🎯 CVE-2020-24932 CRITICAL 9.8 🔥 EPSS 68.9%
📄 .md Alle CVEs anzeigen ✕

CVE-2020-24932: Schwachstellen-Eintrag (NVD)

An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

Klassifikation & Betroffenheit:
razormist complaint_management_system 1.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 🎯 High

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as…

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, consider using persistence layers such as Hibernate or Enterprise Java Beans, which can provide significant protection against SQL injection if used proper…
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 9.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:27.10.2021
Aktualisiert:17.06.2026 03:06
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
19 🔴 Critical im Radar
7 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
1 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 164 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.525 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-14
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 31.1%
CVE-2026-12518 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges

A vulnerability in Logitech Options+ allows a standard Windows user to gain SYSTEM-level privileges by exploiting a weakness in the software’s updater service. Tracked as CVE-2026-12518, the issue requires no administrator rights, network a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 21.6%
CVE-2025-40123 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-40123 | Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2 bpf_prog_test_run_xdp null pointer dereference (Nessus ID 276782 / WID-SEC-2025-2579)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2. The affected element is the function bpf_prog_test_run_xdp. The manipulation results in null pointer dereference. This vulnerability wa

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.7%
CVE-2025-39862 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-39862 | Linux Kernel up to 6.16.5/6.17-rc4 mt7915 ieee80211_restart_hw denial of service (Nessus ID 265846 / WID-SEC-2025-2099)

A vulnerability has been found in Linux Kernel up to 6.16.5/6.17-rc4 and classified as critical. Impacted is the function ieee80211_restart_hw of the component mt7915. The manipulation leads to denial of service. This vulnerability is refer

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 18.7%
CVE-2025-22101 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-22101 | Linux Kernel up to 6.14.1 libwx privilege escalation (EUVD-2025-11193 / Nessus ID 240657)

A vulnerability classified as problematic was found in Linux Kernel up to 6.14.1. Affected is an unknown function of the component libwx. The manipulation results in privilege escalation. This vulnerability is reported as CVE-2025-22101. Th

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24%
CVE-2024-58097 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-58097 | Linux Kernel up to 6.14.1 ath11k buf_id infinite loop (Nessus ID 240657 / WID-SEC-2025-0844)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.14.1. Impacted is the function buf_id of the component ath11k. Such manipulation leads to infinite loop. This vulnerability is referenced as CVE-2024-58

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24%
CVE-2025-21649 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2025-21649 | Linux Kernel up to 6.12.9/6.13-rc6 hns3 null pointer dereference (Nessus ID 214901 / WID-SEC-2025-0119)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.9/6.13-rc6. Affected by this vulnerability is an unknown functionality of the component hns3. Performing a manipulation results in null pointer der

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.4%
CVE-2024-56639 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-56639 | Linux Kernel up to 6.12.4 net net/core/skbuff.c hsr_init_skb allocation of resources (Nessus ID 233479 / WID-SEC-2024-3762)

A vulnerability classified as problematic has been found in Linux Kernel up to 6.12.4. This issue affects the function hsr_init_skb of the file net/core/skbuff.c of the component net. Performing a manipulation results in allocation of resou

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.6%
CVE-2024-41062 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-41062 | Linux Kernel up to 6.1.100/6.6.41/6.9.10 l2cap hci_rx_work null pointer dereference (Nessus ID 207884 / WID-SEC-2024-1722)

A vulnerability was found in Linux Kernel up to 6.1.100/6.6.41/6.9.10. It has been classified as critical. This issue affects the function hci_rx_work of the component l2cap. This manipulation causes null pointer dereference. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.3%
CVE-2024-50029 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-50029 | Linux Kernel up to 6.6.56/6.11.3 Bluetooth use after free (867639300759/98ccd44002d8/18fd04ad856d / Nessus ID 212094)

A vulnerability was found in Linux Kernel up to 6.6.56/6.11.3. It has been classified as critical. This vulnerability affects unknown code of the component Bluetooth. The manipulation leads to use after free. This vulnerability is reference

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.4%
CVE-2026-87591 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87591 | Google Chrome up to 152.0.7977.82 Extensions improper authorization

A vulnerability marked as critical has been reported in Google Chrome. The affected element is an unknown function of the component Extensions. The manipulation leads to improper authorization. This vulnerability is listed as CVE-2026-87591

