🎯 CVE-2019-25011
📄 .md Alle CVEs anzeigen ✕

CVE-2019-25011: Schwachstellen-Eintrag (NVD)

NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.

Klassifikation & Betroffenheit:
netbox netbox *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 🎯 High

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and …
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 5.4
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Erforderlich
S · Scope Verändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Veröffentlicht:31.12.2020
Aktualisiert:17.06.2026 02:31
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 105 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.868 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-17
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 28.7%
CVE-2026-67636 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-67636 | Microsoft SQL Server out-of-bounds

A vulnerability categorized as very critical has been discovered in Microsoft SQL Server. This impacts an unknown function. The manipulation results in out-of-bounds read. This vulnerability is reported as CVE-2026-67636. The attack can be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 22.6%
CVE-2026-67631 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-67631 | Microsoft SQL Server 2017/2019/2022/2025 heap-based overflow

A vulnerability was found in Microsoft SQL Server 2017/2019/2022/2025. It has been rated as very critical. This affects an unknown function. The manipulation leads to heap-based buffer overflow. This vulnerability is documented as CVE-2026-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 21.3%
CVE-2026-67378 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-67378 | Microsoft SQL Server 2019/2022/2025 improper authorization

A vulnerability classified as very critical has been found in Microsoft SQL Server 2019/2022/2025. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper authorization. This vulnerability w

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
5.8 MEDIUM
EPSS 6.6%
CVE-2026-82069 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82069 | MongoDB Server up to 8.3.8 Query Statistics Serialization information disclosure

A vulnerability classified as problematic was found in MongoDB Server up to 8.3.8. This affects an unknown function of the component Query Statistics Serialization. The manipulation results in information disclosure. This vulnerability is c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2026-82066 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82066 | MongoDB up to 7.0.40/8.0.29/8.3.8 Query Planning out-of-bounds (Nessus ID 344375)

A vulnerability was found in MongoDB up to 7.0.40/8.0.29/8.3.8. It has been classified as problematic. Affected is an unknown function of the component Query Planning. Performing a manipulation results in out-of-bounds read. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2026-82059 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82059 | MongoDB Server up to 7.0.40/8.0.29/8.3.8 Index Key Generation resource consumption

A vulnerability, which was classified as problematic, has been found in MongoDB Server up to 7.0.40/8.0.29/8.3.8. The affected element is an unknown function of the component Index Key Generation. The manipulation leads to resource consumpt

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-82060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82060 | MongoDB up to 7.0.40/8.0.29/8.3.8 Change Stream data query logic injection

A vulnerability, which was classified as problematic, was found in MongoDB up to 7.0.40/8.0.29/8.3.8. The impacted element is an unknown function of the component Change Stream. The manipulation results in improper neutralization of special

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.1%
CVE-2026-82065 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82065 | MongoDB Server up to 7.0.40/8.0.29/8.3.8 Storage Engine Integration Layer assertion

A vulnerability categorized as critical has been discovered in MongoDB Server up to 7.0.40/8.0.29/8.3.8. Affected is an unknown function of the component Storage Engine Integration Layer. Executing a manipulation can lead to reachable asser

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-82058 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82058 | MongoDB Server up to 7.0.40/8.0.29/8.3.8 JSON Schema Validation uncaught exception

A vulnerability classified as problematic was found in MongoDB Server up to 7.0.40/8.0.29/8.3.8. Impacted is an unknown function of the component JSON Schema Validation. Executing a manipulation can lead to uncaught exception. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.9%
CVE-2026-87285 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87285 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346968)

A vulnerability categorized as problematic has been discovered in Oracle VirtualBox 7.2.16. Affected by this vulnerability is an unknown functionality of the component Core. Such manipulation leads to improper privilege management. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2026-87276 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87276 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346969)

A vulnerability classified as problematic was found in Oracle VirtualBox 7.2.16. The affected element is an unknown function of the component Core. Such manipulation leads to improper privilege management. This vulnerability is documented a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2026-87270 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87270 | Oracle VM VirtualBox 7.2.16 Core privileges management (Nessus ID 346971)

