🎯 CVE-2020-10614
📄 .md Alle CVEs anzeigen ✕

CVE-2020-10614: Schwachstellen-Eintrag (NVD)

In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display.

Klassifikation & Betroffenheit:
osisoft pi_vision *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 4.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Hoch
UI · Interaktion Erforderlich
S · Scope Verändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Veröffentlicht:25.07.2020
Aktualisiert:17.06.2026 02:48
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 123 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.886 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-16
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 23%
CVE-2026-73469 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73469 | Arista EOS up to 4.35.4M Unicast Reverse Path Forwarding access control (WID-SEC-2026-3287)

A vulnerability was found in Arista EOS up to 4.35.4M and classified as problematic. The affected element is an unknown function of the component Unicast Reverse Path Forwarding. Executing a manipulation can lead to improper access controls

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-73462 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73462 | Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.1F IGMP Snooping Agent input validation (WID-SEC-2026-3287)

A vulnerability was found in Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.1F and classified as critical. Affected by this issue is some unknown functionality of the component IGMP Snooping Agent. Such manipulation leads to improper input

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-73468 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73468 | Arista EOS up to 4.36.1F Multicast Forwarding state issue (WID-SEC-2026-3287)

A vulnerability was found in Arista EOS up to 4.32.x/4.33.8M/4.34.7.1M/4.35.5M/4.36.1F. It has been rated as critical. This impacts an unknown function of the component Multicast Forwarding. This manipulation causes state issue. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-73461 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73461 | Arista EOS up to 4.36.0.1F AAA improper authorization (WID-SEC-2026-3287)

A vulnerability identified as very critical has been detected in Arista EOS up to 4.36.0.1F. Affected is an unknown function of the component AAA. This manipulation causes improper authorization. This vulnerability is tracked as CVE-2026-73

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29%
CVE-2026-73460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73460 | Arista EOS up to 4.36.1F IS-IS Graceful Restart input validation (WID-SEC-2026-3287)

A vulnerability has been found in Arista EOS up to 4.36.1F and classified as critical. This impacts an unknown function of the component IS-IS Graceful Restart. This manipulation causes improper input validation. This vulnerability is regis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.1%
CVE-2026-73459 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73459 | Arista EOS up to 4.36.1F injection (WID-SEC-2026-3287)

A vulnerability classified as critical was found in Arista EOS up to 4.36.1F. This affects an unknown function. Executing a manipulation can lead to injection. This vulnerability is registered as CVE-2026-73459. It is possible to launch the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.2%
CVE-2026-91843 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication

Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products. This flaw could allow an unauthenticated rem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.2%
CVE-2026-91843 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Check Point Flaw Lets Remote Attackers Gain Root Code Execution Without Login

Check Point has issued an urgent security alert for CVE-2026-91843, a critical stack overflow vulnerability that could allow unauthenticated remote attackers to execute arbitrary code with root privileges on vulnerable Security Management,

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2026-25282 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25282 | Qualcomm Snapdragon Compute up to X2 Elite out-of-bounds (EUVD-2026-81329)

A vulnerability labeled as very critical has been found in Qualcomm Snapdragon Compute up to X2 Elite. This affects an unknown function. Such manipulation leads to out-of-bounds read. This vulnerability is traded as CVE-2026-25282. An attac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-25281 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25281 | Qualcomm Snapdragon Compute up to X2 Elite allocation of resources (EUVD-2026-81328)

A vulnerability identified as problematic has been detected in Qualcomm Snapdragon Compute up to X2 Elite. The impacted element is an unknown function. This manipulation causes allocation of resources. This vulnerability appears as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2026-25280 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25280 | Qualcomm Snapdragon Compute/Snapdragon Industrial IOT up to X2 Elite memory corruption (EUVD-2026-81327)

A vulnerability categorized as very critical has been discovered in Qualcomm Snapdragon Compute and Snapdragon Industrial IOT. The affected element is an unknown function. The manipulation results in memory corruption. This vulnerability is

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-25290 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25290 | Qualcomm Snapdragon Compute up to X2 Elite memory corruption (EUVD-2026-81332)

A vulnerability, which was classified as very critical, has been found in Qualcomm Snapdragon Compute up to X2 Elite. Affected is an unknown function. The manipulation leads to memory corruption. This vulnerability is referenced as CVE-2026

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.9%
CVE-2026-25284 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25284 | Qualcomm Snapdragon Compute up to X2 Elite information disclosure (EUVD-2026-81331)

A vulnerability classified as problematic was found in Qualcomm Snapdragon Compute up to X2 Elite. This impacts an unknown function. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.2%
CVE-2026-25283 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25283 | Qualcomm Snapdragon Compute up to X2 Elite buffer overflow (EUVD-2026-81330)