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.8%
CVE-2026-87590 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87590 | Google Chrome up to 152.0.7977.82 Passwords information disclosure

A vulnerability labeled as problematic has been found in Google Chrome. Impacted is an unknown function of the component Passwords. Executing a manipulation can lead to information disclosure. This vulnerability is tracked as CVE-2026-87590

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-87589 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87589 | Google Chrome up to 152.0.7977.82 SiteIsolation privileges management

A vulnerability identified as critical has been detected in Google Chrome. This issue affects some unknown processing of the component SiteIsolation. Performing a manipulation results in improper privilege management. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-87584 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87584 | Google Chrome up to 152.0.7977.82 WebUI access control

A vulnerability was found in Google Chrome and classified as critical. Affected is an unknown function of the component WebUI. Executing a manipulation can lead to improper access controls. This vulnerability is handled as CVE-2026-87584. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-87580 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87580 | Google Chrome up to 152.0.7977.82 WebAppInstalls improper authorization (Nessus ID 344263)

A vulnerability, which was classified as critical, has been found in Google Chrome. The impacted element is an unknown function of the component WebAppInstalls. This manipulation causes improper authorization. This vulnerability appears as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2026-87522 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87522 | Google Chrome up to 152.0.7977.82 WebView access control

A vulnerability, which was classified as critical, was found in Google Chrome. This affects an unknown function of the component WebView. Executing a manipulation can lead to improper access controls. This vulnerability is registered as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-87519 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87519 | Google Chrome up to 152.0.7977.82 Safebrowsing access control

A vulnerability classified as critical has been found in Google Chrome. This affects an unknown function of the component Safebrowsing. Performing a manipulation results in improper access controls. This vulnerability is identified as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.8%
CVE-2026-86418 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86418 | CIRCL MISP up to 2.5.45 Dashboard Organisation Picker createConditions User information disclosure (8ca4486af)

A vulnerability described as problematic has been identified in CIRCL MISP up to 2.5.45. This affects the function Organisation::createConditions of the component Dashboard Organisation Picker. Executing a manipulation of the argument User

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-86452 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86452 | MISP up to 2.5.45 Forgot Password Reset Endpoint email memory corruption (d75d899be)

A vulnerability was found in MISP up to 2.5.45. It has been classified as critical. The impacted element is an unknown function of the component Forgot Password Reset Endpoint. The manipulation of the argument email leads to memory corrupti

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-14298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14298 | Mattermost up to 11.9.x Boards Archive Import allocation of resources

A vulnerability labeled as problematic has been found in Mattermost up to 10.11.22/11.7.7/11.8.4/11.9.0/11.9.x. Impacted is an unknown function of the component Boards Archive Import Handler. Executing a manipulation can lead to allocation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.6%
CVE-2025-53341 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-53341 | Themovation Stratus Plugin up to 4.2.5 on WordPress authorization

A vulnerability, which was classified as problematic, has been found in Themovation Stratus Plugin up to 4.2.5 on WordPress. This affects an unknown part. Performing a manipulation results in missing authorization. This vulnerability was na

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 28.2%
CVE-2024-44951 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44951 | Linux Kernel up to 6.10.4 sc16is7xx kfifo_out_linear_ptr buffer overflow (09cfe05e9907/133f4c00b8b2 / Nessus ID 208423)

A vulnerability described as critical has been identified in Linux Kernel up to 6.10.4. This affects the function kfifo_out_linear_ptr of the component sc16is7xx. Executing a manipulation can lead to buffer overflow. This vulnerability is h

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.4%
CVE-2024-44952 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44952 | Linux Kernel up to 6.10.4 uevent_show deadlock (Nessus ID 208245 / WID-SEC-2024-2057)

It seems this issue is a false-positive. Please confirm the sources provided and consider disregarding this entry. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 22.4%
CVE-2024-44950 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44950 | Linux Kernel up to 6.10.4 IRQ sc16is7xx_startup privilege escalation (6a6730812220/7d3b793faaab / Nessus ID 208423)

A vulnerability marked as problematic has been reported in Linux Kernel up to 6.10.4. Affected is the function sc16is7xx_startup of the component IRQ Handler. The manipulation leads to privilege escalation. This vulnerability is traded as C

