🎯 CVE-2020-10696
📄 .md Alle CVEs anzeigen ✕

CVE-2020-10696: Schwachstellen-Eintrag (NVD)

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

Klassifikation & Betroffenheit:
buildah_project buildah *redhat openshift_container_platform 3.11redhat enterprise_linux 7.0redhat enterprise_linux 8.0
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 5247a1f1a3b3ccf3c2ee9b45f67305c517e2d304 (Commit)
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Erforderlich
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Veröffentlicht:31.03.2020
Aktualisiert:17.06.2026 02:48
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
2 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
6 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 123 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.886 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-16
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 22.6%
CVE-2026-85596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85596 | Traefik Labs up to 3.7.10 Kubernetes Ingress NGINX Provider improper authentication

A vulnerability classified as critical has been found in Traefik Labs Traefik up to 3.7.10. Affected by this vulnerability is an unknown functionality of the component Kubernetes Ingress NGINX Provider. This manipulation causes improper aut

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-81205 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81205 | Drupal LDAP Active Directory Integration up to 2.2.0 ldap injection

A vulnerability, which was classified as critical, was found in Drupal LDAP Active Directory Integration up to 2.2.0. Impacted is an unknown function. The manipulation results in ldap injection. This vulnerability is identified as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-85594 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85594 | Traefik Labs up to 3.7.12 Kubernetes Ingress Provider privileges management

A vulnerability has been found in Traefik Labs Traefik up to 3.7.12 and classified as problematic. Affected by this issue is some unknown functionality of the component Kubernetes Ingress Provider. Performing a manipulation results in impro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-85173 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85173 | n8n-io n8n up to 2.36.1 Insights API projectId improper authorization

A vulnerability marked as problematic has been reported in n8n-io n8n up to 2.36.1. This affects an unknown function of the component Insights API. This manipulation of the argument projectId causes improper authorization. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-85171 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85171 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Strapi/SeaTable/Mailcheck nodes missing encryption

A vulnerability, which was classified as problematic, was found in n8n-io n8n. Affected is an unknown function of the component Strapi/SeaTable/Mailcheck nodes. Executing a manipulation can lead to missing encryption of sensitive data. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.9%
CVE-2026-85172 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85172 | n8n-io n8n up to 2.34.0 Request Helper legacy request helper function uri/url server-side request forgery

A vulnerability identified as critical has been detected in n8n-io n8n up to 2.34.0. The affected element is the function legacy request helper function of the component Request Helper. The manipulation of the argument uri/url leads to serv

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-85168 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85168 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Git node command injection

A vulnerability classified as critical has been found in n8n-io n8n. The impacted element is an unknown function of the component Git node. This manipulation causes command injection. This vulnerability appears as CVE-2026-85168. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-15315 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Sicherheitslücke in der TP-Link-Tapo-C200-Kamera lässt Angreifer ins Haus spähen

Cybersicherheit Cybersicherheit TP-Link Tapo C200 IP-Kameras CVE-2026-15315 IoT-Schwachstelle Videoüberwachung. Inhaltsverzeichnis. 1.Was die ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-81165 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81165 | Drupal Blazy Module up to 3.0.18 improper authorization

A vulnerability was found in Drupal Blazy Module up to 3.0.18. It has been declared as problematic. This impacts an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability is registered as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-59318 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59318 | VMware Spring AI up to 1.0.9/1.1.8/2.0.0 Tool Call privileges management

A vulnerability, which was classified as critical, was found in VMware Spring AI up to 1.0.9/1.1.8/2.0.0. Impacted is an unknown function of the component Tool Call Handler. Executing a manipulation can lead to improper privilege management

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-73478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73478 | Drupal Diff Plugin up to 2.0.1/2.1.1 improper authorization (CNNVD-2026-98018514)

A vulnerability has been found in Drupal Diff Plugin up to 2.0.1/2.1.1 and classified as problematic. This impacts an unknown function. Performing a manipulation results in improper authorization. This vulnerability is identified as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2026-73477 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73477 | Drupal Quick Tabs Plugin up to 4.3.0 improper authorization

A vulnerability, which was classified as critical, was found in Drupal Quick Tabs Plugin up to 4.3.0. This affects an unknown function. Such manipulation leads to improper authorization. This vulnerability is referenced as CVE-2026-73477. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-81201 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81201 | Drupal Monster Menus up to 9.5.2 cross site scripting

