🎯 CVE-2020-26046
📄 .md Alle CVEs anzeigen ✕

CVE-2020-26046: Schwachstellen-Eintrag (NVD)

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

Klassifikation & Betroffenheit:
thedaylightstudio fuel_cms 1.4.11
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 🎯 High

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and …
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 5.4
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Erforderlich
S · Scope Verändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Veröffentlicht:05.01.2021
Aktualisiert:17.06.2026 03:07
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
5 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
27 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 123 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.886 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-17
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 23.7%
CVE-2026-90894 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix

  Security researchers at JFrog disclosed the vulnerability on Tuesday, assigning it the identifier CVE-2026-90894 and the nickname &quot;ParaShells.&quot; JFrog rates the flaw 7.8 out of 10 on the CVSS severity scale. The bug does not allo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2021-44228 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

How Log4Shell Works: Breaking Down CVE-2021-44228

INTRODUCTION Log4jShell is a software vulnerability in Apache Log4j 2 which is a popular java library used for logging events in java-based applications also known by its CVE identifier as CVE-2021-44228 had sent shockwaves in the field of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-89805 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89805 | Linux Kernel up to 7.2.4/7.3-rc1 DRM Pagemap drm_pagemap.c drm_pagemap_migrate_populate_ram_pfn use after free (WID-SEC-2026-3438)

A vulnerability classified as very critical was found in Linux Kernel up to 7.2.4/7.3-rc1. This affects the function drm_pagemap_migrate_populate_ram_pfn of the file drm_pagemap.c of the component DRM Pagemap. Executing a manipulation can l

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.5%
CVE-2026-89803 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89803 | Linux Kernel up to 6.12.109/6.18.50/7.2.4/7.3-rc1 Nouveau DRM Driver nouveau_channel.c nouveau_channel_del chan use after free (WID-SEC-2026-3438)

A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.109/6.18.50/7.2.4/7.3-rc1. The affected element is the function nouveau_channel_del of the file drivers/gpu/drm/nouveau/nvkm/subdev/nvif/nouveau_chann

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.2%
CVE-2026-89804 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89804 | Linux Kernel up to 7.2.4/7.3-rc1 Nouveau Dmem Migration drm/nouveau/dmem.c size memory leak (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4/7.3-rc1. It has been classified as problematic. Affected is the function nouveau_dmem_migrate_to_ram/nouveau_dmem_migrate_copy_one of the file drm/nouveau/dmem.c of the component Nouveau

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.9%
CVE-2026-89802 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89802 | Linux Kernel up to 6.12.109/6.18.50/7.2.4/7.3-rc1 UVMM drm/nouveau/uvmm drm_gpuva_ops_free ops null pointer dereference (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.12.109/6.18.50/7.2.4/7.3-rc1. It has been rated as problematic. Affected by this issue is the function drm_gpuva_ops_free of the file drm/nouveau/uvmm of the component UVMM. Performing a man

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.5%
CVE-2026-89801 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89801 | Linux Kernel up to 7.3-rc1 UVMM uvmm.c nouveau_uvmm_bind_job_submit reg use after free (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4/7.3-rc1. It has been declared as very critical. Affected by this vulnerability is the function nouveau_uvmm_bind_job_submit of the file drivers/gpu/drm/nouveau/n

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.7%
CVE-2026-89800 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89800 | Linux Kernel up to 7.3-rc1 Nouveau UVMM drm/nouveau/uvmm nouveau_uvmm_bind_job_cleanup state issue (WID-SEC-2026-3438)

A vulnerability marked as problematic has been reported in Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4/7.3-rc1. Impacted is the function nouveau_uvmm_bind_job_cleanup of the file drm/nouveau/uvmm of the component Nouveau UVMM. This ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.2%
CVE-2026-4201 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire

