🎯 CVE-2020-26211 HIGH 8.7 🔥 EPSS 27.5%
📄 .md Alle CVEs anzeigen ✕

CVE-2020-26211: Schwachstellen-Eintrag (NVD)

In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with permissions to edit a page could insert a particular meta tag which could be used to silently redirect users to a alternative location upon visit of a page. Dangerous content may remain in the database but will be removed before being displayed on a page. If you think this could have been exploited the linked advisory provides a SQL query to test. As a workaround without upgrading, page edit permissions could be limited to only those that are trusted until you can upgrade although this will not address existing exploitation of this vulnerability. The issue is fixed in BookStack version 0.30.4.

Klassifikation & Betroffenheit:
bookstackapp bookstack *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 06c81e69b9c9d96124239a5565509af6879c4471 (Commit) 🩹 bbd1384acbe7e52c21f89af69f2dc391c95dbf54 (Commit)
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.7
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Erforderlich
S · Scope Verändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Veröffentlicht:03.11.2020
Aktualisiert:17.06.2026 03:07
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 174 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.535 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-12
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 57
Linux 2
Google 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 23.8%
CVE-2026-47227 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47227 | Admidio up to 5.0.9 Category Management modules/categories.php isEditable type/uuid privileges management

A vulnerability identified as problematic has been detected in Admidio up to 5.0.9. The affected element is the function isEditable of the file modules/categories.php of the component Category Management. This manipulation of the argument t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.9%
CVE-2026-47228 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47228 | Admidio up to 5.0.9 Send Login modules/registration.php adm_csrf_token cross-site request forgery

A vulnerability labeled as problematic has been found in Admidio up to 5.0.9. The impacted element is an unknown function of the file modules/registration.php of the component Send Login. Such manipulation of the argument adm_csrf_token lea

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.6%
CVE-2026-63133 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63133 | cisagov Malcolm up to 26.6.x Archive Extractor safe-extract.py resource consumption

A vulnerability categorized as critical has been discovered in cisagov Malcolm up to 26.6.x. This issue affects some unknown processing of the file safe-extract.py of the component Archive Extractor. Such manipulation leads to resource cons

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-63177 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63177 | CISA Malcolm up to 26.6.x Nginx OpenResty Lua Layer access control

A vulnerability identified as critical has been detected in CISA Malcolm up to 26.6.x. Impacted is an unknown function of the component Nginx OpenResty Lua Layer. Performing a manipulation results in improper access controls. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-47226 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47226 | Admidio up to 5.0.9 File Deletion documents-files.php folder_uuid improper authorization

A vulnerability was found in Admidio up to 5.0.9 and classified as problematic. Affected by this issue is some unknown functionality of the file modules/documents-files.php of the component File Deletion. Such manipulation of the argument f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2026-73250 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73250 | notepad-plus-plus Notepad++ up to 8.9.6 Context Menu nppSetup.nsi INSTDIR os command injection (EUVD-2026-57017)

A vulnerability was found in notepad-plus-plus Notepad++ up to 8.9.6. It has been rated as problematic. This impacts an unknown function of the file PowerEditor/installer/nppSetup.nsi of the component Context Menu Component. Performing a ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2026-73247 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73247 | kestra-io Kestra up to 1.x Http Function HttpFunction.java http uri server-side request forgery

A vulnerability was found in kestra-io Kestra up to 1.x. It has been rated as critical. This vulnerability affects the function http of the file core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java of the component H

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.1%
CVE-2026-73246 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73246 | Kestra prior 2.0.0-rc6 WorkerEndpoint WorkerEndpoint.java missing encryption

A vulnerability was found in Kestra prior 2.0.0-rc6. It has been classified as problematic. Affected by this issue is some unknown functionality of the file worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-73249 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73249 | kovidgoyal calibre up to 9.11.x Content Server src/calibre/srv/books.py Router.dispatch improper authorization

A vulnerability was found in kovidgoyal calibre up to 9.11.x. It has been declared as problematic. This affects the function Router.dispatch of the file src/calibre/srv/books.py of the component Content Server. Executing a manipulation can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.5%
CVE-2026-73245 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73245 | kestra-io Kestra up to 2.0.0-rc5 Management Endpoints application.yml information disclosure

