CVE-2019-20667: Schwachstellen-Eintrag (NVD)
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...] Weiterlesen
Gefährliche Sicherheitslücke: Apple-Geräte lassen sich per Bluetooth kapern
Bei iPhones, iPads, Macs und anderen Apple-Geräten lässt sich ohne Zutun des Nutzers über Bluetooth Schadcode einschleusen. Neue Updates beheben das. (Sicherheitslücke, Apple) Weiterlesen
Docker Sandboxes Vulnerabilities Let Malicious Guests Escape Workspace and Access Host Files
Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could let a malicious guest environment bypass workspace isolation and access sensitive resources on the host. These flaws, identified as CVE-2026-7
CVE-2026-19774 | Linux BlueZ stack-based overflow (WID-SEC-2026-2984)
A vulnerability described as very critical has been identified in Linux BlueZ. Affected by this issue is some unknown functionality. Such manipulation leads to stack-based buffer overflow. This vulnerability is listed as CVE-2026-19774. The
CVE-2026-86107 | Arista VeloCloud/VeloCloud Gateway prior 5.2.0.0/5.2.7.0/6.1.5.0/6.4.2.0 VCMP Tunnel Protocol out-of-bounds write (WID-SEC-2026-3287)
A vulnerability was found in Arista VeloCloud and VeloCloud Gateway. It has been declared as critical. The affected element is an unknown function of the component VCMP Tunnel Protocol. The manipulation results in out-of-bounds write. This
CVE-2026-86106 | Arista VeloCloud Edge prior 5.2.0.0/5.2.7.0/6.1.5.0/6.4.2.0 privileges management (WID-SEC-2026-3287)
A vulnerability classified as very critical was found in Arista VeloCloud Edge. Impacted is an unknown function. Such manipulation leads to improper privilege management. This vulnerability is listed as CVE-2026-86106. The attack may be per
CVE-2026-77190 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F Pimsm Agent input validation (WID-SEC-2026-3287)
A vulnerability marked as critical has been reported in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. This affects an unknown part of the component Pimsm Agent. The manipulation leads to improper input validation. This vulnerability is referenc
CVE-2026-68076 | Apache Airflow Connection Test API access control (EUVD-2026-57265)
A vulnerability, which was classified as critical, has been found in Apache Airflow. This issue affects some unknown processing of the component Connection Test API. Performing a manipulation results in improper access controls. This vulner
CVE-2026-77587 | Tor Project 0.4.9.9 Conflux use after free
A vulnerability was found in Tor Project Tor 0.4.9.9. It has been rated as critical. This vulnerability affects unknown code of the component Conflux. The manipulation leads to use after free. This vulnerability is traded as CVE-2026-77587.
CVE-2026-68969 | Apache Airflow Audit Log missing encryption
A vulnerability described as problematic has been identified in Apache Airflow. Affected by this issue is some unknown functionality of the component Audit Log. The manipulation results in missing encryption of sensitive data. This vulnerab
CVE-2026-68970 | Apache Airflow Task Logs/Rendered Templates information disclosure
A vulnerability classified as problematic has been found in Apache Airflow. This affects an unknown part of the component Task Logs/Rendered Templates. This manipulation causes information disclosure. This vulnerability is tracked as CVE-20
CVE-2026-77638 | Tor Project 0.4.9.9 Rendezvous Point race condition (Nessus ID 338660)
A vulnerability labeled as very critical has been found in Tor Project Tor 0.4.9.9. The affected element is an unknown function of the component Rendezvous Point. Such manipulation leads to race condition. This vulnerability is uniquely ide
CVE-2026-68968 | Apache Airflow Backfill API authorization
A vulnerability marked as critical has been reported in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Backfill API. The manipulation leads to authorization bypass. This vulnerability is referenc
CVE-2026-77584 | torproject Tor prior 0.4.9.10 use after free (Nessus ID 338654)
A vulnerability was found in torproject Tor. It has been declared as critical. This affects an unknown part. Executing a manipulation can lead to use after free. This vulnerability appears as CVE-2026-77584. The attack may be performed from
CVE-2026-43971 | ninenines cowlib cow_link cow_link:link escape output (EUVD-2026-60573 / Nessus ID 338849)
A vulnerability, which was classified as critical, was found in ninenines cowlib. This vulnerability affects the function cow_link:link of the component cow_link. Such manipulation leads to escaping of output. This vulnerability is document
CVE-2026-74259 | Linux Kernel up to 7.1.4 cifs cifsFileInfo_put_final null pointer dereference
Further analysis revealed that this issues is a false-positive. Please take a look at the sources mentioned and consider not using this entry at all. Weiterlesen
