🎯 CVE-2020-11306 HIGH 7.8 🔥 EPSS 18.5%
📄 .md Alle CVEs anzeigen ✕

CVE-2020-11306: Schwachstellen-Eintrag (NVD)

Possible integer overflow in RPMB counter due to lack of length check on user provided data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.8
AV · Angriffsvektor Lokal
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:09.06.2021
Aktualisiert:17.06.2026 02:50
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 186 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.547 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-11
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 58
WordPress 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 20.6%
CVE-2026-46358 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-46358 | OpenBao up to 2.5.3 Inline Auth Functionality missing encryption

A vulnerability was found in OpenBao up to 2.5.3. It has been declared as problematic. Impacted is an unknown function of the component Inline Auth Functionality. Executing a manipulation can lead to missing encryption of sensitive data. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.9%
CVE-2026-65819 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-65819 | gopacket up to 1.7.0 Layer Decoders DecodeFromBytes buffer overflow (210f25f / Nessus ID 333523)

A vulnerability, which was classified as problematic, has been found in gopacket up to 1.7.0. This affects the function DecodeFromBytes of the component Layer Decoders. Performing a manipulation results in buffer overflow. This vulnerabilit

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-61808 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61808 | HKUDS LightRAG up to 1.5.4 API Server improper authentication

A vulnerability, which was classified as critical, has been found in HKUDS LightRAG up to 1.5.4. Affected by this vulnerability is an unknown functionality of the component API Server. The manipulation leads to improper authentication. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.9%
CVE-2026-62296 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62296 | hapifhir HAPI FHIR up to 6.9.10 Xhtml Parser XhtmlParser.java parseElementInner input validation

A vulnerability classified as problematic was found in hapifhir HAPI FHIR up to 6.9.10. Affected is the function parseElementInner of the file XhtmlParser.java of the component Xhtml Parser. Executing a manipulation can lead to improper inp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-47661 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47661 | aehrc Pathling up to 1.x Async Export File path traversal

A vulnerability classified as problematic has been found in aehrc Pathling up to 1.x. This impacts an unknown function of the component Async Export. Performing a manipulation of the argument File results in path traversal. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2026-62293 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62293 | HAPI FHIR up to 6.9.10 Scanner Scanner.java cross site scripting

A vulnerability identified as problematic has been detected in HAPI FHIR up to 6.9.10. Impacted is an unknown function of the file Scanner.java of the component Scanner. The manipulation leads to cross site scripting. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2026-47660 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47660 | aehrc Pathling up to 1.x Bulk Submit Operation oauthMetadataUrl insufficiently protected credentials

A vulnerability described as critical has been identified in aehrc Pathling up to 1.x. This affects an unknown function of the component Bulk Submit Operation. Such manipulation of the argument oauthMetadataUrl leads to insufficiently prote

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-48039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48039 | pipeboard-co meta-ads-mcp up to 1.0.108 Auth Injection Middleware http_auth_integration.py AuthInjectionMiddleware.dispatch improper authentication

A vulnerability was found in pipeboard-co meta-ads-mcp up to 1.0.108. It has been declared as critical. This affects the function AuthInjectionMiddleware.dispatch of the file http_auth_integration.py of the component Auth Injection Middlewa

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.2%
CVE-2026-48007 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48007 | Element HQ Element Call up to 0.5.17/0.19.3 Analytics Reporting config.json information disclosure

A vulnerability categorized as problematic has been discovered in Element HQ Element Call up to 0.5.17/0.19.3. This issue affects some unknown processing of the file config.json of the component Analytics Reporting. Executing a manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.4%
CVE-2026-71850 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71850 | honojs Hono up to 4.12.33 jsx memo information disclosure

A vulnerability classified as problematic has been found in honojs Hono up to 4.12.33. This vulnerability affects the function memo of the component jsx. The manipulation leads to information disclosure. This vulnerability is documented as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2026-47659 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47659 | aehrc Pathling up to 1.x Result Endpoint File path traversal