YouTube VideoWhat if a phone call could spread a zero-click worm without you answering, tapping a link, or doing anything at all? Security researchers built WeWorm, a proof-of-concept that exploited WeChat calls on iOS and Android, revealin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-89799 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89799 | Linux Kernel up to 6.18.50/7.2.4 BPF bpf_get_stackid_pe race condition (WID-SEC-2026-3438)

A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.50/7.2.4. This issue affects the function bpf_get_stackid_pe of the component BPF. The manipulation results in race condition. This vulnerability was named C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.1%
CVE-2026-89798 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89798 | Linux Kernel up to 6.18.50/7.2.4 rpcrdma rpcrdma_rn_register rn_done null pointer dereference (WID-SEC-2026-3438)

A vulnerability identified as critical has been detected in Linux Kernel up to 6.18.50/7.2.4. This vulnerability affects the function rpcrdma_rn_register of the component rpcrdma. The manipulation of the argument rn_done leads to null point

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.4%
CVE-2026-89797 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89797 | Linux Kernel up to 6.18.50/7.2.4 ab8500_fg ab8500_fg_remove use after free (WID-SEC-2026-3438)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.4. This affects the function ab8500_fg_remove of the component ab8500_fg. Executing a manipulation can lead to use after free. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.4%
CVE-2026-89796 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89796 | Linux Kernel up to 7.2.4 Damon mm/damon/core.c kdamond_merge_regions infinite loop (WID-SEC-2026-3438)

A vulnerability was found in Linux Kernel up to 7.2.4 and classified as problematic. This impacts the function kdamond_merge_regions of the file mm/damon/core.c of the component Damon. The manipulation results in infinite loop. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.2%
CVE-2026-89795 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89795 | Linux Kernel up to 6.18.51/7.2.4 PCI Hotplug Driver pci_create_slot memory leak (WID-SEC-2026-3438)

A vulnerability has been found in Linux Kernel up to 6.18.51/7.2.4 and classified as critical. This affects the function pci_create_slot of the component PCI Hotplug Driver. The manipulation leads to memory leak. This vulnerability is docum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31%
CVE-2026-89794 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89794 | Linux Kernel up to 6.12.109/6.18.50/7.2.4/7.3-rc1 ksmbd smb2_read_pipe uninitialized pointer (WID-SEC-2026-3438)

A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.109/6.18.50/7.2.4/7.3-rc1. The impacted element is the function smb2_read_pipe of the component ksmbd. Performing a manipulation results in uninitialized

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.7%
CVE-2026-89793 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89793 | Linux Kernel up to 7.3-rc1 ublk ublk_ch_mmap privileges management (WID-SEC-2026-3438)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.6.156/6.12.109/6.18.50/7.2.4/7.3-rc1. This issue affects the function ublk_ch_mmap of the component ublk. Such manipulation leads to improper privilege

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.4%
CVE-2026-73436 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73436 | Arista EOS up to 4.36.1F OSPF denial of service (WID-SEC-2026-3441)

A vulnerability identified as critical has been detected in Arista EOS up to 4.32.x/4.33.9M/4.34.7.1M/4.35.5M/4.36.1F. This affects an unknown function of the component OSPF. This manipulation causes denial of service. The identification of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.5%
CVE-2026-73445 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73445 | Arista EOS up to 4.36.0.1F gRPC Network Security Interface input validation (WID-SEC-2026-3441)

A vulnerability was found in Arista EOS up to 4.36.0.1F. It has been declared as problematic. Impacted is an unknown function of the component gRPC Network Security Interface. Executing a manipulation can lead to improper input validation.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-73463 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73463 | Arista EOS up to 4.36.0.1F gNSI Authz service race condition (WID-SEC-2026-3441)

A vulnerability was found in Arista EOS up to 4.36.0.1F. It has been rated as critical. The affected element is an unknown function of the component gNSI Authz service. The manipulation leads to race condition. This vulnerability is uniquel

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-73435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73435 | Arista EOS up to 4.36.1F OSPFv2 input validation (WID-SEC-2026-3441)