A vulnerability was found in kestra-io Kestra up to 2.0.0-rc5. It has been declared as problematic. The impacted element is an unknown function of the file cli/src/main/resources/application.yml of the component Management Endpoints. The ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-73248 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73248 | Kovid Goyal calibre up to 9.11.x EPUB compile_python_template code injection (Nessus ID 334891)

A vulnerability, which was classified as critical, has been found in Kovid Goyal calibre up to 9.11.x. This affects the function compile_python_template of the component EPUB Handler. The manipulation leads to code injection. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.3%
CVE-2026-63134 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63134 | cisagov Malcolm up to 26.6.x File Extraction safe-extract.py os.makedirs entry.pathname path traversal

A vulnerability marked as critical has been reported in cisagov Malcolm up to 26.6.x. The impacted element is the function os.makedirs of the file safe-extract.py of the component File Extraction. The manipulation of the argument entry.path

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.1%
CVE-2026-72724 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72724 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 Onebox onebox_handler.rb thread_id information disclosure

A vulnerability, which was classified as problematic, has been found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. This impacts an unknown function of the file plugins/chat/lib/chat/onebox_handler.rb of the component Onebox. Performing a m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-72729 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72729 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 discourse-local-dates plugin cross-domain policy

A vulnerability was found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. It has been declared as problematic. The affected element is an unknown function of the component discourse-local-dates plugin. Executing a manipulation can lead to pe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2026-72727 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72727 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 cross site scripting

A vulnerability was found in Discourse up to 2026.1.5/2026.5.1/2026.6.0 and classified as problematic. This issue affects some unknown processing. Such manipulation leads to cross site scripting. This vulnerability is documented as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.2%
CVE-2026-72728 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72728 | Discourse Onebox input validation

A vulnerability has been found in Discourse up to 2026.1.6/2026.6.1/2026.7.0/2026.8.0-latest.0 and classified as problematic. This vulnerability affects unknown code of the component Onebox. This manipulation causes improper input validatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.9%
CVE-2026-72726 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72726 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 information disclosure

A vulnerability classified as problematic has been found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. The impacted element is an unknown function. This manipulation causes information disclosure. This vulnerability is tracked as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-72721 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72721 | Discourse prior 2026.1.6/2026.5.2/2026.6.1/2026.7.0 Onebox DomainChecker.is_blocked redirect

A vulnerability described as problematic has been identified in Discourse. The affected element is the function Onebox::DomainChecker.is_blocked of the component Onebox. The manipulation results in open redirect. This vulnerability is ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.6%
CVE-2026-72723 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72723 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 Navigation Menu Tags /site.json information disclosure

A vulnerability labeled as problematic has been found in Discourse up to 2026.1.5/2026.5.1/2026.6.0. This issue affects the function SiteSerializer.anonymous_default_navigation_menu_tags of the file /site.json of the component Navigation Me

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-72722 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72722 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 privileges management

A vulnerability identified as problematic has been detected in Discourse up to 2026.1.5/2026.5.1/2026.6.0. This vulnerability affects the function TopicLink.extract_from/TopicLink.ensure_entry_for/TopicLink.duplicate_lookup. Performing a ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-66058 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66058 | Frappe up to 15.111.x/16.19.x Document Follow API update_follow privileges management

A vulnerability, which was classified as critical, has been found in Frappe up to 15.111.x/16.19.x. This affects the function update_follow of the component Document Follow API. The manipulation leads to improper privilege management. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2025-71413 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-71413 | ATN-B1 CPDLC unusual condition

A vulnerability was found in ATN-B1 CPDLC. It has been declared as problematic. Affected is an unknown function of the component Aviation Very High Frequency Link Control X.25 Layers. The manipulation results in improper check for unusual c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2025-71409 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-71409 | ATN-B1 CPDLC improper authentication