CVE-2026-73566 | isaacs node-tar up to 7.5.20 Files Filter src/list.ts filesFilter stack-based overflow (Nessus ID 342214)
A vulnerability was found in isaacs node-tar up to 7.5.20. It has been declared as problematic. Impacted is the function filesFilter of the file src/list.ts of the component Files Filter. The manipulation results in stack-based buffer overf
CVE-2026-68971 | Apache Airflow Asset Materialization authorization
A vulnerability classified as critical was found in Apache Airflow. This vulnerability affects unknown code of the component Asset Materialization. Such manipulation leads to authorization bypass. This vulnerability is listed as CVE-2026-68
CVE-2022-44277 | Sanitization Management System 1.0 Master.php?f=delete_product sql injection (EUVD-2022-47225)
A vulnerability, which was classified as critical, was found in Sanitization Management System 1.0. This affects an unknown part of the file /php-sms/classes/Master.php?f=delete_product. Executing a manipulation can lead to sql injection. T
CVE-2022-44264 | Dentsply Sirona Sidexis up to 4.3 unquoted search path (EUVD-2022-47212)
A vulnerability, which was classified as critical, was found in Dentsply Sirona Sidexis up to 4.3. Affected by this issue is some unknown functionality. Executing a manipulation can lead to unquoted search path. This vulnerability is regist
CVE-2022-44263 | Dentsply Sirona Sidexis up to 4.3 access control (EUVD-2022-47211)
A vulnerability, which was classified as critical, has been found in Dentsply Sirona Sidexis up to 4.3. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper access controls. This vulnerab
CVE-2022-44261 | Avery Dennison Monarch Printer M9855 cross site scripting (EUVD-2022-47210)
A vulnerability labeled as problematic has been found in Avery Dennison Monarch Printer M9855. The affected element is an unknown function. Such manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-20
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek. Weiterlesen
Angriff auf Pixel-Smartphones: Modem-Sicherheitslücke wurde laut Google schon aktiv ausgenutzt – alle Infos
Google hat in dieser Woche das große Pixel Update veröffentlicht, das nicht nur viele Neuerungen auf die Pixel-Smartphones bringt, sondern auch zahlreiche Probleme behebt und Sicherheitslücken schließt. Letztes war offenbar dringend notwend
CVE-2026-73469 | Arista EOS up to 4.35.4M Unicast Reverse Path Forwarding access control (WID-SEC-2026-3287)
A vulnerability was found in Arista EOS up to 4.35.4M and classified as problematic. The affected element is an unknown function of the component Unicast Reverse Path Forwarding. Executing a manipulation can lead to improper access controls
CVE-2026-73462 | Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.1F IGMP Snooping Agent input validation (WID-SEC-2026-3287)
A vulnerability was found in Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.1F and classified as critical. Affected by this issue is some unknown functionality of the component IGMP Snooping Agent. Such manipulation leads to improper input
CVE-2026-73468 | Arista EOS up to 4.36.1F Multicast Forwarding state issue (WID-SEC-2026-3287)
A vulnerability was found in Arista EOS up to 4.32.x/4.33.8M/4.34.7.1M/4.35.5M/4.36.1F. It has been rated as critical. This impacts an unknown function of the component Multicast Forwarding. This manipulation causes state issue. This vulner
CVE-2026-73461 | Arista EOS up to 4.36.0.1F AAA improper authorization (WID-SEC-2026-3287)
A vulnerability identified as very critical has been detected in Arista EOS up to 4.36.0.1F. Affected is an unknown function of the component AAA. This manipulation causes improper authorization. This vulnerability is tracked as CVE-2026-73
CVE-2026-73460 | Arista EOS up to 4.36.1F IS-IS Graceful Restart input validation (WID-SEC-2026-3287)
A vulnerability has been found in Arista EOS up to 4.36.1F and classified as critical. This impacts an unknown function of the component IS-IS Graceful Restart. This manipulation causes improper input validation. This vulnerability is regis
CVE-2026-73459 | Arista EOS up to 4.36.1F injection (WID-SEC-2026-3287)
A vulnerability classified as critical was found in Arista EOS up to 4.36.1F. This affects an unknown function. Executing a manipulation can lead to injection. This vulnerability is registered as CVE-2026-73459. It is possible to launch the
Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication
Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products. This flaw could allow an unauthenticated rem
Critical Check Point Flaw Lets Remote Attackers Gain Root Code Execution Without Login
