CVE-2019-18285: Schwachstellen-Eintrag (NVD)
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI communication between the client and the Application Server is unencrypted. An attacker with access to the communication channel can read credentials of a valid user. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2022-44254 | TOTOLINK LR350 9.3.5u.6369_B20220309 setSmsCfg buffer overflow (EUVD-2022-47203)
A vulnerability classified as critical has been found in TOTOLINK LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setSmsCfg. The manipulation leads to buffer overflow. This vulnerability is listed as CVE-2022-44254. The
CVE-2022-44253 | TOTOLINK LR350 9.3.5u.6369_B20220309 setDiagnosisCfg via improper authentication (EUVD-2022-47202)
A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Impacted is the function setDiagnosisCfg. Such manipulation of the argument via leads to improper authentication. This vulnerability is traded as
CVE-2022-44252 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUploadSetting FileName command injection (EUVD-2022-47201)
A vulnerability described as critical has been identified in TOTOLINK NR1800X 9.1.0u.6279_B20210910. This affects the function setUploadSetting. Executing a manipulation of the argument FileName can lead to command injection. This vulnerabi
CVE-2022-44251 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUssd ussd command injection (EUVD-2022-47200)
A vulnerability marked as critical has been reported in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function setUssd. Performing a manipulation of the argument ussd results in command injection. This vulnerability
CVE-2026-65017 | Apache Airflow Config API information disclosure
A vulnerability labeled as problematic has been found in Apache Airflow. Affected is an unknown function of the component Config API. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is C
CVE-2026-67587 | Apache Airflow deserialization
A vulnerability identified as critical has been detected in Apache Airflow. This impacts an unknown function. Performing a manipulation results in deserialization. This vulnerability was named CVE-2026-67587. The attack may be initiated rem
CVE-2026-54183 | Apache Airflow information disclosure (EUVD-2026-57310)
A vulnerability categorized as problematic has been discovered in Apache Airflow. This affects an unknown function. Such manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2026-54183. The attack c
CVE-2026-59242 | Apache Airflow XCom deserialize endpoint deserialization
A vulnerability was found in Apache Airflow. It has been rated as critical. The impacted element is an unknown function of the component XCom deserialize endpoint. This manipulation causes deserialization. This vulnerability is handled as C
CVE-2026-59244 | Apache Airflow Secrets masker information disclosure (EUVD-2026-57316)
A vulnerability was found in Apache Airflow. It has been declared as problematic. The affected element is an unknown function of the component Secrets masker. The manipulation results in information disclosure. This vulnerability is known a
CVE-2026-58076 | Apache Airflow Exception Deserialization BaseSerialization.deserialize deserialization (EUVD-2026-57315)
A vulnerability classified as critical has been found in Apache Airflow. Affected is the function BaseSerialization.deserialize of the component Exception Deserialization. The manipulation leads to deserialization. This vulnerability is lis
CVE-2026-67260 | Apache Airflow Scheduler next_kwargs deserialization
A vulnerability was found in Apache Airflow. It has been classified as critical. Impacted is an unknown function of the component Scheduler. The manipulation of the argument next_kwargs leads to deserialization. This vulnerability is traded
CVE-2026-18708 | MongoDB up to 7.0.39/8.0.28/8.3.7 JavaScript Scripting Engine code injection
A vulnerability, which was classified as problematic, was found in MongoDB up to 7.0.39/8.0.28/8.3.7. The affected element is an unknown function of the component JavaScript Scripting Engine. Such manipulation leads to code injection. This
CVE-2026-68868 | Apache Airflow Secret Manager Backend privileges management
A vulnerability identified as problematic has been detected in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Secret Manager Backend. Performing a manipulation results in improper privilege manag
CVE-2026-18706 | MongoDB Server up to 8.3.7 GraphLookup Aggregation Stage use after free
A vulnerability has been found in MongoDB Server up to 8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component GraphLookup Aggregation Stage. The manipulation leads to use after free. This
CVE-2026-18709 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Transaction Coordinator behavioral workflow
A vulnerability described as very critical has been identified in MongoDB Server up to 7.0.39/8.0.28/8.3.7. This affects an unknown part of the component Transaction Coordinator. Executing a manipulation can lead to enforcement of behaviora
CVE-2026-18707 | MongoDB up to 8.3.7 Aggregation assertion (Nessus ID 343459)
A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. The affected element is an unknown function of the component Aggregation. The manipulation leads to reachable assertion. This vulnerability is uniquely identifi
CVE-2026-18701 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Subsystem denial of service
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component Query Subsystem. Such manipulation leads to denial of service. This vulnerab
CVE-2026-18705 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Atlas Vector Search privileges management
A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as problematic. The impacted element is an unknown function of the component Atlas Vector Search. Performing a manipulation results in improper privil
CVE-2026-18704 | MongoDB up to 8.3.7 Aggregation Framework improper authorization
A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. Affected by this issue is some unknown functionality of the component Aggregation Framework. Performing a manipulation results in improper authorization. This v
CVE-2026-18700 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Geospatial Validation use after free
A vulnerability labeled as problematic has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Geospatial Validation. Such manipulation leads to use after free.