A vulnerability classified as very critical has been found in Qualcomm Snapdragon Compute up to X2 Elite. This affects an unknown function. Performing a manipulation results in buffer overflow. This vulnerability was named CVE-2026-25283. T

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-87935 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
WordPress

CVE-2026-87935 | ichurakov Paid Downloads Plugin up to 3.15 on WordPress /wp-admin/admin-post.php admin_request_handler unrestricted upload (EUVD-2026-81334)

A vulnerability described as critical has been identified in ichurakov Paid Downloads Plugin up to 3.15 on WordPress. Affected is the function admin_request_handler of the file /wp-admin/admin-post.php. Executing a manipulation can lead to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 26.8%
CVE-2026-25294 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-25294 | Qualcomm Snapdragon CCW up to XRV9209 resource consumption (EUVD-2026-81333)

A vulnerability marked as critical has been reported in Qualcomm Snapdragon CCW, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon MC, Snapdragon Mobile and Snapdragon WBC. This impacts an unknown function. Performing a manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.9%
CVE-2026-87796 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-87796 | sh1zen Multi Uploader for Gravity Forms Plugin up to 1.1.9 on WordPress move_file unrestricted upload (EUVD-2026-81335)

A vulnerability classified as critical has been found in sh1zen Multi Uploader for Gravity Forms Plugin up to 1.1.9 on WordPress. Affected by this vulnerability is the function move_file. The manipulation leads to unrestricted upload. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
5.8 MEDIUM
EPSS 4.6%
CVE-2026-73457 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73457 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F gRPC Network Packet Sampling Interface information disclosure (WID-SEC-2026-3287)

A vulnerability, which was classified as problematic, was found in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. Affected is an unknown function of the component gRPC Network Packet Sampling Interface. The manipulation results in information di

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-73456 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73456 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F gRPC Network Packet Sampling Interface code injection (WID-SEC-2026-3287)

A vulnerability described as very critical has been identified in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. The affected element is an unknown function of the component gRPC Network Packet Sampling Interface. Such manipulation leads to code

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-73455 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73455 | Arista EOS up to 4.36.0.1F OSPFv3 input validation (WID-SEC-2026-3287)

A vulnerability identified as critical has been detected in Arista EOS up to 4.32.x/4.33.8M/4.34.6M/4.35.4M/4.36.0.1F. Affected by this vulnerability is an unknown functionality of the component OSPFv3. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-73453 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73453 | Arista EOS up to 4.36.1F P4Runtime code injection (WID-SEC-2026-3287)

A vulnerability has been found in Arista EOS up to 4.36.1F and classified as very critical. Impacted is an unknown function of the component P4Runtime. Performing a manipulation results in code injection. This vulnerability is reported as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2022-44260 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44260 | TOTOLINK LR350 9.3.5u.6369_B20220309 setIpPortFilterRules sPort/ePort buffer overflow (EUVD-2022-47209)

A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309. It has been classified as critical. This impacts the function setIpPortFilterRules. The manipulation of the argument sPort/ePort leads to buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.9%
CVE-2022-44259 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44259 | TOTOLINK LR350 9.3.5u.6369_B20220309 setParentalRules week/sTime/eTime buffer overflow (EUVD-2022-47208)

A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. This affects the function setParentalRules. Executing a manipulation of the argument week/sTime/eTime can lead to buffer overflow. This vulnerabil

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2022-44258 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44258 | TOTOLINK LR350 9.3.5u.6369_B20220309 setTracerouteCfg command buffer overflow (EUVD-2022-47207)

A vulnerability has been found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. The impacted element is the function setTracerouteCfg. Performing a manipulation of the argument command results in buffer overflow. This vul

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2022-44257 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44257 | TOTOLINK LR350 9.3.5u.6369_B20220309 setOpModeCfg pppoeUser buffer overflow (EUVD-2022-47206)

A vulnerability, which was classified as critical, was found in TOTOLINK LR350 9.3.5u.6369_B20220309. The affected element is the function setOpModeCfg. Such manipulation of the argument pppoeUser leads to buffer overflow. This vulnerabilit

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2022-44256 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44256 | TOTOLINK LR350 9.3.5u.6369_B20220309 setLanguageCfg lang buffer overflow (EUVD-2022-47205)

A vulnerability, which was classified as critical, has been found in TOTOLINK LR350 9.3.5u.6369_B20220309. Impacted is the function setLanguageCfg. This manipulation of the argument lang causes buffer overflow. This vulnerability is registe