A vulnerability was found in ATN-B1 CPDLC. It has been classified as problematic. This impacts an unknown function. The manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2025-71409. The attack i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.9%
CVE-2025-71411 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-71411 | ATN-B1 CPDLC resource consumption

A vulnerability was found in ATN-B1 CPDLC and classified as critical. This affects an unknown function. Executing a manipulation can lead to resource consumption. This vulnerability is handled as CVE-2025-71411. The attack can be executed r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2025-71410 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-71410 | ATN-B1 CPDLC allocation of resources

A vulnerability has been found in ATN-B1 CPDLC and classified as problematic. The impacted element is an unknown function. Performing a manipulation results in allocation of resources. This vulnerability is known as CVE-2025-71410. Remote e

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2025-71412 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-71412 | CPDLC injection

A vulnerability, which was classified as critical, was found in CPDLC. The affected element is an unknown function. Such manipulation leads to injection. This vulnerability is traded as CVE-2025-71412. The attack may be launched remotely. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-17264 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-17264 | Medixant RadiAnt DICOM up to 2025.2/2026.0 DICOM file out-of-bounds write

A vulnerability identified as critical has been detected in Medixant RadiAnt DICOM up to 2025.2/2026.0. This impacts an unknown function of the component DICOM file Handler. This manipulation causes out-of-bounds write. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29%
CVE-2026-66000 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66000 | Frappe up to 15.111.x/16.22.x Document Follow Notification Generation permission

A vulnerability was found in Frappe up to 15.111.x/16.22.x. It has been classified as problematic. The affected element is an unknown function of the component Document Follow Notification Generation. Performing a manipulation results in pe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-71439 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71439 | mermaid-js Mermaid up to 11.16.0 Radar Diagrams ticks resource consumption

A vulnerability classified as problematic has been found in mermaid-js Mermaid up to 11.16.0. Affected by this vulnerability is an unknown functionality of the component Radar Diagrams. The manipulation of the argument ticks leads to resour

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-66059 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66059 | Frappe up to 15.111.9/16.19.x permission

A vulnerability marked as critical has been reported in Frappe up to 15.111.9/16.19.x. This vulnerability affects unknown code. Performing a manipulation results in permission issues. This vulnerability is reported as CVE-2026-66059. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.8%
CVE-2026-48763 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48763 | BaptisteArno TypeBot up to 3.16.1 upload-url filePath unrestricted upload

A vulnerability labeled as critical has been found in BaptisteArno TypeBot up to 3.16.1. Affected by this issue is some unknown functionality of the file /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url. Such manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-48765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48765 | baptisteArno TypeBot up to 3.16.x OAuth Credentials handleUpdateOAuthCredentials workspaceId privileges management

A vulnerability labeled as critical has been found in baptisteArno TypeBot up to 3.16.x. The affected element is the function handleUpdateOAuthCredentials of the component OAuth Credentials. Executing a manipulation of the argument workspac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-55676 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55676 | CISA Malcolm up to 26.06.0 config.php unrestricted upload

A vulnerability has been found in CISA Malcolm up to 26.06.0 and classified as critical. This issue affects some unknown processing of the file file-upload/php/config.php. The manipulation leads to unrestricted upload. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-73244 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73244 | kekingcn kkFileView up to 5.0.0 File endpoint FileController.java FileController#getFiles path traversal

A vulnerability, which was classified as problematic, was found in kekingcn kkFileView up to 5.0.0. This affects the function FileController#getFiles of the file server/src/main/java/cn/keking/web/controller/FileController.java of the compo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-73235 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73235 | FreeCAD up to 1.1.1 Xerces SAX2 XMLReader src/Base/Reader.cpp server-side request forgery

A vulnerability described as critical has been identified in FreeCAD up to 1.1.1. Affected by this issue is the function Base::XMLReader::XMLReader of the file src/Base/Reader.cpp of the component Xerces SAX2 XMLReader. The manipulation res

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-73243 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73243 | kekingcn kkFileView up to 5.0.0 TrustHostFilter/TrustDirFilter WebConfig.java FileHandlerService#getFileAttribute fullfilename missing authentication

