CVE-2020-24932: Schwachstellen-Eintrag (NVD)
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-14 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges
A vulnerability in Logitech Options+ allows a standard Windows user to gain SYSTEM-level privileges by exploiting a weakness in the software’s updater service. Tracked as CVE-2026-12518, the issue requires no administrator rights, network a
CVE-2025-40123 | Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2 bpf_prog_test_run_xdp null pointer dereference (Nessus ID 276782 / WID-SEC-2025-2579)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2. The affected element is the function bpf_prog_test_run_xdp. The manipulation results in null pointer dereference. This vulnerability wa
CVE-2025-39862 | Linux Kernel up to 6.16.5/6.17-rc4 mt7915 ieee80211_restart_hw denial of service (Nessus ID 265846 / WID-SEC-2025-2099)
A vulnerability has been found in Linux Kernel up to 6.16.5/6.17-rc4 and classified as critical. Impacted is the function ieee80211_restart_hw of the component mt7915. The manipulation leads to denial of service. This vulnerability is refer
CVE-2025-22101 | Linux Kernel up to 6.14.1 libwx privilege escalation (EUVD-2025-11193 / Nessus ID 240657)
A vulnerability classified as problematic was found in Linux Kernel up to 6.14.1. Affected is an unknown function of the component libwx. The manipulation results in privilege escalation. This vulnerability is reported as CVE-2025-22101. Th
CVE-2024-58097 | Linux Kernel up to 6.14.1 ath11k buf_id infinite loop (Nessus ID 240657 / WID-SEC-2025-0844)
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.14.1. Impacted is the function buf_id of the component ath11k. Such manipulation leads to infinite loop. This vulnerability is referenced as CVE-2024-58
CVE-2025-21649 | Linux Kernel up to 6.12.9/6.13-rc6 hns3 null pointer dereference (Nessus ID 214901 / WID-SEC-2025-0119)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.9/6.13-rc6. Affected by this vulnerability is an unknown functionality of the component hns3. Performing a manipulation results in null pointer der
CVE-2024-56639 | Linux Kernel up to 6.12.4 net net/core/skbuff.c hsr_init_skb allocation of resources (Nessus ID 233479 / WID-SEC-2024-3762)
A vulnerability classified as problematic has been found in Linux Kernel up to 6.12.4. This issue affects the function hsr_init_skb of the file net/core/skbuff.c of the component net. Performing a manipulation results in allocation of resou
CVE-2024-41062 | Linux Kernel up to 6.1.100/6.6.41/6.9.10 l2cap hci_rx_work null pointer dereference (Nessus ID 207884 / WID-SEC-2024-1722)
A vulnerability was found in Linux Kernel up to 6.1.100/6.6.41/6.9.10. It has been classified as critical. This issue affects the function hci_rx_work of the component l2cap. This manipulation causes null pointer dereference. This vulnerabi
CVE-2024-50029 | Linux Kernel up to 6.6.56/6.11.3 Bluetooth use after free (867639300759/98ccd44002d8/18fd04ad856d / Nessus ID 212094)
A vulnerability was found in Linux Kernel up to 6.6.56/6.11.3. It has been classified as critical. This vulnerability affects unknown code of the component Bluetooth. The manipulation leads to use after free. This vulnerability is reference
CVE-2026-87591 | Google Chrome up to 152.0.7977.82 Extensions improper authorization
A vulnerability marked as critical has been reported in Google Chrome. The affected element is an unknown function of the component Extensions. The manipulation leads to improper authorization. This vulnerability is listed as CVE-2026-87591
CVE-2026-87590 | Google Chrome up to 152.0.7977.82 Passwords information disclosure
A vulnerability labeled as problematic has been found in Google Chrome. Impacted is an unknown function of the component Passwords. Executing a manipulation can lead to information disclosure. This vulnerability is tracked as CVE-2026-87590
CVE-2026-87589 | Google Chrome up to 152.0.7977.82 SiteIsolation privileges management
A vulnerability identified as critical has been detected in Google Chrome. This issue affects some unknown processing of the component SiteIsolation. Performing a manipulation results in improper privilege management. This vulnerability is
CVE-2026-87584 | Google Chrome up to 152.0.7977.82 WebUI access control
A vulnerability was found in Google Chrome and classified as critical. Affected is an unknown function of the component WebUI. Executing a manipulation can lead to improper access controls. This vulnerability is handled as CVE-2026-87584. T
CVE-2026-87580 | Google Chrome up to 152.0.7977.82 WebAppInstalls improper authorization (Nessus ID 344263)
A vulnerability, which was classified as critical, has been found in Google Chrome. The impacted element is an unknown function of the component WebAppInstalls. This manipulation causes improper authorization. This vulnerability appears as
CVE-2026-87522 | Google Chrome up to 152.0.7977.82 WebView access control
A vulnerability, which was classified as critical, was found in Google Chrome. This affects an unknown function of the component WebView. Executing a manipulation can lead to improper access controls. This vulnerability is registered as CVE
CVE-2026-87519 | Google Chrome up to 152.0.7977.82 Safebrowsing access control
A vulnerability classified as critical has been found in Google Chrome. This affects an unknown function of the component Safebrowsing. Performing a manipulation results in improper access controls. This vulnerability is identified as CVE-2
CVE-2026-86418 | CIRCL MISP up to 2.5.45 Dashboard Organisation Picker createConditions User information disclosure (8ca4486af)
A vulnerability described as problematic has been identified in CIRCL MISP up to 2.5.45. This affects the function Organisation::createConditions of the component Dashboard Organisation Picker. Executing a manipulation of the argument User
CVE-2026-86452 | MISP up to 2.5.45 Forgot Password Reset Endpoint email memory corruption (d75d899be)