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.6%
CVE-2022-44255 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44255 | TOTOLINK LR350 9.3.5u.6369_B20220309 buffer overflow (EUVD-2022-47204)

A vulnerability classified as critical was found in TOTOLINK LR350 9.3.5u.6369_B20220309. This issue affects some unknown processing. The manipulation results in buffer overflow. This vulnerability is cataloged as CVE-2022-44255. The attack

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Aktiv ausgenutzte GitLab-Sicherheits­lücke gibt Dateien preis

Eine kritische Schwachstelle in GitLab CE und EE erlaubt nicht angemelde­ten Angreifern unter bestimmten Bedingungen, beliebige Dateien vom GitLab-Server zu lesen. Die CISA führt die Schwachstelle bereits als aktiv ausgenutzt. (Bild: Gemini

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.7%
CVE-2026-63917 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-63917 | Linux Kernel Vti net/core/dev.c vti6_changelink dev use after free (61220ab34948 / Nessus ID 346426)

A vulnerability was found in Linux Kernel. It has been declared as critical. This vulnerability affects the function vti6_changelink of the file net/core/dev.c of the component Vti. The manipulation of the argument dev results in use after

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.8%
CVE-2026-68426 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-68426 | Linux Kernel up to 6.18.41/7.1.5/7.2-rc3 xfrm validate_xmit_skb_list use after free (Nessus ID 346426)

A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.41/7.1.5/7.2-rc3. Impacted is the function validate_xmit_skb_list of the component xfrm. Such manipulation leads to use after free. This vulnerability is doc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.6%
CVE-2022-44254 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44254 | TOTOLINK LR350 9.3.5u.6369_B20220309 setSmsCfg buffer overflow (EUVD-2022-47203)

A vulnerability classified as critical has been found in TOTOLINK LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setSmsCfg. The manipulation leads to buffer overflow. This vulnerability is listed as CVE-2022-44254. The

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.9%
CVE-2022-44253 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44253 | TOTOLINK LR350 9.3.5u.6369_B20220309 setDiagnosisCfg via improper authentication (EUVD-2022-47202)

A vulnerability was found in TOTOLINK LR350 9.3.5u.6369_B20220309 and classified as critical. Impacted is the function setDiagnosisCfg. Such manipulation of the argument via leads to improper authentication. This vulnerability is traded as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2022-44252 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44252 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUploadSetting FileName command injection (EUVD-2022-47201)

A vulnerability described as critical has been identified in TOTOLINK NR1800X 9.1.0u.6279_B20210910. This affects the function setUploadSetting. Executing a manipulation of the argument FileName can lead to command injection. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2022-44251 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44251 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setUssd ussd command injection (EUVD-2022-47200)

A vulnerability marked as critical has been reported in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function setUssd. Performing a manipulation of the argument ussd results in command injection. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.6%
CVE-2026-65017 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-65017 | Apache Airflow Config API information disclosure

A vulnerability labeled as problematic has been found in Apache Airflow. Affected is an unknown function of the component Config API. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 31.7%
CVE-2026-67587 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-67587 | Apache Airflow deserialization

A vulnerability identified as critical has been detected in Apache Airflow. This impacts an unknown function. Performing a manipulation results in deserialization. This vulnerability was named CVE-2026-67587. The attack may be initiated rem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
5.8 MEDIUM
EPSS 2.4%
CVE-2026-54183 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-54183 | Apache Airflow information disclosure (EUVD-2026-57310)

A vulnerability categorized as problematic has been discovered in Apache Airflow. This affects an unknown function. Such manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2026-54183. The attack c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-59242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-59242 | Apache Airflow XCom deserialize endpoint deserialization

A vulnerability was found in Apache Airflow. It has been rated as critical. The impacted element is an unknown function of the component XCom deserialize endpoint. This manipulation causes deserialization. This vulnerability is handled as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
5.8 MEDIUM
EPSS 5.5%
CVE-2026-59244 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-59244 | Apache Airflow Secrets masker information disclosure (EUVD-2026-57316)

A vulnerability was found in Apache Airflow. It has been declared as problematic. The affected element is an unknown function of the component Secrets masker. The manipulation results in information disclosure. This vulnerability is known a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-58076 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-58076 | Apache Airflow Exception Deserialization BaseSerialization.deserialize deserialization (EUVD-2026-57315)

A vulnerability classified as critical has been found in Apache Airflow. Affected is the function BaseSerialization.deserialize of the component Exception Deserialization. The manipulation leads to deserialization. This vulnerability is lis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.9%
CVE-2026-67260 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-67260 | Apache Airflow Scheduler next_kwargs deserialization