CVE-2026-18698 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 improper authorization
A vulnerability identified as very critical has been detected in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. This manipulation causes improper authorization. This vulnerability appears as CVE-2026-18698. The a
CVE-2026-18696 | MongoDB up to 7.0.39/8.0.28/8.3.7 Authorization Check applyOps improper authorization
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been rated as critical. This affects the function applyOps of the component Authorization Check. The manipulation leads to improper authorization. This vulnerability is
CVE-2026-18697 | MongoDB up to 7.0.39/8.0.28/8.3.7 Aggregation Framework denial of service
A vulnerability categorized as problematic has been discovered in MongoDB up to 7.0.39/8.0.28/8.3.7. This impacts an unknown function of the component Aggregation Framework. The manipulation results in denial of service. This vulnerability
CVE-2026-18699 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Planner denial of service
A vulnerability classified as problematic has been found in MongoDB up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Query Planner. Performing a manipulation results in denial of service
CVE-2026-18702 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Diagnostic Logging improper authorization
A vulnerability classified as critical was found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this issue is some unknown functionality of the component Diagnostic Logging. Executing a manipulation can lead to improper authorizat
CVE-2026-18703 | MongoDB Server up to 8.3.7 certificate validation
A vulnerability, which was classified as problematic, was found in MongoDB Server up to 8.3.7. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper certificate validation. This vulnerabil
CVE-2022-44249 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 UploadFirmwareFile FileName command injection (EUVD-2022-47198)
A vulnerability identified as critical has been detected in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected is the function UploadFirmwareFile. This manipulation of the argument FileName causes command injection. The identification of this
CVE-2022-44250 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setOpModeCfg Hostname command injection (EUVD-2022-47199)
A vulnerability labeled as critical has been found in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this vulnerability is the function setOpModeCfg. Such manipulation of the argument Hostname leads to command injection. This vulnerabi
CVE-2022-44236 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 weak password (EUVD-2022-47186)
A vulnerability classified as critical has been found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. Impacted is an unknown function. This manipulation causes weak password requirements. This vulnerability is registered as CVE-2022-44236
Detecting and Containing CVE-2026-19490: A Defender's Checklist for NetScaler SAML Bypass
Detecting and Containing CVE-2026-19490: A Defender's Checklist for NetScaler SAML Bypass Most authentication bypasses announce themselves through failed logins. CVE-2026-19490 does the opposite. An attacker who exploits it produces a
CVE-2022-44235 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 cross site scripting (EUVD-2022-47185)
A vulnerability was found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting. This vulnerability
CVE-2022-44232 | libming 0.4.8 decompile.c getInt denial of service (EUVD-2022-47182)
A vulnerability was found in libming 0.4.8. It has been classified as problematic. The affected element is the function getInt of the file decompile.c. The manipulation leads to denial of service. This vulnerability is traded as CVE-2022-44
CVE-2022-44216 | Gnuboard 5.5.4/5.5.5 Change Password permission (EUVD-2022-47166)
A vulnerability was found in Gnuboard 5.5.4/5.5.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. Such manipulation leads to permission issues. This vulnerabil
CVE-2022-44215 | Titan FTP Server up to 19.0 redirect (EUVD-2022-47165)
A vulnerability classified as problematic was found in Titan FTP Server up to 19.0. This issue affects some unknown processing. The manipulation results in open redirect. This vulnerability is identified as CVE-2022-44215. The attack can on
