amdgpu_device_pre_asic_reset of the file drm/amdgpu of the component KIQ ring. Such manipulation leads to race conditio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.2%
CVE-2026-89812 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89812 | Linux Kernel MES ring amdgpu_device_pre_asic_reset infinite loop (WID-SEC-2026-3438)

A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function amdgpu_device_pre_asic_reset of the component MES ring. This manipulation causes infinite loop. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.8%
CVE-2026-89811 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89811 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 amdkfd/MES Queue Management amdkfd evict_process_queues_cpsch/suspend_queues race condition (WID-SEC-2026-3438)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This impacts the function evict_process_queues_cpsch/suspend_queues of the file drivers/gpu/drm/amd/amdkfd of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.8%
CVE-2026-89810 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89810 | Linux Kernel up to 6.18.50/7.2.4 amdkfd drm/amdkfd svm_migrate_copy_to_ram allocation of resources (WID-SEC-2026-3438)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. Impacted is the function svm_migrate_copy_to_ram of the file drm/amdkfd of the component amdkfd. The manipulation results in allocation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.7%
CVE-2026-89808 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89808 | Linux Kernel up to 6.18.50/7.2.4 amdkfd svm_migrate_copy_memory_gart uninitialized variable (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4. It has been rated as very critical. This issue affects the function svm_migrate_copy_memory_gart of the file drivers/gpu/drm/amd/amdkfd of the component amdkfd. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.5%
CVE-2026-89809 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89809 | Linux Kernel up to 7.2.4/7.3-rc1 amdkfd mqds pqm_debugfs_mqds pqn null pointer dereference (WID-SEC-2026-3438)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 7.2.4/7.3-rc1. Affected is the function pqm_debugfs_mqds of the file /sys/kernel/debug/kfd/mqds of the component amdkfd. The manipulation of the argument

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.2%
CVE-2026-89807 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89807 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 amdkfd amdkfd.c create_queue_cpsch/create_queue_nocpsch null pointer dereference (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4. It has been declared as problematic. This vulnerability affects the function create_queue_cpsch/create_queue_nocpsch of the file drivers/gpu/drm/amd/amdkfd/amdkfd.c of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.8%
CVE-2026-89806 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89806 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 Sysfb drm/sysfb integer overflow (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. It has been classified as very critical. This affects an unknown part of the file drm/sysfb of the component Sysfb. Performing a manipulation results in integer overflow

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.9%
CVE-2022-44315 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44315 | PicoC 3.2.2 expression.c ExpressionAssign heap-based overflow (Issue 37 / EUVD-2022-47260)

A vulnerability classified as critical was found in PicoC 3.2.2. Impacted is the function ExpressionAssign of the file expression.c. The manipulation results in heap-based buffer overflow. This vulnerability was named CVE-2022-44315. The at

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.1%
CVE-2022-44314 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44314 | PicoC 3.2.2 cstdlib/string.c StringStrncpy heap-based overflow (Issue 37 / EUVD-2022-47259)

A vulnerability classified as critical has been found in PicoC 3.2.2. This issue affects the function StringStrncpy in the library cstdlib/string.c. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2022-44313 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44313 | PicoC 3.2.2 expression.c ExpressionCoerceUnsignedInteger heap-based overflow (Issue 37 / EUVD-2022-47258)

A vulnerability labeled as critical has been found in PicoC 3.2.2. Affected by this issue is the function ExpressionCoerceUnsignedInteger of the file expression.c. Such manipulation leads to heap-based buffer overflow. This vulnerability is

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2022-44312 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44312 | PicoC 3.2.2 expression.c ExpressionCoerceInteger heap-based overflow (Issue 37 / EUVD-2022-47257)

A vulnerability identified as critical has been detected in PicoC 3.2.2. Affected by this vulnerability is the function ExpressionCoerceInteger of the file expression.c. This manipulation causes heap-based buffer overflow. This vulnerabilit

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2022-44311 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44311 | html2xhtml 1.3 HTML File procesador.c elm_close out-of-bounds (Issue 19 / EUVD-2022-47256)