A vulnerability described as problematic has been identified in Drupal Monster Menus up to 9.5.2. This issue affects some unknown processing. Executing a manipulation can lead to cross site scripting. This vulnerability is handled as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-81166 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81166 | Drupal Digital Signage Framework up to 2.6.1 access control

A vulnerability was found in Drupal Digital Signage Framework up to 2.6.1. It has been rated as critical. Affected is an unknown function. The manipulation leads to improper access controls. This vulnerability is documented as CVE-2026-8116

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2026-81159 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81159 | Drupal Commerce CyberSource Plugin up to 1.9.x excessive authentication

A vulnerability has been found in Drupal Commerce CyberSource Plugin up to 1.9.x and classified as problematic. The affected element is an unknown function. This manipulation causes improper restriction of excessive authentication attempts.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-56100 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-56100 | SpringBlade up to 3.5.0 Authentication Filter privileges management

A vulnerability classified as critical was found in SpringBlade up to 3.5.0. This vulnerability affects unknown code of the component Authentication Filter. Such manipulation leads to improper privilege management. This vulnerability is uni

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-59308 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59308 | Spring AI 2.0.0 Semantic Cache access control

A vulnerability has been found in Spring AI 2.0.0 and classified as critical. The affected element is an unknown function of the component Semantic Cache. The manipulation leads to improper access controls. This vulnerability is listed as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-90894 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs

A newly documented security flaw in Parallels Desktop, identified as CVE-2026-90894 and nicknamed &quot;ParaShells,&quot; could let any local account on a Mac escalate to full root control of the host machine, according to researchers at JF

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Linux-Entwickler gibt auf: Geheime Sicherheitslücke gemeldet

Andy Nguyen beendet sein PS5-Linux-Projekt, nachdem KI-gestützte Modder eine geheim gehaltene Sicherheitslücke an Sony meldeten. Der Sicherheitsforscher Andy Nguyen, bekannt unter dem Namen TheFlow0, hat sein Projekt PS5 Linux nach eigenen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.5%
CVE-2026-77179 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Docker Sandboxes Flaw Lets Malicious Guests Escape Isolation and Access Host Files

Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could allow a malicious guest environment to break workspace isolation and reach sensitive host-side resources. The flaws, tracked as CVE-2026-77179

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-91014 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91014 | Realtyna Organic IDX Plugin/WPL Real Estate Plugin up to 5.4.1 on WordPress cross site scripting (EUVD-2026-81355)

A vulnerability labeled as problematic has been found in Realtyna Organic IDX Plugin and WPL Real Estate Plugin up to 5.4.1 on WordPress. This vulnerability affects unknown code. The manipulation results in cross site scripting. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.3%
CVE-2026-91011 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91011 | EWWW Image Optimizer Plugin up to 8.7.6 on WordPress cross site scripting (EUVD-2026-81354)

A vulnerability was found in EWWW Image Optimizer Plugin up to 8.7.6 on WordPress and classified as problematic. This affects an unknown function. The manipulation results in cross site scripting. This vulnerability is identified as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.3%
CVE-2026-91010 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91010 | Invisible Anti-Spam &amp; CAPTCHA Plugin up to 5.1.0 on WordPress Message Deletion nonce authorization (EUVD-2026-81353)

A vulnerability has been found in Invisible Anti-Spam &amp;amp; CAPTCHA Plugin up to 5.1.0 on WordPress and classified as critical. The impacted element is an unknown function of the component Message Deletion. The manipulation of the argum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 24.2%
CVE-2026-91016 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91016 | Motors Plugin up to 1.4.120 on WordPress user id authorization (EUVD-2026-81357)

A vulnerability identified as problematic has been detected in Motors Plugin up to 1.4.120 on WordPress. This affects an unknown part. The manipulation of the argument user id leads to authorization bypass. This vulnerability is documented

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 27.8%
CVE-2026-91015 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91015 | Master Addons for Elementor Plugin up to 3.1.8 on WordPress authorization (EUVD-2026-81356)

A vulnerability categorized as critical has been discovered in Master Addons for Elementor Plugin up to 3.1.8 on WordPress. Affected by this issue is some unknown functionality. Executing a manipulation can lead to missing authorization. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.1%
CVE-2026-91019 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91019 | Event Booking Manager Plugin up to 5.5.x on WordPress access control (EUVD-2026-81358)