A vulnerability was found in Oracle VM VirtualBox 7.2.16. It has been declared as very critical. This impacts an unknown function of the component Core. The manipulation results in improper privilege management. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.5%
CVE-2026-87267 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87267 | Oracle VM VirtualBox 7.2.16 Core privileges management (Nessus ID 346970)

A vulnerability classified as problematic has been found in Oracle VM VirtualBox 7.2.16. This affects an unknown part of the component Core. The manipulation leads to improper privilege management. This vulnerability is documented as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2026-87279 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87279 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346972)

A vulnerability classified as problematic has been found in Oracle VirtualBox 7.2.16. Impacted is an unknown function of the component Core. This manipulation causes improper privilege management. This vulnerability is registered as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2026-87269 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87269 | Oracle VM VirtualBox 7.2.16 Core privileges management (Nessus ID 346973)

A vulnerability was found in Oracle VM VirtualBox 7.2.16. It has been classified as problematic. This affects an unknown function of the component Core. The manipulation leads to improper privilege management. This vulnerability is uniquely

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-84578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-84578 | Apple macOS up to 15.7/26.6/26 sandbox (EUVD-2026-78101)

A vulnerability was found in Apple macOS up to 15.7/26.6/26 and classified as very critical. Affected is an unknown function. The manipulation results in sandbox issue. This vulnerability is cataloged as CVE-2026-84578. The attack may be la

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.4%
CVE-2026-76409 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-76409 | Cisco Nexus Dashboard up to 4.2.1 path traversal (EUVD-2026-81115)

A vulnerability was found in Cisco Nexus Dashboard. It has been classified as very critical. Affected is an unknown function. The manipulation leads to path traversal. This vulnerability is traded as CVE-2026-76409. It is possible to initia

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 31.4%
CVE-2026-20350 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20350 | Cisco ThousandEyes Virtual Appliance up to 5.2.0 Web-based Management Interface os command injection (EUVD-2026-81117)

A vulnerability classified as very critical has been found in Cisco ThousandEyes Virtual Appliance up to 5.2.0. Affected by this issue is some unknown functionality of the component Web-based Management Interface. Performing a manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 31.5%
CVE-2026-20340 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20340 | Cisco Secure Firewall Management Center up to 10.0.1 deserialization (EUVD-2026-81116)

A vulnerability marked as very critical has been reported in Cisco Secure Firewall Management Center. Affected is an unknown function. This manipulation causes deserialization. This vulnerability is tracked as CVE-2026-20340. The attack is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
5.8 MEDIUM
EPSS 5.1%
CVE-2026-20360 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20360 | Cisco Nexus Dashboard up to 4.2.1 information disclosure (EUVD-2026-81127)

A vulnerability was found in Cisco Nexus Dashboard and classified as problematic. This impacts an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability appears as CVE-2026-20360. The attack may be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 21.7%
CVE-2026-20336 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20336 | Cisco Secure Adaptive Security Appliance Software resource control (EUVD-2026-81119)

A vulnerability, which was classified as very critical, was found in Cisco Secure Adaptive Security Appliance Software, Secure Firewall Management Center and Secure Firewall Threat Defense Software. This issue affects some unknown processin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
8.2 HIGH
EPSS 20.8%
CVE-2026-20344 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20344 | Cisco Secure Firewall Management Center up to 10.0.1 Web-based Management Interface sql injection (EUVD-2026-81129)

A vulnerability has been found in Cisco Secure Firewall Management Center and classified as problematic. This affects an unknown function of the component Web-based Management Interface. Performing a manipulation results in sql injection. T

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 23%
CVE-2026-20276 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-20276 | Cisco IOS XR Software up to 26.2.101 Control Flow Management insufficient control flow management (EUVD-2026-70203)