A vulnerability marked as problematic has been reported in aehrc Pathling up to 1.x. The impacted element is an unknown function of the component Result Endpoint Handler. This manipulation of the argument File causes path traversal. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.2%
CVE-2026-48098 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48098 | 0x5t4l1n NexTor IP Changer up to 1.x privileges management

A vulnerability labeled as problematic has been found in 0x5t4l1n NexTor IP Changer up to 1.x. This vulnerability affects unknown code. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.5%
CVE-2026-48097 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48097 | 0x5t4l1n NexTor IP Changer up to 1.x os command injection

A vulnerability identified as problematic has been detected in 0x5t4l1n NexTor IP Changer up to 1.x. This affects an unknown part. Performing a manipulation results in os command injection. This vulnerability is identified as CVE-2026-48097

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.3%
CVE-2026-71848 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71848 | Honojs Hono up to 4.12.33 languageDetector normalizeLanguage resource consumption

A vulnerability described as problematic has been identified in Honojs Hono up to 4.12.33. This affects the function normalizeLanguage of the component languageDetector. Executing a manipulation can lead to resource consumption. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.9%
CVE-2026-71849 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71849 | honojs Hono up to 4.12.33 Proxy Helper proxy information disclosure

A vulnerability marked as problematic has been reported in honojs Hono up to 4.12.33. Affected by this issue is the function proxy of the component Proxy Helper. Performing a manipulation results in information disclosure. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-56818 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-56818 | Netty prior 4.1.136.Final/4.2.16.Final RedisArrayAggregator decodeRedisArrayHeader allocation of resources

A vulnerability categorized as problematic has been discovered in Netty. The affected element is the function decodeRedisArrayHeader of the component RedisArrayAggregator. Executing a manipulation can lead to allocation of resources. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-70591 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70591 | TryGhost up to 6.54.0 server-side request forgery

A vulnerability described as problematic has been identified in TryGhost Ghost up to 6.54.0. This affects an unknown part. The manipulation results in server-side request forgery. This vulnerability is reported as CVE-2026-70591. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-45705 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45705 | OpenSIPS up to 3.6.5 Multipart Body Parser find_line_delimiter out-of-bounds

A vulnerability was found in OpenSIPS up to 3.6.5. It has been classified as critical. This impacts the function find_line_delimiter of the component Multipart Body Parser. This manipulation causes out-of-bounds read. The identification of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2026-45537 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45537 | OpenSIPS up to 3.6.5 URI Construction construct_uri Username buffer overflow

A vulnerability has been found in OpenSIPS up to 3.6.5 and classified as very critical. The impacted element is the function construct_uri of the component URI Construction. The manipulation of the argument Username leads to buffer overflow

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.4%
CVE-2026-70593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70593 | TryGhost up to 6.54.0 LocalStorageBase path traversal

A vulnerability classified as critical has been found in TryGhost Ghost up to 6.54.0. This vulnerability affects unknown code of the component LocalStorageBase. This manipulation causes path traversal. This vulnerability appears as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-70470 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70470 | FlowiseAI Flowise up to 3.1.2 Python Code Validator pythonCodeValidator.ts validatePythonCodeForDataFrame os command injection

A vulnerability was found in FlowiseAI Flowise up to 3.1.2 and classified as critical. Affected by this issue is the function validatePythonCodeForDataFrame of the file packages/components/src/pythonCodeValidator.ts of the component Python

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-70594 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-70594 | TryGhost up to 6.54.0 Admin session fixiation

A vulnerability marked as problematic has been reported in TryGhost Ghost up to 6.54.0. Affected by this issue is some unknown functionality of the component Admin. The manipulation leads to session fixiation. This vulnerability is document

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-45103 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45103 | OpenSIPS prior 3.6.6/4.0.0-rc1 TCP Message Framing Layer integer overflow

A vulnerability identified as very critical has been detected in OpenSIPS. Affected is an unknown function of the component TCP Message Framing Layer. Performing a manipulation results in integer overflow. This vulnerability is cataloged as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.6%
CVE-2026-70592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70592 | TryGhost up to 6.54.0 Database Export Endpoint path traversal