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.9%
CVE-2024-44949 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44949 | Linux Kernel up to 6.6.45/6.10.4 parisc arch_slab_minalign memory corruption (642a0b7453da/533de2f470ba/7ae04ba36b38 / Nessus ID 211777)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.45/6.10.4. Affected by this vulnerability is the function arch_slab_minalign of the component parisc. This manipulation causes memory corruption. Th

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.3%
CVE-2024-44948 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44948 | Linux Kernel up to 6.10.4 mtrr_save_state state issue (Nessus ID 208245 / WID-SEC-2024-2057)

A vulnerability labeled as problematic has been found in Linux Kernel up to 6.10.4. This impacts the function mtrr_save_state. Executing a manipulation can lead to state issue. This vulnerability appears as CVE-2024-44948. The attacker need

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 5.6%
CVE-2024-44947 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44947 | Linux Kernel up to 6.1.106/6.6.47/6.10.6 fuse fuse_notify_store information disclosure (Nessus ID 207884 / WID-SEC-2024-2057)

A vulnerability has been found in Linux Kernel up to 6.1.106/6.6.47/6.10.6 and classified as problematic. The impacted element is the function fuse_notify_store of the component fuse. This manipulation causes information disclosure. The ide

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.4%
CVE-2024-44946 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44946 | Linux Kernel up to 6.1.106/6.6.47/6.10.6 include/linux/skbuff.h kcm_release use after free (Nessus ID 208099 / WID-SEC-2024-2057)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.1.106/6.6.47/6.10.6. Impacted is the function kcm_release in the library include/linux/skbuff.h. The manipulation results in use after free. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32%
CVE-2025-4435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-4435 | Python CPython up to 3.14.0b1 calculation (Issue 135034 / EUVD-2025-16725)

A vulnerability has been found in Python CPython up to 3.14.0b1 and classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in incorrect calculation. This vulnerability is identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-82079 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Nintendo warns of Switch code execution flaw via on-screen QR codes

Nintendo has patched a high-severity Nintendo Switch vulnerability that could allow a nearby attacker to execute unauthorized code or access information stored on the console. The flaw, tracked as CVE-2026-82079, affects Switch systems runn

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-90843 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90843 | SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25 New Nmap Scan functions_nmap.py nmap_newscan target/params os command injection

A vulnerability described as critical has been identified in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] CPython: Schwachstelle ermöglicht Manipulation von Dateien

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CPython ausnutzen, um Dateien zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] FasterXML Jackson: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FasterXML Jackson ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 60.1%
CVE-2026-61511 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution

A critical vulnerability in vBulletin lets unauthenticated remote attackers execute arbitrary PHP code on a vulnerable forum server, creating a direct path to server compromise. Tracked as CVE-2026-61511, the issue affects vBulletin 6.2.1 a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA warnt: GitLab-Schlagloch CVE-2026-85706 aktiv ausgenutzt

USA / LONDON (IT BOLTWISE) – Die US-Cybersicherheitsbehörde CISA meldet, dass Angreifer eine GitLab-Sicherheitslücke maximaler Schwere (CVE-2026-85706) bereits ausnutzen. Betroffen ist ein DevSecOps-Feature, bei dem fehlende Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.3%
CVE-2026-51990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.5 CRITICAL
EPSS 79.3%
CVE-2026-51990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.5%
CVE-2026-89049 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials

A critical vulnerability in the AWS Systems Manager (SSM) Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, and steal temporary IAM credentials assigned to Amazon EC2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw Triggered by a Single Git Push

GitHub has reportedly awarded a $100,000 bug bounty to security researcher Saif Ghani for identifying a critical remote code execution vulnerability that could be triggered through a specially crafted Git repository operation. The flaw, tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2026-85102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Check Point VPN Flaws Could Face Large-Scale Exploitation, NCSC Warns

The Netherlands’ National Cyber Security Center (NCSC) has warned organizations to urgently patch two critical vulnerabilities in Check Point VPN products, saying widespread exploitation attempts are likely to begin soon. Tracked as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 25.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes

LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.5 CRITICAL
EPSS 56.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source

TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.8 CRITICAL
⚠️ KEV
EPSS 87.1%
CVE-2026-81963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as &quot;critical.&quot;Microsoft notes that 2 of the vulnerabiliti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores

Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2026-83548 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 22.1%
CVE-2026-75757 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 ash-project

CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.