A vulnerability was found in Cisco IOS XR Software. It has been classified as critical. This affects an unknown part of the component Control Flow Management. Performing a manipulation results in insufficient control flow management. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2026-84971 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84971 | MongoDB libmongocrypt up to 1.20.3 assertion (Nessus ID 342821 / WID-SEC-2026-3182)

A vulnerability classified as problematic was found in MongoDB libmongocrypt up to 1.20.3. Affected by this issue is some unknown functionality. The manipulation results in reachable assertion. This vulnerability is cataloged as CVE-2026-84

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5%
CVE-2026-20124 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-20124 | Cisco IOS XE Software up to 17.18.2 SNMP Subsystem denial of service

A vulnerability was found in Cisco IOS XE Software. It has been rated as critical. This affects an unknown function of the component SNMP Subsystem. Performing a manipulation results in denial of service. This vulnerability is known as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2026-11803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-11803 | Autodesk Revit prior 2026.5.0/2027.2.0 PDF file out-of-bounds

A vulnerability categorized as critical has been discovered in Autodesk Revit. This vulnerability affects unknown code of the component PDF file Handler. The manipulation results in out-of-bounds read. This vulnerability is known as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.7%
CVE-2026-20301 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-20301 | Cisco IOS XE Software/IOS XMCP denial of service

A vulnerability categorized as critical has been discovered in Cisco IOS XE Software and IOS. Affected by this issue is some unknown functionality of the component XMCP. The manipulation results in denial of service. This vulnerability is k

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.9%
CVE-2026-89841 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89841 | Linux Kernel up to 6.18.50/7.2.4 f2fs redirty_blocks use after free (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.18.50/7.2.4 and classified as very critical. The impacted element is the function redirty_blocks of the component f2fs. The manipulation results in use after free. This vulnerability is cata

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.5%
CVE-2026-89840 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89840 | Linux Kernel up to 7.2.4 f2fs __clone_blkaddrs input validation (WID-SEC-2026-3438)

A vulnerability has been found in Linux Kernel up to 7.2.4 and classified as very critical. The affected element is the function __clone_blkaddrs of the component f2fs. The manipulation leads to improper input validation. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.2%
CVE-2026-89839 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89839 | Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4 f2fs f2fs_xattr_advise_set privileges management (WID-SEC-2026-3438)

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4. This vulnerability affects the function f2fs_xattr_advise_set of the component f2fs. This manipulation causes improper privilege

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.8%
CVE-2026-89838 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89838 | Linux Kernel up to 7.2.4 F2FS recover_inode/recover_dentry buffer overflow (WID-SEC-2026-3438)

A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.2.4. Impacted is the function recover_inode/recover_dentry of the component F2FS. Executing a manipulation can lead to buffer overflow. This vulnerabi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.9%
CVE-2026-89837 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89837 | Linux Kernel up to 6.18.50/7.2.4 f2fs find_in_level release of resource (WID-SEC-2026-3438)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.50/7.2.4. This affects the function find_in_level of the component f2fs. The manipulation results in missing release of resource. This vulnerability is known as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18%
CVE-2026-26950 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-26950 | Dell SmartFabric Manager up to 2.2.0 improper authentication (EUVD-2026-81676)

A vulnerability categorized as critical has been discovered in Dell SmartFabric Manager up to 2.2.0. This issue affects some unknown processing. Executing a manipulation can lead to improper authentication. This vulnerability appears as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.2%
CVE-2026-80355 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80355 | Dell OpenManage Server Administrator up to 11.1.0.2 cross-site request forgery (EUVD-2026-81578)

A vulnerability was found in Dell OpenManage Server Administrator. It has been rated as problematic. This affects an unknown part. This manipulation causes cross-site request forgery. This vulnerability is handled as CVE-2026-80355. The att

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2026-28326 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-28326 | SolarWinds Access Rights Manager hard-coded credentials (EUVD-2026-82317)

A vulnerability labeled as critical has been found in SolarWinds Access Rights Manager. Affected is an unknown function. Executing a manipulation can lead to hard-coded credentials. This vulnerability is registered as CVE-2026-28326. It is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-43815 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43815 | Apple macOS up to 14.8.7/15.7.7/26.5 afpfs buffer overflow (EUVD-2026-77899)