A vulnerability labeled as problematic has been found in TryGhost Ghost up to 6.54.0. Affected by this vulnerability is an unknown functionality of the component Database Export Endpoint. Executing a manipulation can lead to path traversal.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2026-70590 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-70590 | TryGhost up to 6.54.0 Admin API privileges management

A vulnerability, which was classified as problematic, has been found in TryGhost Ghost up to 6.54.0. This affects an unknown part of the component Admin API. This manipulation causes improper privilege management. This vulnerability is hand

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-45100 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45100 | OpenSIPS prior 3.6.6/4.0.0-rc1 Base64 Encoding s.b64encode buffer overflow

A vulnerability categorized as very critical has been discovered in OpenSIPS. This impacts the function s.b64encode of the component Base64 Encoding. Such manipulation leads to buffer overflow. This vulnerability is listed as CVE-2026-45100

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.5%
CVE-2026-45084 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45084 | OpenSIPS up to 3.6.5 Presence handle_publish denial of service

A vulnerability labeled as problematic has been found in OpenSIPS up to 3.6.5. This affects the function handle_publish of the component Presence Module. Such manipulation leads to denial of service. This vulnerability is documented as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2026-70589 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70589 | TryGhost up to 6.54.0 input validation

A vulnerability classified as problematic was found in TryGhost Ghost up to 6.54.0. Affected by this issue is some unknown functionality. The manipulation results in improper input validation. This vulnerability is known as CVE-2026-70589.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-64835 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64835 | FFmpeg up to 8.1.2 ADX Decoder libavcodec/adxdec.c adx_decode_frame prev out-of-bounds (Nessus ID 333552 / WID-SEC-2026-2491)

A vulnerability categorized as critical has been discovered in FFmpeg up to 8.1.2. This affects the function adx_decode_frame of the file libavcodec/adxdec.c of the component ADX Decoder. Executing a manipulation of the argument prev can le

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.4%
CVE-2026-64833 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64833 | FFmpeg up to 8.1.2 SPDIF Muxer spdif_header_dts4 core_size out-of-bounds (Nessus ID 344622 / WID-SEC-2026-2491)

A vulnerability labeled as critical has been found in FFmpeg up to 8.1.2. Affected is the function spdif_header_dts4 of the component SPDIF Muxer. The manipulation of the argument core_size results in out-of-bounds read. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-64832 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64832 | FFmpeg up to 8.1.2 NVIDIA NVDEC hardware decoder libavcodec/nvdec.c ff_nvdec_start_frame_sep_ref memory corruption (Nessus ID 333552 / WID-SEC-2026-2491)

A vulnerability identified as critical has been detected in FFmpeg up to 8.1.2. This impacts the function ff_nvdec_start_frame_sep_ref of the file libavcodec/nvdec.c of the component NVIDIA NVDEC hardware decoder. The manipulation leads to

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.9%
CVE-2026-64834 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64834 | FFmpeg up to 8.1.2 ASF Demuxer libavformat/rtpdec_asf.c rtp_asf_fix_header infinite loop (Nessus ID 344622 / WID-SEC-2026-2491)

A vulnerability was found in FFmpeg up to 8.1.2. It has been rated as problematic. The impacted element is the function rtp_asf_fix_header of the file libavformat/rtpdec_asf.c of the component ASF Demuxer. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24%
CVE-2026-64831 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64831 | FFmpeg up to 8.1.2 Vulkan HEVC hardware decoder vk_hevc_end_frame vps_num_hrd_parameters stack-based overflow (WID-SEC-2026-2491)

A vulnerability was found in FFmpeg up to 8.1.2. It has been classified as critical. Impacted is the function vk_hevc_end_frame of the component Vulkan HEVC hardware decoder. This manipulation of the argument vps_num_hrd_parameters causes s

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.2%
CVE-2026-64830 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64830 | FFmpeg up to 8.1.2 VobSub subtitle demuxer libavformat/mpeg.c ff_subtitles_queue_insert q heap-based overflow (Nessus ID 333552 / WID-SEC-2026-2491)

A vulnerability was found in FFmpeg up to 8.1.2. It has been declared as critical. The affected element is the function ff_subtitles_queue_insert of the file libavformat/mpeg.c of the component VobSub subtitle demuxer. Such manipulation of

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-66062 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66062 | SvelteJS Kit up to 2.70.1 Content Negotiation Header Parser resource consumption

A vulnerability was found in SvelteJS Kit up to 2.70.1. It has been declared as problematic. This issue affects some unknown processing of the component Content Negotiation Header Parser. Such manipulation leads to resource consumption. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-48093 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-48093 | dartiss Code Embed Plugin up to 2.6.0 on WordPress External URL Embed Feature cross site scripting

A vulnerability described as problematic has been identified in dartiss Code Embed Plugin up to 2.6.0 on WordPress. This issue affects some unknown processing of the component External URL Embed Feature. Executing a manipulation can lead to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
5.8 MEDIUM
EPSS 5.4%
CVE-2026-62996 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62996 | smarty-php Smarty up to 5.8.3 Stream information disclosure

A vulnerability has been found in smarty-php Smarty up to 5.8.3 and classified as problematic. The affected element is an unknown function of the component Stream Handler. This manipulation causes information disclosure. The identification

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-62992 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-62992 | smarty-php Smarty up to 4.5.6/5.8.1 Directory Validation Security::_checkDir path traversal

A vulnerability, which was classified as problematic, was found in smarty-php Smarty up to 4.5.6/5.8.1. Impacted is the function Security::_checkDir of the component Directory Validation. The manipulation results in path traversal. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.3%
CVE-2026-48094 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-48094 | dartiss ShareOpenly Plugin up to 1.2.0 on WordPress esc_url cross site scripting

A vulnerability, which was classified as problematic, has been found in dartiss ShareOpenly Plugin up to 1.2.0 on WordPress. Affected by this issue is the function esc_url. Performing a manipulation of the argument url results in cross site

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 28.7%
CVE-2026-71497 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71497 | jhy jsoup up to 1.23.0 HTML Parser HTML injection (WID-SEC-2026-2698)

A vulnerability was found in jhy jsoup up to 1.23.0. It has been declared as problematic. The impacted element is an unknown function of the component HTML Parser. The manipulation results in HTML injection. This vulnerability is known as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-71555 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71555 | THM-Health PILOS up to 4.14.0 cross-domain policy

A vulnerability, which was classified as problematic, has been found in THM-Health PILOS up to 4.14.0. This affects an unknown part. This manipulation causes permissive cross-domain policy with untrusted domains. This vulnerability is regis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.4%
CVE-2026-71433 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71433 | langchain-ai langgraph-checkpoint-postgres up to 3.1.0 information disclosure

A vulnerability identified as problematic has been detected in langchain-ai langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite up to 3.1.0. The impacted element is an unknown function. This manipulation causes information disclos

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2026-71430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71430 | uhop node-re2 up to 1.25.0 Replace WrappedRE2::Replace return value

A vulnerability was found in uhop node-re2 up to 1.25.0. It has been rated as problematic. This affects the function WrappedRE2::Replace of the component Replace. This manipulation causes unchecked return value. This vulnerability is handle

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.9%
CVE-2026-67434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67434 | PHPCSStandards PHP_CodeSniffer up to 3.13.5/4.0.1 command injection

A vulnerability classified as critical has been found in PHPCSStandards PHP_CodeSniffer up to 3.13.5/4.0.1. Affected by this vulnerability is an unknown functionality. This manipulation causes command injection. The identification of this v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.8%
CVE-2026-19127 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19127 | Gitroomhq Postiz up to 2.21.9 Billing improper authorization

A vulnerability marked as problematic has been reported in Gitroomhq Postiz up to 2.21.9. Affected by this issue is some unknown functionality of the component Billing. This manipulation causes improper authorization. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 23.8%
CVE-2026-63637 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63637 | dgraph-io Dgraph up to 25.3.7 Query Rewriter query_rewriter.go maybeQuoteArg sql injection

A vulnerability labeled as critical has been found in dgraph-io Dgraph up to 25.3.7. This affects the function maybeQuoteArg of the file graphql/resolve/query_rewriter.go of the component Query Rewriter. Executing a manipulation can lead to

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-39924 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-39924 | Flarum up to 1.8.15 Session Invalidation clearPasswordTokens session expiration

A vulnerability was found in Flarum up to 1.8.15. It has been classified as problematic. This affects the function TokensClearer::clearPasswordTokens of the component Session Invalidation. This manipulation causes session expiration. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.1%
CVE-2025-63822 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-63822 | SirenGPS 2.19.44 user identifier access control

A vulnerability classified as critical has been found in SirenGPS 2.19.44. This affects an unknown function. Performing a manipulation of the argument user identifier results in improper access controls. This vulnerability is reported as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.3%
CVE-2025-63823 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-63823 | My Safetipin 5.2.1 Authentication hard-coded credentials

A vulnerability described as critical has been identified in My Safetipin 5.2.1. The impacted element is an unknown function of the component Authentication Module. Such manipulation leads to hard-coded credentials. This vulnerability is do

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2026-71192 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71192 | OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0 S3API Middleware improper authorization

A vulnerability has been found in OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0 and classified as problematic. This affects an unknown part of the component S3API Middleware. Performing a manipulation results in improper authorization.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2026-39923 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-39923 | Flarum Framework up to 1.8.15 Password Reset handle password recovery

A vulnerability was found in Flarum Framework up to 1.8.15 and classified as critical. The impacted element is the function SavePasswordController::handle of the component Password Reset. The manipulation results in weak password recovery.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2025-70962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-70962 | Zosi Camera 4.2.8.823C01 hard-coded credentials

A vulnerability described as problematic has been identified in Zosi Camera 4.2.8.823C01. This impacts an unknown function. Executing a manipulation can lead to hard-coded credentials. This vulnerability is registered as CVE-2025-70962. It

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22%
CVE-2026-66747 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66747 | Zbtlink Router Firmware Command librctl.so popen improper authentication

A vulnerability was found in Zbtlink Router Firmware. It has been declared as very critical. Affected is the function popen of the file librctl.so of the component Command Handler. The manipulation results in improper authentication. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-47682 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47682 | cvat-ai CVAT up to 2.64.0 path traversal

A vulnerability was found in cvat-ai CVAT up to 2.64.0. It has been declared as critical. This impacts an unknown function. The manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-47682. The attack may be lau

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.5%
CVE-2026-52370 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52370 | O2OA 10 Forum Posting cross site scripting

A vulnerability was found in O2OA 10. It has been declared as problematic. The impacted element is an unknown function of the component Forum Posting. The manipulation results in cross site scripting. This vulnerability is identified as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-70619 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70619 | odysseus-dev Odysseus Embedding Backend improper authorization

A vulnerability marked as critical has been reported in odysseus-dev Odysseus. This impacts an unknown function of the component Embedding Backend. Performing a manipulation results in improper authorization. This vulnerability is reported

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-70620 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70620 | odysseus-dev Odysseus Embedding Endpoint server-side request forgery

A vulnerability was found in odysseus-dev Odysseus and classified as problematic. Impacted is an unknown function of the component Embedding Endpoint. Executing a manipulation can lead to server-side request forgery. The identification of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-48154 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48154 | pilinux GoRest up to 1.12.1 2FA twoFA.go race condition

A vulnerability marked as problematic has been reported in pilinux GoRest up to 1.12.1. This vulnerability affects unknown code of the file handler/login.go/handler/twoFA.go of the component 2FA. The manipulation leads to race condition. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.4%
CVE-2026-73282 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73282 | OpenBSD OpenSSH up to 10.4 use after free (Nessus ID 344614 / WID-SEC-2026-2747)

A vulnerability was found in OpenBSD OpenSSH up to 10.4 and classified as very critical. This vulnerability affects unknown code. Such manipulation leads to use after free. This vulnerability is referenced as CVE-2026-73282. It is possible

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2026-73281 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73281 | OpenBSD OpenSSH up to 10.4 ssh-agent locking (Nessus ID 344614 / WID-SEC-2026-2747)

A vulnerability described as critical has been identified in OpenBSD OpenSSH up to 10.4. This affects an unknown function of the component ssh-agent. Such manipulation leads to improper locking. This vulnerability is traded as CVE-2026-7328

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.