A vulnerability classified as critical was found in kekingcn kkFileView up to 5.0.0. The affected element is the function FileHandlerService#getFileAttribute of the file server/src/main/java/cn/keking/config/WebConfig.java of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-73241 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73241 | FreeRDP up to 3.29.x RDSTLS libfreerdp/core/rdstls.c rdstls_server_authenticate improper authentication (Nessus ID 342051 / WID-SEC-2026-2776)

A vulnerability identified as critical has been detected in FreeRDP up to 3.29.x. This impacts the function rdstls_server_authenticate of the file libfreerdp/core/rdstls.c of the component RDSTLS. Performing a manipulation results in improp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-73242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73242 | FreeRDP up to 3.29.x Kerberos kerberos.c kerberos_DecryptMessage out-of-bounds (Nessus ID 342051 / WID-SEC-2026-2776)

A vulnerability labeled as problematic has been found in FreeRDP up to 3.29.x. Affected is the function kerberos_DecryptMessage of the file winpr/libwinpr/sspi/Kerberos/kerberos.c of the component Kerberos. Executing a manipulation can lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-73233 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73233 | FreeCAD up to 1.1.1 FEM Displacement Constraint Task Dialog TaskFemConstraintDisplacement.cpp accept neutralization

A vulnerability has been found in FreeCAD up to 1.1.1 and classified as critical. This vulnerability affects the function TaskDlgFemConstraintDisplacement::accept of the file src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp of the componen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-73234 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73234 | FreeCAD up to 1.1.1 File Restore src/App/PropertyFile.cpp path traversal (Nessus ID 334893)

A vulnerability was found in FreeCAD up to 1.1.1. It has been declared as critical. The affected element is the function PropertyFileIncluded::Restore of the file src/App/PropertyFile.cpp of the component File Restore. The manipulation resu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2026-48762 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48762 | baptisteArno TypeBot up to 3.15.x Create Transcription server-side request forgery

A vulnerability described as problematic has been identified in baptisteArno TypeBot up to 3.15.x. This affects an unknown function of the component Create Transcription. The manipulation results in server-side request forgery. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-79522 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79522 | GPAC Downloader src/utils/downloader.c gf_dm_get_chunk_data out-of-bounds (Nessus ID 344757)

A vulnerability labeled as critical has been found in GPAC. The affected element is the function gf_dm_get_chunk_data of the file src/utils/downloader.c of the component Downloader. The manipulation results in out-of-bounds read. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.9%
CVE-2026-45762 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45762 | OISF Suricata up to 7.0.15/8.0.4 IP Defragmentation Tracker input validation (Nessus ID 344759)

A vulnerability was found in OISF Suricata up to 7.0.15/8.0.4. It has been rated as critical. This issue affects some unknown processing of the component IP Defragmentation Tracker. This manipulation causes improper input validation. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-71613 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71613 | GPAC j2kdec_process buffer overflow (EUVD-2026-75131 / Nessus ID 344761)

A vulnerability classified as critical was found in GPAC. The impacted element is the function j2kdec_process. Such manipulation leads to buffer overflow. This vulnerability is referenced as CVE-2026-71613. It is possible to launch the atta

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.4%
CVE-2026-89169 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89169 | Debian live-boot Dm-verity improper authentication (Nessus ID 344758)

A vulnerability was found in Debian live-boot and classified as very critical. This vulnerability affects unknown code of the component Dm-verity. Such manipulation leads to improper authentication. This vulnerability is referenced as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.1%
CVE-2026-77159 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-77159 | Red Hat Enterprise Linux TPM Emulator qemuTPMEmulatorPrepareHost link following (Nessus ID 344762)

A vulnerability was found in Red Hat Enterprise Linux and classified as problematic. Affected by this issue is the function qemuTPMEmulatorPrepareHost of the component TPM Emulator. Such manipulation leads to link following. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18%
CVE-2026-48813 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48813 | david-a-wheeler flawfinder up to 2.0.19 output_sonar neutralization (Nessus ID 335310)

A vulnerability classified as problematic was found in david-a-wheeler flawfinder up to 2.0.19. Affected is the function output_sonar. Executing a manipulation can lead to improper neutralization. This vulnerability is handled as CVE-2026-4