A vulnerability was found in MISP up to 2.5.45. It has been classified as critical. The impacted element is an unknown function of the component Forgot Password Reset Endpoint. The manipulation of the argument email leads to memory corrupti
CVE-2026-14298 | Mattermost up to 11.9.x Boards Archive Import allocation of resources
A vulnerability labeled as problematic has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0/11.9.x. Impacted is an unknown function of the component Boards Archive Import Handler. Executing a manipulation can lead to allocation
CVE-2025-53341 | Themovation Stratus Plugin up to 4.2.5 on WordPress authorization
A vulnerability, which was classified as problematic, has been found in Themovation Stratus Plugin up to 4.2.5 on WordPress. This affects an unknown part. Performing a manipulation results in missing authorization. This vulnerability was na
CVE-2024-44951 | Linux Kernel up to 6.10.4 sc16is7xx kfifo_out_linear_ptr buffer overflow (09cfe05e9907/133f4c00b8b2 / Nessus ID 208423)
A vulnerability described as critical has been identified in Linux Kernel up to 6.10.4. This affects the function kfifo_out_linear_ptr of the component sc16is7xx. Executing a manipulation can lead to buffer overflow. This vulnerability is h
CVE-2024-44952 | Linux Kernel up to 6.10.4 uevent_show deadlock (Nessus ID 208245 / WID-SEC-2024-2057)
It seems this issue is a false-positive. Please confirm the sources provided and consider disregarding this entry. Weiterlesen
CVE-2024-44950 | Linux Kernel up to 6.10.4 IRQ sc16is7xx_startup privilege escalation (6a6730812220/7d3b793faaab / Nessus ID 208423)
A vulnerability marked as problematic has been reported in Linux Kernel up to 6.10.4. Affected is the function sc16is7xx_startup of the component IRQ Handler. The manipulation leads to privilege escalation. This vulnerability is traded as C
CVE-2024-44949 | Linux Kernel up to 6.6.45/6.10.4 parisc arch_slab_minalign memory corruption (642a0b7453da/533de2f470ba/7ae04ba36b38 / Nessus ID 211777)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.45/6.10.4. Affected by this vulnerability is the function arch_slab_minalign of the component parisc. This manipulation causes memory corruption. Th
CVE-2024-44948 | Linux Kernel up to 6.10.4 mtrr_save_state state issue (Nessus ID 208245 / WID-SEC-2024-2057)
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.10.4. This impacts the function mtrr_save_state. Executing a manipulation can lead to state issue. This vulnerability appears as CVE-2024-44948. The attacker need
CVE-2024-44947 | Linux Kernel up to 6.1.106/6.6.47/6.10.6 fuse fuse_notify_store information disclosure (Nessus ID 207884 / WID-SEC-2024-2057)
A vulnerability has been found in Linux Kernel up to 6.1.106/6.6.47/6.10.6 and classified as problematic. The impacted element is the function fuse_notify_store of the component fuse. This manipulation causes information disclosure. The ide
CVE-2024-44946 | Linux Kernel up to 6.1.106/6.6.47/6.10.6 include/linux/skbuff.h kcm_release use after free (Nessus ID 208099 / WID-SEC-2024-2057)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.1.106/6.6.47/6.10.6. Impacted is the function kcm_release in the library include/linux/skbuff.h. The manipulation results in use after free. This vulnerabil
CVE-2025-4435 | Python CPython up to 3.14.0b1 calculation (Issue 135034 / EUVD-2025-16725)
A vulnerability has been found in Python CPython up to 3.14.0b1 and classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in incorrect calculation. This vulnerability is identifie
Nintendo warns of Switch code execution flaw via on-screen QR codes
Nintendo has patched a high-severity Nintendo Switch vulnerability that could allow a nearby attacker to execute unauthorized code or access information stored on the console. The flaw, tracked as CVE-2026-82079, affects Switch systems runn
CVE-2026-90843 | SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25 New Nmap Scan functions_nmap.py nmap_newscan target/params os command injection
A vulnerability described as critical has been identified in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler.
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg
[UPDATE] [mittel] CPython: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CPython ausnutzen, um Dateien zu manipulieren. Weiterlesen
[UPDATE] [mittel] FasterXML Jackson: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FasterXML Jackson ausnutzen, um Informationen offenzulegen. Weiterlesen
Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution
A critical vulnerability in vBulletin lets unauthenticated remote attackers execute arbitrary PHP code on a vulnerable forum server, creating a direct path to server compromise. Tracked as CVE-2026-61511, the issue affects vBulletin 6.2.1 a
CISA warnt: GitLab-Schlagloch CVE-2026-85706 aktiv ausgenutzt
USA / LONDON (IT BOLTWISE) – Die US-Cybersicherheitsbehörde CISA meldet, dass Angreifer eine GitLab-Sicherheitslücke maximaler Schwere (CVE-2026-85706) bereits ausnutzen. Betroffen ist ein DevSecOps-Feature, bei dem fehlende Authentifizieru
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519
Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials
A critical vulnerability in the AWS Systems Manager (SSM) Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, and steal temporary IAM credentials assigned to Amazon EC2
GitHub Pays $100,000 Bounty for Critical RCE Flaw Triggered by a Single Git Push
GitHub has reportedly awarded a $100,000 bug bounty to security researcher Saif Ghani for identifying a critical remote code execution vulnerability that could be triggered through a specially crafted Git repository operation. The flaw, tra
Critical Check Point VPN Flaws Could Face Large-Scale Exploitation, NCSC Warns
The Netherlands’ National Cyber Security Center (NCSC) has warned organizations to urgently patch two critical vulnerabilities in Check Point VPN products, saying widespread exploitation attempts are likely to begin soon. Tracked as CVE-202
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading