🎯 CVE-2020-17456 CRITICAL 9.8 🔥 EPSS 56.5%
📄 .md Alle CVEs anzeigen ✕

CVE-2020-17456: Schwachstellen-Eintrag (NVD)

SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.

Klassifikation & Betroffenheit:
seowonintech slr-120s42g_firmware *seowonintech slr-120d42g_firmware *seowonintech slr-120t42g_firmware *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🧪 Exploit-Evidenz: EDB-50821 · Seowon SLR-120 Router - Remote Code Execution (Unauthenticated)
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 9.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:20.08.2020
Aktualisiert:17.06.2026 02:58
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
4 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 186 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.547 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-11
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 58
Apache 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 30%
CVE-2026-55524 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55524 | MervinPraison PraisonAI up to 1.6.57 web_crawl server-side request forgery

A vulnerability was found in MervinPraison PraisonAI up to 1.6.57. It has been classified as critical. This affects the function web_crawl. The manipulation leads to server-side request forgery. This vulnerability is referenced as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-55523 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55523 | MervinPraison PraisonAI 1.5.128-1.6.57 Web Crawl Tools web_crawl_tools.py praisonaiagents.tools.web_crawl_tools.web_crawl url server-side request forgery

A vulnerability, which was classified as critical, has been found in MervinPraison PraisonAI 1.5.128-1.6.57. Affected by this issue is the function praisonaiagents.tools.web_crawl_tools.web_crawl of the file praisonaiagents/tools/web_crawl_

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.5%
CVE-2026-55522 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55522 | MervinPraison PraisonAI/praisonaiagents Tool Loader tools.py Workflow._execute_include code injection

A vulnerability marked as critical has been reported in MervinPraison PraisonAI and praisonaiagents. This affects the function Workflow._execute_include of the file tools.py of the component Tool Loader. This manipulation causes code inject

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.5%
CVE-2026-70612 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70612 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 iFrame Sandbox setPermissionRequestHandler sandbox

A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been declared as critical. Affected by this vulnerability is the function setPermissionRequestHandler of the component iFrame Sandbox. The manipulation r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.9%
CVE-2026-70611 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70611 | Electron up to 39.8.8/40.9.1/41.2.0/42.0.0-beta.2 DevTools showItemInFolder sandbox

A vulnerability was found in Electron up to 39.8.8/40.9.1/41.2.0/42.0.0-beta.2 and classified as critical. The affected element is the function showItemInFolder of the component DevTools. Such manipulation leads to sandbox issue. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2026-70610 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70610 | Electron up to 39.8.8/40.9.1/41.2.1/42.0.0-beta.3 contextBridge prototype pollution

A vulnerability, which was classified as critical, has been found in Electron up to 39.8.8/40.9.1/41.2.1/42.0.0-beta.3. This vulnerability affects unknown code of the component contextBridge. The manipulation leads to improperly controlled

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2026-38057 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-38057 | ST Engineering iDirect Evolution iQ-Series terminals up to 4.5.2.1 API endpoint /api/reboot SameSite cross-site request forgery

A vulnerability was found in ST Engineering iDirect Evolution iQ-Series terminals, 3315-Series and 9-Series Terminals up to 4.5.2.1. It has been classified as problematic. This impacts the function reboot of the file /api/reboot of the comp

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.8%
CVE-2026-38059 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-38059 | ST Engineering iDirect Evolution iQ-Series terminals up to 4.5.2.1 REST API Endpoint /api/identity information disclosure

A vulnerability, which was classified as problematic, was found in ST Engineering iDirect Evolution iQ-Series terminals, 3315-Series and 9-Series Terminals up to 4.5.2.1. This affects an unknown function of the file /api/identity of the com

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2026-58592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58592 | LadybirdBrowser Ladybird WebAssembly WebAssemblyModule.cpp expired pointer dereference

A vulnerability categorized as problematic has been discovered in LadybirdBrowser Ladybird. Affected by this issue is some unknown functionality of the file WebAssemblyModule.cpp of the component WebAssembly Module. The manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.8%
CVE-2026-48168 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48168 | MervinPraison PraisonAI up to 4.6.39 Claude GitHub Actions Workflow command injection

A vulnerability has been found in MervinPraison PraisonAI up to 4.6.39 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Claude GitHub Actions Workflow. The manipulation leads to command

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-66738 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66738 | SPIP up to 4.4.17 Navigation Menu Endpoint code injection

A vulnerability was found in SPIP up to 4.4.17 and classified as critical. This vulnerability affects unknown code of the component Navigation Menu Endpoint. The manipulation results in code injection. This vulnerability is known as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2025-36572 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-36572 | Dell PowerStore 4.0.0.0 Image File hard-coded credentials (dsa-2025-223)

A vulnerability was found in Dell PowerStore 4.0.0.0. It has been rated as critical. This issue affects some unknown processing of the component Image File Handler. The manipulation leads to hard-coded credentials. This vulnerability is uni

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.8%
CVE-2026-28265 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-28265 | Dell PowerStore path traversal (dsa-2026-157)

A vulnerability was found in Dell PowerStore, PowerStore 500T, PowerStore 1000T, PowerStore 1200T, PowerStore 3000T, PowerStore 3200Q, PowerStore 3200T, PowerStore 5000T, PowerStore 5200Q, PowerStore 5200T, PowerStore 7000T, PowerStore 9000

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.1%
CVE-2026-48158 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48158 | dai-shi use-context-selector src/install.js permission

A vulnerability classified as critical was found in dai-shi use-context-selector. This affects an unknown function of the file src/install.js. Such manipulation leads to permission issues. This vulnerability is listed as CVE-2026-48158. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.8%
CVE-2026-63105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63105 | Razinsoft Ready eCommerce up to 4.5.1 Messaging System Messages.vue cross site scripting

A vulnerability marked as problematic has been reported in Razinsoft Ready eCommerce up to 4.5.1. This affects an unknown part of the file Messages.vue of the component Messaging System. The manipulation leads to cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 27%
CVE-2026-63106 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63106 | Razinsoft Ready eCommerce up to 4.5.1 Product Listing API ProductController.php rating sql injection

A vulnerability, which was classified as critical, was found in Razinsoft Ready eCommerce up to 4.5.1. This issue affects some unknown processing of the file ProductController.php of the component Product Listing API. Such manipulation of t

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.1%
CVE-2026-52880 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52880 | klever-io klever-go up to 1.7.17 REST API Gin Engine.Run denial of service (EUVD-2026-54722)

A vulnerability was found in klever-io klever-go up to 1.7.17. It has been declared as problematic. Affected by this vulnerability is the function Gin Engine.Run of the component REST API. Such manipulation leads to denial of service. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.8%
CVE-2026-52878 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52878 | Klever-IO Klever-Go up to 1.7.17 Pubsub Topic-Validator Callback txVersionChecker.CheckTxVersion null pointer dereference

A vulnerability has been found in Klever-IO Klever-Go up to 1.7.17 and classified as problematic. This affects the function txVersionChecker.CheckTxVersion of the component Pubsub Topic-Validator Callback. The manipulation leads to null poi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.6%
CVE-2026-52879 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52879 | klever-io klever-go up to 1.7.17 Direct-Message Ingress allocation of resources

A vulnerability, which was classified as problematic, has been found in klever-io klever-go up to 1.7.17. The affected element is an unknown function of the component Direct-Message Ingress Handler. Performing a manipulation results in allo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2022-43640 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43640 | Foxit PDF Reader PDF File Parser out-of-bounds (ZDI-22-1660 / EUVD-2022-46636)

A vulnerability, which was classified as problematic, has been found in Foxit PDF Reader. Affected by this vulnerability is an unknown functionality of the component PDF File Parser. The manipulation leads to out-of-bounds read. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.6%
CVE-2022-43639 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43639 | Foxit PDF Reader U3D File Parser use after free (ZDI-22-1659 / EUVD-2022-46635)

A vulnerability labeled as critical has been found in Foxit PDF Reader. The affected element is an unknown function of the component U3D File Parser. The manipulation results in use after free. This vulnerability was named CVE-2022-43639. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.2%
CVE-2022-43638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43638 | Foxit PDF Reader U3D File Parser use after free (ZDI-22-1658 / EUVD-2022-46634)

A vulnerability marked as critical has been reported in Foxit PDF Reader. The impacted element is an unknown function of the component U3D File Parser. This manipulation causes use after free. The identification of this vulnerability is CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-47249 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47249 | klever-io klever-go up to 1.7.17 Resolver Batch.Decompress allocation of resources

A vulnerability labeled as problematic has been found in klever-io klever-go up to 1.7.17. Affected by this issue is the function Batch.Decompress of the component Resolver. Executing a manipulation can lead to allocation of resources. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2026-42016 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-42016 | JFrog Artifactory up to 7.133.10 privileges management

A vulnerability identified as critical has been detected in JFrog Artifactory up to 7.133.10. Impacted is an unknown function. Performing a manipulation results in improper privilege management. This vulnerability was named CVE-2026-42016.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-59717 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59717 | Home Assistant up to 2026.6.0 Onboarding Flow /auth/authorize redirect

A vulnerability was found in Home Assistant up to 2026.6.0. It has been classified as problematic. This issue affects some unknown processing of the file /auth/authorize of the component Onboarding Flow. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-48026 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48026 | Treeverse lakeFS/lakeFS-Enterprise up to 1.81.0/1.83.0 Web UI README.md cross site scripting (EUVD-2026-54717)

A vulnerability classified as problematic was found in Treeverse lakeFS and lakeFS-Enterprise up to 1.81.0/1.83.0. Impacted is an unknown function of the file README.md of the component Web UI. Such manipulation leads to cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.1%
CVE-2026-47243 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47243 | Kata Containers kata-containers up to 3.30.x virtiofsd symlink

A vulnerability classified as critical has been found in Kata Containers kata-containers up to 3.30.x. This affects an unknown part of the component virtiofsd. The manipulation leads to symlink following. This vulnerability is uniquely iden

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2026-58262 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58262 | klever-io klever-go up to 1.7.19 signature verification (EUVD-2026-54712)

A vulnerability identified as problematic has been detected in klever-io klever-go up to 1.7.19. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper verification of cryptographic signatu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-66061 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66061 | home-assistant Home Assistant 1.10.0 improper authorization

A vulnerability, which was classified as problematic, has been found in home-assistant Home Assistant 1.10.0. This vulnerability affects unknown code. This manipulation causes improper authorization. This vulnerability is registered as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-54338 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-54338 | JupyterHub up to 5.4.x Form-based Login Authenticator resource consumption (Nessus ID 333522)

A vulnerability classified as problematic has been found in JupyterHub up to 5.4.x. Affected by this issue is some unknown functionality of the component Form-based Login Authenticator. The manipulation leads to resource consumption. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.1%
CVE-2026-69207 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69207 | honojs Hono up to 4.12.33 CORS Middleware cors redos

A vulnerability classified as problematic was found in honojs Hono up to 4.12.33. This affects the function cors of the component CORS Middleware. The manipulation results in inefficient regular expression complexity. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2026-73515 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73515 | PostGIS 2.3.3 FlatGeobuf property metadata decoder out-of-bounds (WID-SEC-2026-3306)

A vulnerability was found in PostGIS 2.3.3 and classified as critical. Affected is an unknown function of the component FlatGeobuf property metadata decoder. The manipulation results in out-of-bounds read. This vulnerability is reported as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2022-43637 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43637 | Foxit PDF Reader U3D File Parser use after free (ZDI-22-1657 / EUVD-2022-46633)

A vulnerability described as critical has been identified in Foxit PDF Reader. This affects an unknown function of the component U3D File Parser. Such manipulation leads to use after free. This vulnerability is referenced as CVE-2022-43637.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2022-43636 💻 Lokal 🔓 Keine Authentifizierung nötig
Apache

CVE-2022-43636 | TP-Link TL-WR940N httpd random values (ZDI-22-1614 / EUVD-2022-46632)

A vulnerability classified as problematic has been found in TP-Link TL-WR940N. Affected by this vulnerability is an unknown functionality of the component httpd. The manipulation leads to insufficiently random values. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 19.7%
CVE-2022-43634 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43634 | Netatalk dsi_writeinit heap-based overflow (EUVD-2022-46630)

A vulnerability categorized as critical has been discovered in Netatalk. Affected is the function dsi_writeinit. Such manipulation leads to heap-based buffer overflow. This vulnerability is referenced as CVE-2022-43634. It is possible to la

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.3%
CVE-2022-43635 💻 Lokal 🔓 Keine Authentifizierung nötig
Apache

CVE-2022-43635 | TP-Link TL-WR940N httpd information disclosure (ZDI-22-1615 / EUVD-2022-46631)

A vulnerability categorized as problematic has been discovered in TP-Link TL-WR940N. The affected element is an unknown function of the component httpd. The manipulation results in information disclosure. This vulnerability is known as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.4%
CVE-2022-43633 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43633 | D-Link DIR-1935 SetSysLogSettings command injection (ZDI-22-1505 / EUVD-2022-46629)

A vulnerability has been found in D-Link DIR-1935 and classified as critical. Affected by this vulnerability is the function SetSysLogSettings. This manipulation causes command injection. This vulnerability is handled as CVE-2022-43633. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2022-43631 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43631 | D-Link DIR-1935 SetVirtualServerSettings VirtualServerInfo command injection (ZDI-22-1502 / EUVD-2022-46627)

A vulnerability was found in D-Link DIR-1935. It has been classified as critical. This affects the function SetVirtualServerSettings. Performing a manipulation of the argument VirtualServerInfo results in command injection. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2022-43632 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43632 | D-Link DIR-1935 SetQoSSettings QoSInfo command injection (ZDI-22-1504 / EUVD-2022-46628)

A vulnerability was found in D-Link DIR-1935 and classified as critical. Affected by this issue is the function SetQoSSettings. Such manipulation of the argument QoSInfo leads to command injection. This vulnerability is uniquely identified

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2022-43629 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43629 | D-Link DIR-1935 SetSysEmailSettings command injection (ZDI-22-1500 / EUVD-2022-46625)