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.1%
CVE-2026-73231 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73231 | faker-js faker up to 10.4.x Helpers eval.ts faker.helpers.fake code injection (Nessus ID 335301)

A vulnerability categorized as critical has been discovered in faker-js faker up to 10.4.x. This affects the function faker.helpers.fake of the file src/modules/helpers/eval.ts of the component Helpers. Such manipulation leads to code injec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.2%
CVE-2026-73217 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73217 | Cursor up to 3.1.1 Auto-Run Sandbox mode sandbox

A vulnerability identified as problematic has been detected in Cursor up to 3.1.1. The affected element is an unknown function of the component Auto-Run Sandbox mode. Performing a manipulation results in sandbox issue. This vulnerability wa

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.5%
CVE-2026-73224 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73224 | Electerm up to 3.15.119 Sftp File Info Modal file-info-modal.jsx calcLocal os command injection

A vulnerability identified as problematic has been detected in Electerm up to 3.15.119. This affects the function calcLocal of the file src/client/components/sftp/file-info-modal.jsx of the component Sftp File Info Modal. Performing a manip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.7%
CVE-2026-73227 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73227 | Electerm up to 3.15.119 RDP File Transfer file-transfer.js fileInfo.name file inclusion

A vulnerability was found in Electerm up to 3.15.119. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the file src/client/components/rdp/file-transfer.js of the component RDP File Transfer. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-73226 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73226 | electerm up to 3.15.185 Dispatch Center dispatch-center.js upgrade-func os command injection

A vulnerability was found in electerm up to 3.15.185. It has been declared as critical. Affected is the function upgrade-func of the file src/app/server/dispatch-center.js of the component Dispatch Center. The manipulation of the argument f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-73225 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73225 | Electerm up to 3.15.119 File Transfer transfer.jsx path traversal

A vulnerability was found in Electerm up to 3.15.119. It has been classified as problematic. This impacts an unknown function of the file src/client/components/file-transfer/transfer.jsx of the component File Transfer. The manipulation lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.4%
CVE-2026-73223 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73223 | Electerm up to 3.15.119 SFTP file-item.jsx editWithSystemEditor Name path traversal

A vulnerability was found in Electerm up to 3.15.119 and classified as critical. This affects the function editWithSystemEditor of the file src/client/components/sftp/file-item.jsx of the component SFTP Handler. Executing a manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-73222 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73222 | davila7 claude-code-templates up to 1.29.3 Studio sandbox-server.js child_process.spawn prompt/agentName os command injection

A vulnerability categorized as critical has been discovered in davila7 claude-code-templates up to 1.29.3. This vulnerability affects the function child_process.spawn of the file cli-tool/src/sandbox-server.js of the component Studio. Such

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.3%
CVE-2026-73218 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73218 | Cursor up to 2.x Auto-Run Sandbox mode privileges management

A vulnerability identified as problematic has been detected in Cursor up to 2.x. This impacts an unknown function of the component Auto-Run Sandbox mode. The manipulation leads to improper privilege management. This vulnerability is uniquel

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-73216 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73216 | Coturn up to 4.16.x Quota Accounting ns_turn_server.c shutdown_client_connection allocation of resources

A vulnerability was found in Coturn up to 4.16.x. It has been declared as problematic. The affected element is the function shutdown_client_connection of the file src/server/ns_turn_server.c of the component Quota Accounting. Such manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-73088 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73088 | Browserslist up to 4.28.6 Stats Normalization normalizeStats prototype pollution

A vulnerability has been found in Browserslist up to 4.28.6 and classified as critical. This vulnerability affects the function normalizeStats of the component Stats Normalization. The manipulation leads to improperly controlled modificatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-48767 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-48767 | baptisteArno Typebot up to 3.16.0 Google Sheets Helper getAccessToken privileges management

A vulnerability, which was classified as critical, has been found in baptisteArno Typebot up to 3.16.0. This vulnerability affects the function getAccessToken of the component Google Sheets Helper. Performing a manipulation results in impro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.