CVE-2022-44213 | ZKTeco ZKBio ECO ADMS up to 3.1-164 cross site scripting (EUVD-2022-47163)
A vulnerability was found in ZKTeco ZKBio ECO ADMS up to 3.1-164 and classified as problematic. This affects an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44213. Th
CVE-2022-44212 | GL.iNet Goodcloud 1.0 Admin Panel access control (EUVD-2022-47162)
A vulnerability labeled as critical has been found in GL.iNet Goodcloud 1.0. This issue affects some unknown processing of the component Admin Panel. Such manipulation leads to improper access controls. This vulnerability is listed as CVE-2
CVE-2022-44211 | GL.iNet Goodcloud 1.1 Setting access control (EUVD-2022-47161)
A vulnerability identified as critical has been detected in GL.iNet Goodcloud 1.1. This vulnerability affects unknown code of the component Setting Handler. This manipulation causes improper access controls. This vulnerability is tracked as
CVE-2022-44201 | D-Link DIR823G 1.02B05 command injection (EUVD-2022-47151)
A vulnerability was found in D-Link DIR823G 1.02B05 and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to command injection. The identification of this vulnerability is CVE-20
CVE-2022-44200 | Netgear R7000P 1.3.0.8/1.3.1.64 stamode_dns1_pri/stamode_dns1_sec buffer overflow (EUVD-2022-47150)
A vulnerability, which was classified as critical, was found in Netgear R7000P 1.3.0.8/1.3.1.64. Affected is an unknown function. Such manipulation of the argument stamode_dns1_pri/stamode_dns1_sec leads to buffer overflow. This vulnerabili
CVE-2022-44199 | Netgear R7000P 1.3.1.64 openvpn_server_ip buffer overflow (EUVD-2022-47149)
A vulnerability, which was classified as critical, has been found in Netgear R7000P 1.3.1.64. This impacts an unknown function. This manipulation of the argument openvpn_server_ip causes buffer overflow. This vulnerability is handled as CVE
CVE-2022-44198 | Netgear R7000P 1.3.1.64 openvpn_push1 buffer overflow (EUVD-2022-47148)
A vulnerability classified as critical was found in Netgear R7000P 1.3.1.64. This affects an unknown function. The manipulation of the argument openvpn_push1 results in buffer overflow. This vulnerability is known as CVE-2022-44198. Access
CVE-2022-44197 | Netgear R7000P 1.3.0.8 openvpn_server_ip buffer overflow (EUVD-2022-47147)
A vulnerability classified as critical has been found in Netgear R7000P 1.3.0.8. The impacted element is an unknown function. The manipulation of the argument openvpn_server_ip leads to buffer overflow. This vulnerability is traded as CVE-2
CVE-2022-44196 | Netgear R7000P 1.3.0.8 openvpn_push1 buffer overflow (EUVD-2022-47146)
A vulnerability described as critical has been identified in Netgear R7000P 1.3.0.8. The affected element is an unknown function. Executing a manipulation of the argument openvpn_push1 can lead to buffer overflow. This vulnerability appears
CVE-2022-44194 | Netgear R7000P 1.3.0.8 apmode_dns1_pri/apmode_dns1_sec buffer overflow (EUVD-2022-47144)
A vulnerability marked as critical has been reported in Netgear R7000P 1.3.0.8. Impacted is an unknown function. Performing a manipulation of the argument apmode_dns1_pri/apmode_dns1_sec results in buffer overflow. This vulnerability is rep
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance Software Remote Access SSL VPN service denial of service
A vulnerability was found in Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software and classified as critical. Affected by this issue is some unknown functionality of the component Remote Acc
CVE-2026-69116 | xpf0000 FlyEnv up to 4.17.x Html Sanitization injection
A vulnerability, which was classified as problematic, has been found in xpf0000 FlyEnv up to 4.17.x. This vulnerability affects unknown code of the component Html Sanitization. Performing a manipulation results in injection. This vulnerabil
CVE-2026-69114 | Spacebar Server Message Deletion Handlers permission
A vulnerability classified as problematic was found in Spacebar Server. This affects an unknown part of the component Message Deletion Handlers. Such manipulation leads to permission issues. This vulnerability is traded as CVE-2026-69114. T