A vulnerability was found in Event Booking Manager Plugin up to 5.5.x on WordPress. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper access controls.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Update schnell installieren: Pixel-Sicherheitslücke wird bereits aktiv ausgenutzt

Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. weiterlesen auf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Update schnell installieren: Pixel-Sicherheitslücke wird bereits aktiv ausgenutzt

Google hat ein neues Update für seine Pixel-Smartphones veröffentlicht. Neben praktischen Funktionen enthält die Aktualisierung aber auch einen wichtigen Fix für eine aktiv ausgenutzte Sicherheitslücke. Was dazu bekannt ist. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.6%
CVE-2022-44280 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44280 | oretnom23 Automotive Shop Management System 1.0 Master.php?f=delete_img denial of service (EUVD-2022-47228)

A vulnerability identified as problematic has been detected in oretnom23 Automotive Shop Management System 1.0. The impacted element is an unknown function of the file /asms/classes/Master.php?f=delete_img. The manipulation leads to denial

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.9%
CVE-2022-44279 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44279 | Garage Management System 1.0 createBrand.php cross site scripting (EUVD-2022-47227)

A vulnerability, which was classified as problematic, has been found in Garage Management System 1.0. This affects an unknown part of the file /garage/php_action/createBrand.php. This manipulation causes cross site scripting. The identifica

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 31.5%
CVE-2022-44278 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44278 | oretnom23 Sanitization Management System 1.0 manage_user ID sql injection (EUVD-2022-47226)

A vulnerability categorized as critical has been discovered in oretnom23 Sanitization Management System 1.0. The affected element is an unknown function of the file /php-sms/admin/?page=user/manage_user. Executing a manipulation of the argu

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...] Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Gefährliche Sicherheitslücke: Apple-Geräte lassen sich per Bluetooth kapern

Bei iPhones, iPads, Macs und anderen Apple-Geräten lässt sich ohne Zutun des Nutzers über Bluetooth Schadcode einschleusen. Neue Updates beheben das. (Sicherheitslücke, Apple) Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2026-77179 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Docker Sandboxes Vulnerabilities Let Malicious Guests Escape Workspace and Access Host Files

Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could let a malicious guest environment bypass workspace isolation and access sensitive resources on the host. These flaws, identified as CVE-2026-7

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.1%
CVE-2026-19774 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-19774 | Linux BlueZ stack-based overflow (WID-SEC-2026-2984)

A vulnerability described as very critical has been identified in Linux BlueZ. Affected by this issue is some unknown functionality. Such manipulation leads to stack-based buffer overflow. This vulnerability is listed as CVE-2026-19774. The

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.9%
CVE-2026-86107 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86107 | Arista VeloCloud/VeloCloud Gateway prior 5.2.0.0/5.2.7.0/6.1.5.0/6.4.2.0 VCMP Tunnel Protocol out-of-bounds write (WID-SEC-2026-3287)

A vulnerability was found in Arista VeloCloud and VeloCloud Gateway. It has been declared as critical. The affected element is an unknown function of the component VCMP Tunnel Protocol. The manipulation results in out-of-bounds write. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-86106 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86106 | Arista VeloCloud Edge prior 5.2.0.0/5.2.7.0/6.1.5.0/6.4.2.0 privileges management (WID-SEC-2026-3287)

A vulnerability classified as very critical was found in Arista VeloCloud Edge. Impacted is an unknown function. Such manipulation leads to improper privilege management. This vulnerability is listed as CVE-2026-86106. The attack may be per

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2026-77190 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77190 | Arista EOS up to 4.34.7M/4.35.5M/4.36.1F Pimsm Agent input validation (WID-SEC-2026-3287)

A vulnerability marked as critical has been reported in Arista EOS up to 4.34.7M/4.35.5M/4.36.1F. This affects an unknown part of the component Pimsm Agent. The manipulation leads to improper input validation. This vulnerability is referenc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-68076 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68076 | Apache Airflow Connection Test API access control (EUVD-2026-57265)

A vulnerability, which was classified as critical, has been found in Apache Airflow. This issue affects some unknown processing of the component Connection Test API. Performing a manipulation results in improper access controls. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 19.9%
CVE-2026-77587 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77587 | Tor Project 0.4.9.9 Conflux use after free