Check Point has issued an urgent security alert for CVE-2026-91843, a critical stack overflow vulnerability that could allow unauthenticated remote attackers to execute arbitrary code with root privileges on vulnerable Security Management,
CVE-2026-25282 | Qualcomm Snapdragon Compute up to X2 Elite out-of-bounds (EUVD-2026-81329)
A vulnerability labeled as very critical has been found in Qualcomm Snapdragon Compute up to X2 Elite. This affects an unknown function. Such manipulation leads to out-of-bounds read. This vulnerability is traded as CVE-2026-25282. An attac
CVE-2026-25281 | Qualcomm Snapdragon Compute up to X2 Elite allocation of resources (EUVD-2026-81328)
A vulnerability identified as problematic has been detected in Qualcomm Snapdragon Compute up to X2 Elite. The impacted element is an unknown function. This manipulation causes allocation of resources. This vulnerability appears as CVE-2026
CVE-2026-25280 | Qualcomm Snapdragon Compute/Snapdragon Industrial IOT up to X2 Elite memory corruption (EUVD-2026-81327)
A vulnerability categorized as very critical has been discovered in Qualcomm Snapdragon Compute and Snapdragon Industrial IOT. The affected element is an unknown function. The manipulation results in memory corruption. This vulnerability is
CVE-2026-25290 | Qualcomm Snapdragon Compute up to X2 Elite memory corruption (EUVD-2026-81332)
A vulnerability, which was classified as very critical, has been found in Qualcomm Snapdragon Compute up to X2 Elite. Affected is an unknown function. The manipulation leads to memory corruption. This vulnerability is referenced as CVE-2026
CVE-2026-25284 | Qualcomm Snapdragon Compute up to X2 Elite information disclosure (EUVD-2026-81331)
A vulnerability classified as problematic was found in Qualcomm Snapdragon Compute up to X2 Elite. This impacts an unknown function. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CV
CVE-2026-25283 | Qualcomm Snapdragon Compute up to X2 Elite buffer overflow (EUVD-2026-81330)
A vulnerability classified as very critical has been found in Qualcomm Snapdragon Compute up to X2 Elite. This affects an unknown function. Performing a manipulation results in buffer overflow. This vulnerability was named CVE-2026-25283. T
CVE-2026-87935 | ichurakov Paid Downloads Plugin up to 3.15 on WordPress /wp-admin/admin-post.php admin_request_handler unrestricted upload (EUVD-2026-81334)
A vulnerability described as critical has been identified in ichurakov Paid Downloads Plugin up to 3.15 on WordPress. Affected is the function admin_request_handler of the file /wp-admin/admin-post.php. Executing a manipulation can lead to
CVE-2026-25294 | Qualcomm Snapdragon CCW up to XRV9209 resource consumption (EUVD-2026-81333)
A vulnerability marked as critical has been reported in Qualcomm Snapdragon CCW, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon MC, Snapdragon Mobile and Snapdragon WBC. This impacts an unknown function. Performing a manipulation
CVE-2026-87796 | sh1zen Multi Uploader for Gravity Forms Plugin up to 1.1.9 on WordPress move_file unrestricted upload (EUVD-2026-81335)
A vulnerability classified as critical has been found in sh1zen Multi Uploader for Gravity Forms Plugin up to 1.1.9 on WordPress. Affected by this vulnerability is the function move_file. The manipulation leads to unrestricted upload. This
CVE-2026-73457 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F gRPC Network Packet Sampling Interface information disclosure (WID-SEC-2026-3287)
A vulnerability, which was classified as problematic, was found in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. Affected is an unknown function of the component gRPC Network Packet Sampling Interface. The manipulation results in information di
CVE-2026-73456 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F gRPC Network Packet Sampling Interface code injection (WID-SEC-2026-3287)
A vulnerability described as very critical has been identified in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. The affected element is an unknown function of the component gRPC Network Packet Sampling Interface. Such manipulation leads to code
CVE-2026-73455 | Arista EOS up to 4.36.0.1F OSPFv3 input validation (WID-SEC-2026-3287)
A vulnerability identified as critical has been detected in Arista EOS up to 4.32.x/4.33.8M/4.34.6M/4.35.4M/4.36.0.1F. Affected by this vulnerability is an unknown functionality of the component OSPFv3. Performing a manipulation results in
CVE-2026-73453 | Arista EOS up to 4.36.1F P4Runtime code injection (WID-SEC-2026-3287)
A vulnerability has been found in Arista EOS up to 4.36.1F and classified as very critical. Impacted is an unknown function of the component P4Runtime. Performing a manipulation results in code injection. This vulnerability is reported as C
CVE-2022-44260 | TOTOLINK LR350 9.3.5u.6369_B20220309 setIpPortFilterRules sPort/ePort buffer overflow (EUVD-2022-47209)