A vulnerability categorized as critical has been discovered in Arista EOS up to 4.32.x/4.33.9M/4.34.7M/4.35.5M/4.36.1F. The impacted element is an unknown function of the component OSPFv2. The manipulation results in improper input validati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.1%
CVE-2026-73438 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73438 | Arista EOS up to 4.36.1F OSPFv3 input validation (WID-SEC-2026-3441)

A vulnerability categorized as critical has been discovered in Arista EOS up to 4.32.x/4.33.9M/4.34.7M/4.35.5M/4.36.1F. Affected is an unknown function of the component OSPFv3. Such manipulation leads to improper input validation. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.5%
CVE-2026-2380 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-2380 | Arista EOS up to 4.36.1F OpenConfig Services information disclosure (WID-SEC-2026-3441)

A vulnerability categorized as problematic has been discovered in Arista EOS up to 4.32.x/4.33.x/4.34.x/4.35.x/4.36.1F. This issue affects some unknown processing of the component OpenConfig Services. Executing a manipulation can lead to in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.2%
CVE-2026-19640 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19640 | Arista EOS up to 4.36.0.1F gNMI improper authorization (WID-SEC-2026-3441)

A vulnerability labeled as critical has been found in Arista EOS up to 4.32.x/4.33.8M/4.34.7M/4.35.5M/4.36.0.1F. This impacts an unknown function of the component gNMI. Such manipulation leads to improper authorization. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
10.0 CRITICAL
EPSS 57.4%
CVE-2026-76460 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Critical Cisco ISE Authentication Bypass (CVE-2026-76460) Under Active Exploitation

HOC Shorts Cisco has issued a critical security advisory cisco-sa-ISE-ABP-VNSW7Tn5 warning of a maximum-severity CVSS 10.0 authentication bypass vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
8.2 HIGH
EPSS 23%
CVE-2022-44294 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44294 | oretnom23 Sanitization Management System 1.0 manage_service ID sql injection (EUVD-2022-47241)

A vulnerability marked as critical has been reported in oretnom23 Sanitization Management System 1.0. This issue affects some unknown processing of the file /php-sms/admin/?page=services/manage_service. This manipulation of the argument ID

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2022-44284 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44284 | Dinstar FXO Analog VoIP Gateway DAG2000-16O cross site scripting (ID 169531 / EUVD-2022-47232)

A vulnerability was found in Dinstar FXO Analog VoIP Gateway DAG2000-16O. It has been rated as problematic. The affected element is an unknown function. Performing a manipulation results in cross site scripting. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.6%
CVE-2022-44283 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44283 | AVS Audio Converter 10.3 buffer overflow (ID 169427 / EUVD-2022-47231)

A vulnerability was found in AVS Audio Converter 10.3. It has been classified as critical. This issue affects some unknown processing. This manipulation causes buffer overflow. This vulnerability is handled as CVE-2022-44283. The attack can

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 24.7%
CVE-2026-58704 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

Google Pixel CVE-2026-58704: Limited Active Exploitation of Modem Authorization Bypass

1. Basic Information Original Title: Pixel Update Bulletin—September 2026 Source: Google Published: 2026-09-15 Updated: None Severity: High Basis of Severity: Google has stated that there are indications this vulnerability may be exploited

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 74%
CVE-2026-5430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

WSO2 CVE-2026-5430: Authentication Bypass in API Management Infrastructure via JWT with Unsupported Algorithm

1. Basic Information Original Title: Enterprises Warned of Attacks Exploiting WSO2 Vulnerability Source: SecurityWeek Published Date: September 16, 2026 Updated Date: None Severity: Critical Basis of Severity: An unauthenticated vulnerabili

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Linux-Entwickler gibt auf: Geheime Sicherheitslücke gemeldet - <b>it</b>-daily.net