A vulnerability was found in Tor Project Tor 0.4.9.9. It has been rated as critical. This vulnerability affects unknown code of the component Conflux. The manipulation leads to use after free. This vulnerability is traded as CVE-2026-77587.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-68969 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68969 | Apache Airflow Audit Log missing encryption

A vulnerability described as problematic has been identified in Apache Airflow. Affected by this issue is some unknown functionality of the component Audit Log. The manipulation results in missing encryption of sensitive data. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
5.8 MEDIUM
EPSS 5.7%
CVE-2026-68970 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68970 | Apache Airflow Task Logs/Rendered Templates information disclosure

A vulnerability classified as problematic has been found in Apache Airflow. This affects an unknown part of the component Task Logs/Rendered Templates. This manipulation causes information disclosure. This vulnerability is tracked as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 25.8%
CVE-2026-77638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77638 | Tor Project 0.4.9.9 Rendezvous Point race condition (Nessus ID 338660)

A vulnerability labeled as very critical has been found in Tor Project Tor 0.4.9.9. The affected element is an unknown function of the component Rendezvous Point. Such manipulation leads to race condition. This vulnerability is uniquely ide

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-68968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68968 | Apache Airflow Backfill API authorization

A vulnerability marked as critical has been reported in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Backfill API. The manipulation leads to authorization bypass. This vulnerability is referenc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-77584 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77584 | torproject Tor prior 0.4.9.10 use after free (Nessus ID 338654)

A vulnerability was found in torproject Tor. It has been declared as critical. This affects an unknown part. Executing a manipulation can lead to use after free. This vulnerability appears as CVE-2026-77584. The attack may be performed from

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-43971 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-43971 | ninenines cowlib cow_link cow_link:link escape output (EUVD-2026-60573 / Nessus ID 338849)

A vulnerability, which was classified as critical, was found in ninenines cowlib. This vulnerability affects the function cow_link:link of the component cow_link. Such manipulation leads to escaping of output. This vulnerability is document

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22%
CVE-2026-74259 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74259 | Linux Kernel up to 7.1.4 cifs cifsFileInfo_put_final null pointer dereference

Further analysis revealed that this issues is a false-positive. Please take a look at the sources mentioned and consider not using this entry at all. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.6%
CVE-2026-73566 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73566 | isaacs node-tar up to 7.5.20 Files Filter src/list.ts filesFilter stack-based overflow (Nessus ID 342214)

A vulnerability was found in isaacs node-tar up to 7.5.20. It has been declared as problematic. Impacted is the function filesFilter of the file src/list.ts of the component Files Filter. The manipulation results in stack-based buffer overf

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2026-68971 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-68971 | Apache Airflow Asset Materialization authorization

A vulnerability classified as critical was found in Apache Airflow. This vulnerability affects unknown code of the component Asset Materialization. Such manipulation leads to authorization bypass. This vulnerability is listed as CVE-2026-68

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
8.2 HIGH
EPSS 29.2%
CVE-2022-44277 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44277 | Sanitization Management System 1.0 Master.php?f=delete_product sql injection (EUVD-2022-47225)

A vulnerability, which was classified as critical, was found in Sanitization Management System 1.0. This affects an unknown part of the file /php-sms/classes/Master.php?f=delete_product. Executing a manipulation can lead to sql injection. T

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.9%
CVE-2022-44264 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44264 | Dentsply Sirona Sidexis up to 4.3 unquoted search path (EUVD-2022-47212)

A vulnerability, which was classified as critical, was found in Dentsply Sirona Sidexis up to 4.3. Affected by this issue is some unknown functionality. Executing a manipulation can lead to unquoted search path. This vulnerability is regist

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2022-44263 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44263 | Dentsply Sirona Sidexis up to 4.3 access control (EUVD-2022-47211)

A vulnerability, which was classified as critical, has been found in Dentsply Sirona Sidexis up to 4.3. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper access controls. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.4%
CVE-2022-44261 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44261 | Avery Dennison Monarch Printer M9855 cross site scripting (EUVD-2022-47210)

A vulnerability labeled as problematic has been found in Avery Dennison Monarch Printer M9855. The affected element is an unknown function. Such manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
8.1 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61591 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.4 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 djust-org

CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.1 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-61597 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 31.2%
CVE-2026-92599 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 hapijs

CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in

joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 26%
CVE-2026-92598 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92598 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addres

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 30.7%
CVE-2026-92597 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92597 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as [email protected](x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registr

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.