A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309. It has been classified as critical. This impacts the function setIpPortFilterRules. The manipulation of the argument sPort/ePort leads to buffer overflow. This vulnerability
CVE-2022-44259 | TOTOLINK LR350 9.3.5u.6369_B20220309 setParentalRules week/sTime/eTime buffer overflow (EUVD-2022-47208)
A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. This affects the function setParentalRules. Executing a manipulation of the argument week/sTime/eTime can lead to buffer overflow. This vulnerabil
CVE-2022-44258 | TOTOLINK LR350 9.3.5u.6369_B20220309 setTracerouteCfg command buffer overflow (EUVD-2022-47207)
A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. The impacted element is the function setTracerouteCfg. Performing a manipulation of the argument command results in buffer overflow. This vul
CVE-2022-44257 | TOTOLINK LR350 9.3.5u.6369_B20220309 setOpModeCfg pppoeUser buffer overflow (EUVD-2022-47206)
A vulnerability, which was classified as critical, was found in TOTOLINK LR350 9.3.5u.6369_B20220309. The affected element is the function setOpModeCfg. Such manipulation of the argument pppoeUser leads to buffer overflow. This vulnerabilit
CVE-2022-44256 | TOTOLINK LR350 9.3.5u.6369_B20220309 setLanguageCfg lang buffer overflow (EUVD-2022-47205)
A vulnerability, which was classified as critical, has been found in TOTOLINK LR350 9.3.5u.6369_B20220309. Impacted is the function setLanguageCfg. This manipulation of the argument lang causes buffer overflow. This vulnerability is registe
CVE-2022-44255 | TOTOLINK LR350 9.3.5u.6369_B20220309 buffer overflow (EUVD-2022-47204)
A vulnerability classified as critical was found in TOTOLINK LR350 9.3.5u.6369_B20220309. This issue affects some unknown processing. The manipulation results in buffer overflow. This vulnerability is cataloged as CVE-2022-44255. The attack
Aktiv ausgenutzte GitLab-Sicherheitslücke gibt Dateien preis
Eine kritische Schwachstelle in GitLab CE und EE erlaubt nicht angemeldeten Angreifern unter bestimmten Bedingungen, beliebige Dateien vom GitLab-Server zu lesen. Die CISA führt die Schwachstelle bereits als aktiv ausgenutzt. (Bild: Gemini
CVE-2026-63917 | Linux Kernel Vti net/core/dev.c vti6_changelink dev use after free (61220ab34948 / Nessus ID 346426)
A vulnerability was found in Linux Kernel. It has been declared as critical. This vulnerability affects the function vti6_changelink of the file net/core/dev.c of the component Vti. The manipulation of the argument dev results in use after
CVE-2026-68426 | Linux Kernel up to 6.18.41/7.1.5/7.2-rc3 xfrm validate_xmit_skb_list use after free (Nessus ID 346426)
A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.41/7.1.5/7.2-rc3. Impacted is the function validate_xmit_skb_list of the component xfrm. Such manipulation leads to use after free. This vulnerability is doc
CVE-2022-44254 | TOTOLINK LR350 9.3.5u.6369_B20220309 setSmsCfg buffer overflow (EUVD-2022-47203)
A vulnerability classified as critical has been found in TOTOLINK LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setSmsCfg. The manipulation leads to buffer overflow. This vulnerability is listed as CVE-2022-44254. The
CVE-2022-44253 | TOTOLINK LR350 9.3.5u.6369_B20220309 setDiagnosisCfg via improper authentication (EUVD-2022-47202)
A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Impacted is the function setDiagnosisCfg. Such manipulation of the argument via leads to improper authentication. This vulnerability is traded as
CVE-2022-44252 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUploadSetting FileName command injection (EUVD-2022-47201)
A vulnerability described as critical has been identified in TOTOLINK NR1800X 9.1.0u.6279_B20210910. This affects the function setUploadSetting. Executing a manipulation of the argument FileName can lead to command injection. This vulnerabi
CVE-2022-44251 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUssd ussd command injection (EUVD-2022-47200)
A vulnerability marked as critical has been reported in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function setUssd. Performing a manipulation of the argument ussd results in command injection. This vulnerability
CVE-2026-65017 | Apache Airflow Config API information disclosure
A vulnerability labeled as problematic has been found in Apache Airflow. Affected is an unknown function of the component Config API. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is C
CVE-2026-67587 | Apache Airflow deserialization
A vulnerability identified as critical has been detected in Apache Airflow. This impacts an unknown function. Performing a manipulation results in deserialization. This vulnerability was named CVE-2026-67587. The attack may be initiated rem