A vulnerability marked as very critical has been reported in Apple macOS up to 14.8.7/15.7.7/26.5. This vulnerability affects unknown code of the component afpfs. This manipulation causes buffer overflow. This vulnerability appears as CVE-2

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-76781 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-76781 | Fedora libxml2 Catalog null pointer dereference (EUVD-2026-81679)

A vulnerability was found in Fedora libxml2. It has been declared as critical. This affects an unknown part of the component Catalog. Executing a manipulation can lead to null pointer dereference. This vulnerability appears as CVE-2026-7678

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-89836 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89836 | Linux Kernel up to 7.2.4 f2fs folio_nr_pages i_pages/mapping race condition (WID-SEC-2026-3438)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 7.2.4. This issue affects the function folio_nr_pages of the component f2fs. Performing a manipulation of the argument i_pages/mapping results in r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.3%
CVE-2026-89834 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89834 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 f2fs free_segment_range out-of-bounds (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4 and classified as very critical. Affected is the function free_segment_range of the component f2fs. Such manipulation leads to out-of-bounds read. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.3%
CVE-2026-89835 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89835 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 f2fs set_task_ioprio null pointer dereference (WID-SEC-2026-3438)

A vulnerability identified as problematic has been detected in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected by this issue is the function set_task_ioprio of the component f2fs. The manipulation leads to null pointer dereference. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.6%
CVE-2026-89832 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89832 | Linux Kernel up to 6.18.50/7.2.4 f2fs return value (WID-SEC-2026-3438)

A vulnerability classified as very critical was found in Linux Kernel up to 6.18.50/7.2.4. This vulnerability affects unknown code of the component f2fs. Such manipulation leads to unchecked return value. This vulnerability is referenced as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.6%
CVE-2026-89833 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89833 | Linux Kernel up to 6.18.50/7.2.4 f2fs f2fs_fsync_node_pages race condition (WID-SEC-2026-3438)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function f2fs_fsync_node_pages of the component f2fs. Executing a manipulation can lead to race condition

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.2%
CVE-2026-89831 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89831 | Linux Kernel up to 7.2.4 f2fs race condition (WID-SEC-2026-3438)

A vulnerability classified as critical has been found in Linux Kernel up to 7.2.4. This affects an unknown part of the component f2fs. This manipulation causes race condition. The identification of this vulnerability is CVE-2026-89831. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.4%
CVE-2026-89830 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89830 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 f2fs __allocate_data_block data_blkaddr allocation of resources (WID-SEC-2026-3438)

A vulnerability described as critical has been identified in Linux Kernel up to 6.12.109/6.18.50/7.2.4. Affected by this issue is the function __allocate_data_block of the component f2fs. The manipulation of the argument data_blkaddr result

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.5%
CVE-2026-89829 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89829 | Linux Kernel up to 6.18.50/7.2.4 f2fs f2fs_sanity_check_node_footer index infinite loop (WID-SEC-2026-3438)

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.50/7.2.4. Affected by this vulnerability is the function f2fs_sanity_check_node_footer of the component f2fs. The manipulation of the argument index leads

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.7%
CVE-2026-89828 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89828 | Linux Kernel up to 6.18.50/7.2.4 amdgpu_vram_mgr drm/amdgpu amdgpu_vram_mgr_init free_trees null pointer dereference (WID-SEC-2026-3438)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.50/7.2.4. Affected is the function amdgpu_vram_mgr_init of the file drm/amdgpu of the component amdgpu_vram_mgr. Executing a manipulation of the argument free_tre

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.6%
CVE-2026-89826 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89826 | Linux Kernel up to 6.18.50/7.2.4 panthor panthor_fw_read_build_info out-of-bounds (WID-SEC-2026-3438)