CVE-2026-71967 | OP-TEE OS up to 4.10.0 Widevine PTA is_user_ta_ctx null pointer dereference
A vulnerability was found in OP-TEE OS up to 4.10.0. It has been declared as critical. Affected is the function is_user_ta_ctx of the component Widevine PTA. Such manipulation leads to null pointer dereference. This vulnerability is listed
CVE-2026-18694 | MongoDB up to 7.0.39/8.0.28/8.3.7 Geospatial Query Processing memory corruption
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been declared as critical. The impacted element is an unknown function of the component Geospatial Query Processing. Executing a manipulation can lead to memory corrupti
CVE-2026-18695 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 denial of service
A vulnerability, which was classified as problematic, has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. Performing a manipulation results in denial of service. This vulnerability is identified as C
CVE-2026-69112 | Hugging Face Accelerate up to 1.14.0 Sharded Checkpoint Index weight_map path traversal
A vulnerability, which was classified as critical, was found in Hugging Face Accelerate up to 1.14.0. Affected by this issue is the function load_checkpoint_in_model/load_checkpoint_and_dispatch of the component Sharded Checkpoint Index. Su
CVE-2026-18691 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Intra-cluster Connection Setup improper authentication
A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as critical. This issue affects some unknown processing of the component Intra-cluster Connection Setup. This manipulation causes improper authenticat
CVE-2026-18692 | MongoDB Server up to 8.3.7 Timeseries use after free
A vulnerability was found in MongoDB Server up to 8.3.7 and classified as critical. Impacted is an unknown function of the component Timeseries Handler. Such manipulation leads to use after free. This vulnerability is listed as CVE-2026-186
CVE-2026-18693 | MongoDB up to 7.0.39/8.0.28/8.3.7 Timeseries memory corruption
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been classified as critical. The affected element is an unknown function of the component Timeseries Handler. Performing a manipulation results in memory corruption. Thi
CVE-2026-76460 | Cisco Identity Services Engine Software API improper authentication
A vulnerability classified as very critical was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. This affects an unknown function of the component API. Such manipulation leads to improper authentication.
CVE-2026-68772 | ZenML up to 0.94.6 CloudpickleMaterializer cloudpickle_materializer.py cloudpickle.load deserialization
A vulnerability was found in ZenML up to 0.94.6. It has been rated as problematic. Impacted is the function cloudpickle.load of the file cloudpickle_materializer.py of the component CloudpickleMaterializer. Performing a manipulation results
CVE-2026-5855 | Contiki-NG LwM2M TLV parser lwm2m-tlv.c lwm2m_tlv_read length out-of-bounds
A vulnerability, which was classified as very critical, has been found in Contiki-NG. This impacts the function lwm2m_tlv_read of the file os/services/lwm2m/lwm2m-tlv.c of the component LwM2M TLV parser. Performing a manipulation of the arg
CVE-2026-5856 | Contiki-NG mDNS Resolver resolv.c skip_name out-of-bounds
A vulnerability was found in Contiki-NG. It has been classified as critical. This affects the function skip_name of the file os/services/resolv/resolv.c of the component mDNS Resolver. This manipulation causes out-of-bounds read. The identi
CVE-2026-53977 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Route bootstrap-runtime.js improper authentication
A vulnerability was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. It has been rated as critical. The affected element is an unknown function of the file bootstrap-runtime.js of the component Route Handler. The manipulation leads to i
CVE-2026-53975 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Command Execution /api/fs/exec spawn os command injection
A vulnerability, which was classified as critical, was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. This vulnerability affects the function spawn of the file /api/fs/exec of the component Command Execution. The manipulation results