Der Sicherheitsforscher Andy Nguyen, bekannt unter dem Namen TheFlow0, hat sein Projekt PS5 Linux nach eigenen Angaben aufgegeben. Das öffentlich auf ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.2%
CVE-2026-77960 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Bransys ELD

View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android &amp;lt;11.00.00 (CVE-2026-86520, CVE-2026-86689,

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 62.9%
CVE-2026-91826 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the i

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.1 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61591 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.4 HIGH
🇪🇺 EUVD
EPSS 21.7%
CVE-2026-61592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 djust-org

CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.1 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-61597 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 djust-org

CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 31.2%
CVE-2026-92599 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 hapijs

CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in

joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 26%
CVE-2026-92598 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92598 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addres

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 30.7%
CVE-2026-92597 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92597 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as [email protected](x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registr

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.0 MEDIUM
🇪🇺 EUVD
EPSS 4.5%
CVE-2026-92595 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 nodemailer

CVE-2026-92595 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key, callback)`. Because `shared.resolveContent()` normalizes the missing `options` argument to an empty object, the message-level flags copied into `mai

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 26.7%
CVE-2026-92596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 nodemailer

CVE-2026-92596 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a sing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 19.3%
CVE-2026-92594 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 craftcms

CVE-2026-92594 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding on

Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are ga

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 23.4%
CVE-2026-92593 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92593 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on a single element type can mint a token over attacker-controlled

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
🇪🇺 EUVD
EPSS 31.2%
CVE-2026-92591 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 craftcms

CVE-2026-92591 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action accepts a site name, serializes it through Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker who obtained

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 29%
CVE-2026-92592 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92592 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie vi

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.1 MEDIUM
🇪🇺 EUVD
EPSS 2.8%
CVE-2026-92590 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92590 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScr

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.3%
CVE-2026-92589 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 craftcms

CVE-2026-92589 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.9 MEDIUM
🇪🇺 EUVD
EPSS 6.9%
CVE-2026-92588 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
🧪 n8n-io

CVE-2026-92588 | n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a project admin) could therefore reference files belonging to projects they have no access to and push a deletion of t

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.6%
CVE-2026-92587 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 n8n-io

CVE-2026-92587 | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical UR

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git wal

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4%
CVE-2026-92585 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 WWBN

CVE-2026-92585 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.php endpoint with APIName parameters.

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can sub

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 2.6%
CVE-2026-92586 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 WWBN

CVE-2026-92586 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests to the comment API endpoint with arbitrary video IDs to write comments on videos they cannot watch.

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 6.8%
CVE-2026-92584 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92584 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings verbatim) directly into the `app` column of the videos_statistics table without invoking the sanitizing setter setApp(); normalizeApp() only truncat

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's Us

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 32.5%
CVE-2026-92582 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92582 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are never validated and are read from $_REQUEST, so an attacker can supply them in the query string of a cross-site

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['b

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
🇪🇺 EUVD
EPSS 5.9%
CVE-2026-92583 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92583 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency.

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurre

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.5%
CVE-2026-92581 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 WWBN

CVE-2026-92581 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 19.1%
CVE-2026-92580 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92580 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password breaks out of the quoted word and injects arbitrary shell. The password is written through the admin-only endpoint objects/pluginAddDataObject.j

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ..

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.2 CRITICAL
🇪🇺 EUVD
EPSS 76%
CVE-2026-92578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92578 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 2.2%
CVE-2026-92579 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92579 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials.

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin f

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.7 HIGH
🇪🇺 EUVD
EPSS 26.9%
CVE-2026-92577 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 WWBN

CVE-2026-92577 | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status.

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.2 CRITICAL
🇪🇺 EUVD
EPSS 61.9%
CVE-2026-92576 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 HKUDS

CVE-2026-92576 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 22.5%
CVE-2026-89034 🌐 Adjacent Network 🔓 Keine Authentifizierung nötig
TCH

CVE-2026-89034 | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the offici

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or u

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.