A vulnerability was found in D-Link DIR-1935. It has been rated as critical. This issue affects the function SetSysEmailSettings. The manipulation leads to command injection. This vulnerability is referenced as CVE-2022-43629. The attack ne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.4%
CVE-2022-43630 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43630 | D-Link DIR-1935 SOAPAction stack-based overflow (ZDI-22-1501 / EUVD-2022-46626)

A vulnerability was found in D-Link DIR-1935. It has been declared as critical. This vulnerability affects the function SOAPAction. Executing a manipulation can lead to stack-based buffer overflow. The identification of this vulnerability i

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2022-43628 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43628 | D-Link DIR-1935 SetIPv6FirewallSettings IPv6FirewallRule command injection (ZDI-22-1499 / EUVD-2022-46624)

A vulnerability labeled as critical has been found in D-Link DIR-1935. The impacted element is the function SetIPv6FirewallSettings. Such manipulation of the argument IPv6FirewallRule leads to command injection. This vulnerability is listed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

cPanel ConfigServer Security &amp; Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

A critical vulnerability in ConfigServer Security &amp;amp; Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security &amp;amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 74.6%
CVE-2026-85102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2026-70429 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70429 | Jenkins Project up to 2.567.x privileges management

A vulnerability labeled as critical has been found in Jenkins Project Jenkins up to 2.567.x. The affected element is an unknown function. Executing a manipulation can lead to improper privilege management. This vulnerability is handled as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2026-70609 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70609 | Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 DevTools webContents.openDevTools mode sandbox

A vulnerability has been found in Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 and classified as critical. Impacted is the function webContents.openDevTools of the component DevTools. This manipulation of the argument mode causes sandb

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-70608 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70608 | Electron up to 39.8.9/41.10.2/42.0.0 iFrame Sandbox sandbox

A vulnerability, which was classified as critical, was found in Electron up to 39.8.9/41.10.2/42.0.0. This issue affects some unknown processing of the component iFrame Sandbox. The manipulation results in sandbox issue. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2024-7049 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-7049 | open-webui up to 0.3.8 wrong session

This issue appears to be a false-positive. Please verify the sources mentioned and consider not using this entry at all. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-70607 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70607 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 BrowserWindow window.open input validation

A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been declared as critical. This affects the function window.open of the component BrowserWindow. The manipulation results in improper input validation. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.6%
CVE-2026-70602 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70602 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Extension Tab/Scripting APIs information disclosure

A vulnerability labeled as problematic has been found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. This affects an unknown function of the component Extension Tab/Scripting APIs. Executing a manipulation can lead to information dis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2026-70605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70605 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Redirect net.fetch/net.request redirect

A vulnerability identified as problematic has been detected in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. The impacted element is the function net.fetch/net.request of the component Redirect Handler. Performing a manipulation result

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24%
CVE-2026-70603 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70603 | Electron up to 39.8.5/40.8.x/41.1.0/42.0.0-beta.0 Shell shell.openPath input validation

A vulnerability was found in Electron up to 39.8.5/40.8.x/41.1.0/42.0.0-beta.0. It has been rated as critical. Impacted is the function shell.openPath of the component Shell. This manipulation causes improper input validation. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.5%
CVE-2026-70606 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70606 | Electron up to 40.10.5/41.9.0/42.5.0 Custom Protocol information disclosure

A vulnerability classified as problematic was found in Electron up to 40.10.5/41.9.0/42.5.0. This impacts an unknown function of the component Custom Protocol Handler. The manipulation results in information disclosure. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-70604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70604 | Electron up to 39.8.9/40.9.2/41.3.9 Custom Scheme cross-domain policy

A vulnerability described as problematic has been identified in Electron up to 39.8.9/40.9.2/41.3.9. The impacted element is an unknown function of the component Custom Scheme. Executing a manipulation can lead to permissive cross-domain po

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-78575 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78575 | IBM Langflow OSS up to 1.11.5 MCP stdio server command injection (WID-SEC-2026-3239)

A vulnerability has been found in IBM Langflow OSS up to 1.11.5 and classified as critical. The affected element is an unknown function of the component MCP stdio server. This manipulation causes command injection. This vulnerability is reg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2026-78569 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78569 | IBM Langflow OSS up to 1.11.5 Security Scanner access control (WID-SEC-2026-3239)

A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.11.5. The impacted element is an unknown function of the component Security Scanner. This manipulation causes improper access controls. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2026-78571 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78571 | IBM Langflow up to 1.11.5 eval code injection (WID-SEC-2026-3239)

A vulnerability was found in IBM Langflow up to 1.11.5. It has been declared as critical. This impacts the function eval. Executing a manipulation can lead to code injection. This vulnerability appears as CVE-2026-78571. The attack may be p

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.