A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.50/7.2.4. This impacts the function panthor_fw_read_build_info of the component panthor. Performing a manipulation results in out-of-bounds read. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22%
CVE-2026-89827 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89827 | Linux Kernel up to 7.2.4 UVD Ring drm/amdgpu amdgpu_uvd_resume uninitialized pointer (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4. It has been rated as very critical. The impacted element is the function amdgpu_uvd_resume of the file drm/amdgpu of the component UVD Ring. This manipulation causes uninitialized point

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.4%
CVE-2026-89825 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89825 | Linux Kernel up to 6.12.109/6.18.50/7.2.4 panthor drm/panthor panthor_init_cs_iface/panthor_init_csg_iface memory corruption (WID-SEC-2026-3438)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.109/6.18.50/7.2.4. This affects the function panthor_init_cs_iface/panthor_init_csg_iface of the file drm/panthor of the component panthor. Such man

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.7%
CVE-2026-93313 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93313 | Freedesktop Poppler 26.07.0 poppler/JBIG2Stream.cc readCodeTableSeg integer overflow (ID 1760 / EUVD-2026-82614)

A vulnerability identified as critical has been detected in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer ove

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2026-93456 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-93456 | batiste django-page-cms up to 2.0.13 Admin Views pages/admin/views.py cross site scripting (EUVD-2026-82616)

A vulnerability has been found in batiste django-page-cms up to 2.0.13 and classified as problematic. This vulnerability affects unknown code of the file pages/admin/views.py of the component Admin Views. The manipulation leads to cross sit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-93455 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93455 | batiste django-page-cms up to 2.0.13 permission (EUVD-2026-82615)

A vulnerability classified as problematic was found in batiste django-page-cms up to 2.0.13. Affected by this vulnerability is an unknown functionality. Such manipulation leads to permission issues. This vulnerability is referenced as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-82980 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82980 | Nextcloud Files Lock up to 33.0.0 WebDAV Plugin improper authorization (EUVD-2026-82617)

A vulnerability, which was classified as critical, has been found in Nextcloud Files Lock up to 33.0.0. Affected by this issue is some unknown functionality of the component WebDAV Plugin. Performing a manipulation results in improper autho

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-77169 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77169 | Nextcloud Team Folders up to 21.x improper authorization (EUVD-2026-82618)

A vulnerability classified as problematic has been found in Nextcloud Team Folders up to 21.x. Affected is an unknown function. This manipulation causes improper authorization. The identification of this vulnerability is CVE-2026-77169. It

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2026-82982 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82982 | Nextcloud Approval up to 3.0.0 etag improper authentication (EUVD-2026-82619)

A vulnerability identified as problematic has been detected in Nextcloud Approval up to 3.0.0. The affected element is an unknown function. Performing a manipulation of the argument etag results in improper authentication. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-77170 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77170 | Nextcloud Deck up to 1.18.0 Deck config API permission (EUVD-2026-82620)

A vulnerability marked as problematic has been reported in Nextcloud Deck up to 1.18.0. This affects an unknown function of the component Deck config API. The manipulation leads to permission issues. This vulnerability is uniquely identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-87283 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87283 | Oracle VirtualBox 7.2.16 Core privileges management (Nessus ID 346974)

A vulnerability marked as problematic has been reported in Oracle VirtualBox 7.2.16. This vulnerability affects unknown code of the component Core. The manipulation leads to improper privilege management. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-92413 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92413 | Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9 PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference (Bug 709610 / Nessus ID 346975)

A vulnerability described as problematic has been identified in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-92987 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92987 | RazrFalcon roxmltree up to 0.21.1 XML Parsing resource consumption (Nessus ID 346976)

A vulnerability was found in RazrFalcon roxmltree up to 0.21.1. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component XML Parsing. This manipulation causes resource consumption. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.7%
CVE-2026-87278 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87278 | Oracle VirtualBox 7.2.16 Core denial of service (Nessus ID 346977)

A vulnerability was found in Oracle VirtualBox 7.2.16. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Core. Such manipulation leads to denial of service. This vulnerability is uniq

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.