A vulnerability was found in Apache Airflow. It has been classified as critical. Impacted is an unknown function of the component Scheduler. The manipulation of the argument next_kwargs leads to deserialization. This vulnerability is traded

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-18708 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18708 | MongoDB up to 7.0.39/8.0.28/8.3.7 JavaScript Scripting Engine code injection

A vulnerability, which was classified as problematic, was found in MongoDB up to 7.0.39/8.0.28/8.3.7. The affected element is an unknown function of the component JavaScript Scripting Engine. Such manipulation leads to code injection. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2026-68868 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68868 | Apache Airflow Secret Manager Backend privileges management

A vulnerability identified as problematic has been detected in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Secret Manager Backend. Performing a manipulation results in improper privilege manag

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-18706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18706 | MongoDB Server up to 8.3.7 GraphLookup Aggregation Stage use after free

A vulnerability has been found in MongoDB Server up to 8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component GraphLookup Aggregation Stage. The manipulation leads to use after free. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-18709 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18709 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Transaction Coordinator behavioral workflow

A vulnerability described as very critical has been identified in MongoDB Server up to 7.0.39/8.0.28/8.3.7. This affects an unknown part of the component Transaction Coordinator. Executing a manipulation can lead to enforcement of behaviora

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2026-18707 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18707 | MongoDB up to 8.3.7 Aggregation assertion (Nessus ID 343459)

A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. The affected element is an unknown function of the component Aggregation. The manipulation leads to reachable assertion. This vulnerability is uniquely identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.4%
CVE-2026-18701 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18701 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Subsystem denial of service

A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component Query Subsystem. Such manipulation leads to denial of service. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-18705 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18705 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Atlas Vector Search privileges management

A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as problematic. The impacted element is an unknown function of the component Atlas Vector Search. Performing a manipulation results in improper privil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2026-18704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18704 | MongoDB up to 8.3.7 Aggregation Framework improper authorization

A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. Affected by this issue is some unknown functionality of the component Aggregation Framework. Performing a manipulation results in improper authorization. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.2%
CVE-2026-18700 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18700 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Geospatial Validation use after free

A vulnerability labeled as problematic has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Geospatial Validation. Such manipulation leads to use after free.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28%
CVE-2026-18698 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18698 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 improper authorization

A vulnerability identified as very critical has been detected in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. This manipulation causes improper authorization. This vulnerability appears as CVE-2026-18698. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-18696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18696 | MongoDB up to 7.0.39/8.0.28/8.3.7 Authorization Check applyOps improper authorization

A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been rated as critical. This affects the function applyOps of the component Authorization Check. The manipulation leads to improper authorization. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.3%
CVE-2026-18697 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18697 | MongoDB up to 7.0.39/8.0.28/8.3.7 Aggregation Framework denial of service

A vulnerability categorized as problematic has been discovered in MongoDB up to 7.0.39/8.0.28/8.3.7. This impacts an unknown function of the component Aggregation Framework. The manipulation results in denial of service. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.2%
CVE-2026-18699 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18699 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Planner denial of service

A vulnerability classified as problematic has been found in MongoDB up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Query Planner. Performing a manipulation results in denial of service

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-18702 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18702 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Diagnostic Logging improper authorization

A vulnerability classified as critical was found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this issue is some unknown functionality of the component Diagnostic Logging. Executing a manipulation can lead to improper authorizat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-18703 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18703 | MongoDB Server up to 8.3.7 certificate validation

A vulnerability, which was classified as problematic, was found in MongoDB Server up to 8.3.7. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper certificate validation. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2022-44249 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44249 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 UploadFirmwareFile FileName command injection (EUVD-2022-47198)

A vulnerability identified as critical has been detected in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected is the function UploadFirmwareFile. This manipulation of the argument FileName causes command injection. The identification of this

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2022-44250 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44250 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setOpModeCfg Hostname command injection (EUVD-2022-47199)

A vulnerability labeled as critical has been found in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this vulnerability is the function setOpModeCfg. Such manipulation of the argument Hostname leads to command injection. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2022-44236 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44236 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 weak password (EUVD-2022-47186)

A vulnerability classified as critical has been found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. Impacted is an unknown function. This manipulation causes weak password requirements. This vulnerability is registered as CVE-2022-44236

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-19490 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Detecting and Containing CVE-2026-19490: A Defender's Checklist for NetScaler SAML Bypass

Detecting and Containing CVE-2026-19490: A Defender&#039;s Checklist for NetScaler SAML Bypass Most authentication bypasses announce themselves through failed logins. CVE-2026-19490 does the opposite. An attacker who exploits it produces a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.