A vulnerability categorized as problematic has been discovered in html2xhtml 1.3. Affected is the function elm_close of the file procesador.c of the component HTML File Handler. The manipulation results in out-of-bounds read. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.7%
CVE-2022-44299 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44299 | SiteServerCMS 7.1.3 information disclosure (Issue 3491 / EUVD-2022-47246)

A vulnerability was found in SiteServerCMS 7.1.3 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CVE-2022-44299. The attac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20.3%
CVE-2022-44298 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44298 | SiteServer CMS 7.1.3 sql injection (Issue 3492 / EUVD-2022-47245)

A vulnerability labeled as critical has been found in SiteServer CMS 7.1.3. Impacted is an unknown function. The manipulation results in sql injection. This vulnerability is reported as CVE-2022-44298. The attacker must have access to the l

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29%
CVE-2022-44297 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44297 | SiteServer CMS 7.1.3 sql injection (Issue 3490 / EUVD-2022-47244)

A vulnerability was found in SiteServer CMS 7.1.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is reported as CVE-2022-44297. The at

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 24.2%
CVE-2022-44296 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44296 | oretnom23 Sanitization Management System 1.0 manage_remark.php ID sql injection (EUVD-2022-47243)

A vulnerability classified as critical has been found in oretnom23 Sanitization Management System 1.0. The affected element is an unknown function of the file /php-sms/admin/quotes/manage_remark.php. Performing a manipulation of the argumen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 23.4%
CVE-2022-44295 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44295 | oretnom23 Sanitization Management System 1.0 assign_team.php ID sql injection (EUVD-2022-47242)

A vulnerability described as critical has been identified in oretnom23 Sanitization Management System 1.0. Impacted is an unknown function of the file /php-sms/admin/orders/assign_team.php. Such manipulation of the argument ID leads to sql

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-34078 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

How to Protect Your Linux System from Flatpak Security Issues (2026)

Flatpak 1.18.1 patched 10 security vulnerabilities including a critical sandbox escape (CVE-2026-34078). This guide walks you through checking your Flatpak version, updating on Ubuntu, Fedora, and Arch Linux, auditing app permissions with F

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 5.7%
CVE-2026-93386 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-93386 | Google Chrome up to 153.0.8010.47 WebAppInstalls information disclosure (EUVD-2026-82490)

A vulnerability was found in Google Chrome. It has been rated as problematic. This impacts an unknown function of the component WebAppInstalls. The manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-9

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 25.6%
CVE-2026-93426 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93426 | SigNoz up to 0.141.x Query Range API sql injection (EUVD-2026-82493)

A vulnerability was found in SigNoz up to 0.141.x and classified as critical. This issue affects some unknown processing of the component Query Range API. Such manipulation leads to sql injection. This vulnerability is referenced as CVE-202

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.9%
CVE-2026-73638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73638 | Imager up to 1.034 tiff_load_ifd out-of-bounds (EUVD-2026-82491)

A vulnerability, which was classified as problematic, was found in Imager up to 1.034. This affects the function tiff_load_ifd. The manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-73638. The attack may be p

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-73639 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73639 | Imager 1.003 PNG read_direct8 buffer overflow (EUVD-2026-82492)

A vulnerability, which was classified as problematic, has been found in Imager 1.003. Affected by this issue is the function read_direct8 of the component PNG. The manipulation leads to buffer overflow. This vulnerability is uniquely identi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-16750 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-16750 | Stylemix Motors Plugin up to 1.4.120 on WordPress mvl_ajax_dealer_load_cars improper authorization (EUVD-2026-82494)

A vulnerability classified as problematic was found in Stylemix Motors Plugin up to 1.4.120 on WordPress. This impacts the function mvl_ajax_dealer_load_cars. Executing a manipulation can lead to improper authorization. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 29.7%
CVE-2026-16582 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-16582 | melograno Booking for Appointments and Events Calendar Plugin improper authorization (EUVD-2026-82495)

A vulnerability described as problematic has been identified in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.5 on WordPress. The impacted element is an unknown function. Such manipulation of the argument package-r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 24.7%
CVE-2026-14311 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-14311 | melograno Booking for Appointments and Events Calendar Plugin /users/customers/ improper authorization (EUVD-2026-82496)

A vulnerability classified as critical has been found in melograno Booking for Appointments and Events Calendar Plugin up to 2.4.4 on WordPress. This affects an unknown function of the file /users/customers/. Performing a manipulation resul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 26.5%
CVE-2023-4751 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-4751 | vim up to 9.0.1247 heap-based overflow

A vulnerability was found in vim and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is registered as CVE-2023-4751. The attac

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2021-20327 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2021-20327 | mongodb-client-encryption 1.2.0 on Node.js certificate validation

A vulnerability was found in mongodb-client-encryption 1.2.0 on Node.js and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to improper certificate validation. This vulnerability is reg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2017-7200 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2017-7200 | OpenStack Glance Image Service API v1 Portscan server-side request forgery (BID-96988)

A vulnerability classified as problematic has been found in OpenStack Glance. The affected element is an unknown function of the component Image Service API v1. This manipulation causes server-side request forgery (Portscan). This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2012-5825 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2012-5825 | Horde Kronolith 3.0.17 Portal Blocks input validation (ID 349780 / XFDB-80084)

A vulnerability described as problematic has been identified in Horde Kronolith 3.0.17. This issue affects some unknown processing of the component Portal Blocks. Such manipulation leads to improper input validation. This vulnerability is d

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2012-5825 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2012-5825 | Horde Groupware/Groupware Webmail Edition 4.0.8 Portal Blocks input validation (ID 349780 / XFDB-80084)

A vulnerability marked as problematic has been reported in Horde Groupware and Groupware Webmail Edition 4.0.8. This vulnerability affects unknown code of the component Portal Blocks. This manipulation causes improper input validation. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2023-5535 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-5535 | vim up to 9.0.1969 use after free

A vulnerability described as critical has been identified in vim. This affects an unknown part. Executing a manipulation can lead to use after free. This vulnerability is tracked as CVE-2023-5535. The attack can be launched remotely. No exp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.2%
CVE-2026-87766 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8779-2: Bubblewrap regression

USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.8%
CVE-2026-19592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure

Finding the Agent Infrastructure: What Internet Measurement Can and Cannot Say About AI Coding Tool Exposure In September 2026, researchers disclosed a class of configuration injection flaws affecting several AI coding agents, including Cla

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network control and policy enforcement. This is the second zero-day flaw

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.8 CRITICAL
EPSS 94.4%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco alerts customers to second actively exploited zero-day in as many days

Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 32.2%
CVE-2026-91843 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Check Point: Authentifizierungs-Bypass ermöglicht Root-Codeausführung per CVE-2026-91843

LONDON (IT BOLTWISE) – Eine kritische Schwachstelle in den Security Management und Log Servern von Check Point (CVE-2026-91843) kann es Angreifern ohne Login ermöglichen, Root-Code über das Netzwerk auszuführen. Check Point hat dafür einen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

<b>Windows</b> Defender: Falsche Warnung täuscht Sicherheitslücke vor - ad-hoc-news.de

Eine fehlerhafte Defender-Meldung betrifft Windows- und Server-Systeme. Microsoft bestätigt den Anzeigefehler und stellt eine Korrektur in ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
8.2 HIGH
EPSS 29.2%
CVE-2026-76423 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423

Hunting the Cisco ISE Authentication Bypass: Detection and Response for CVE-2026-76423 Vulnerability overview CVE-2026-76423 is an authentication bypass in the Cisco Identity Services Engine REST API, disclosed on 16 September 2026 with a C

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 21.5%
CVE-2026-1467 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8780-1: libsoup vulnerabilities

It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 3.6%
CVE-2019-12439 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

USN-8779-1: Bubblewrap vulnerabilities

It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.1 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61591 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.4 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 djust-org

CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.1 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-61597 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 31.2%
CVE-2026-92599 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 hapijs

CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in

joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.