CVE-2020-26241: Schwachstellen-Eintrag (NVD)
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause a chain-split where vulnerable nodes reject the canonical chain. Geth's pre-compiled dataCopy (at 0x00...04) contract did a shallow copy on invocation. An attacker could deploy a contract that writes X to an EVM memory region R, then calls 0x00..04 with R as an argument, then overwrites R to Y, and finally invokes the RETURNDATACOPY opcode. When this contract is invoked, a consensus-compliant node would push X on the EVM stack, whereas Geth would push Y. This is fixed in version 1.9.17.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-08-30 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-79671 | lin-snow Ech0 up to 4.2.1 Webhook webhook_setting_service.go validateWebhookURL server-side request forgery
A vulnerability categorized as problematic has been discovered in lin-snow Ech0 up to 4.2.1. Affected by this vulnerability is the function validateWebhookURL of the file webhook_setting_service.go of the component Webhook. Executing a mani
CVE-2026-79671 | lin-snow Ech0 up to 4.2.1 Webhook webhook_setting_service.go validateWebhookURL server-side request forgery
A vulnerability categorized as problematic has been discovered in lin-snow Ech0 up to 4.2.1. Affected by this vulnerability is the function validateWebhookURL of the file webhook_setting_service.go of the component Webhook. Executing a mani
CVE-2026-6464 | PostgreSQL up to 18.4 COPY injection (Nessus ID 341035 / WID-SEC-2026-2844)
A vulnerability classified as critical has been found in PostgreSQL up to 14.23/15.18/16.14/17.10/18.4. This issue affects some unknown processing of the component COPY. This manipulation causes injection. This vulnerability is tracked as C
CVE-2026-6464 | PostgreSQL up to 18.4 COPY injection (Nessus ID 341035 / WID-SEC-2026-2844)
A vulnerability classified as critical has been found in PostgreSQL up to 14.23/15.18/16.14/17.10/18.4. This issue affects some unknown processing of the component COPY. This manipulation causes injection. This vulnerability is tracked as C
CVE-2026-16445 | Red Hat Enterprise Linux NetworkManager command injection
A vulnerability labeled as very critical has been found in Red Hat Enterprise Linux, Hardened Images and OpenShift Container Platform. This affects an unknown part of the component NetworkManager. Executing a manipulation can lead to comman
CVE-2026-6471 | PostgreSQL up to 18.4 Logical Decoding improper authorization (Nessus ID 339174 / WID-SEC-2026-2844)
A vulnerability, which was classified as critical, was found in PostgreSQL up to 14.23/15.18/16.14/17.10/18.4. The impacted element is an unknown function of the component Logical Decoding. Executing a manipulation can lead to improper auth
CVE-2026-77915 | rConfig up to 8.2.12 Registration routes/web.php Auth::routes improper authentication (EUVD-2026-64955)
A vulnerability identified as critical has been detected in rConfig up to 8.2.12. Affected by this issue is the function Auth::routes of the file routes/web.php of the component Registration. Performing a manipulation results in improper au
CVE-2026-6469 | PostgreSQL up to 18.4 privileges management (Nessus ID 341035 / WID-SEC-2026-2844)
A vulnerability classified as problematic was found in PostgreSQL up to 14.23/15.18/16.14/17.10/18.4. Impacted is an unknown function. Such manipulation leads to improper privilege management. This vulnerability is listed as CVE-2026-6469.
CVE-2026-6470 | PostgreSQL up to 18.4 authorization (Nessus ID 341035 / WID-SEC-2026-2844)
A vulnerability categorized as problematic has been discovered in PostgreSQL up to 14.23/15.18/16.14/17.10/18.4. Affected is an unknown function. Such manipulation leads to missing authorization. This vulnerability is uniquely identified as
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
Originally published at HOL CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files from Checkpoint Indexes TL;DR: Hugging Face Accelerate through version 1.14.0 fails to sanitize weight_map entries in sha
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
Originally published at HOL CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files from Checkpoint Indexes TL;DR: Hugging Face Accelerate through version 1.14.0 fails to sanitize weight_map entries in sha
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
Originally published at HOL BREAKING: CVE-2026-18500 - @fastify/jwt key override authorization bypass TL;DR: CVE-2026-18500 affects @fastify/jwt versions before 10.2.2. A route that passes a specific verification key to request.jwtVerify({
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
Originally published at HOL BREAKING: CVE-2026-18500 - @fastify/jwt key override authorization bypass TL;DR: CVE-2026-18500 affects @fastify/jwt versions before 10.2.2. A route that passes a specific verification key to request.jwtVerify({
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
OpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities that would allow it to independently discover zero-day vulnerabilities and conduct compl
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
OpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities that would allow it to independently discover zero-day vulnerabilities and conduct compl
CVE-2026-77850 | ash-project ash_admin up to 1.3.0 Typeahead Phoenix.HTML.raw cross site scripting (EUVD-2026-68326)
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been declared as problematic. This issue affects the function Phoenix.HTML.raw of the component Typeahead. Such manipulation leads to cross site scripting. This vulnerab
CVE-2026-77850 | ash-project ash_admin up to 1.3.0 Typeahead Phoenix.HTML.raw cross site scripting (EUVD-2026-68326)
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been declared as problematic. This issue affects the function Phoenix.HTML.raw of the component Typeahead. Such manipulation leads to cross site scripting. This vulnerab
CVE-2026-75757 | ash-project ash_admin up to 1.3.0 Cookie improper authorization (EUVD-2026-68324)
A vulnerability has been found in ash-project ash_admin up to 1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie. The manipulation leads to improper authorization. This vulnerab
CVE-2026-75757 | ash-project ash_admin up to 1.3.0 Cookie improper authorization (EUVD-2026-68324)
A vulnerability has been found in ash-project ash_admin up to 1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie. The manipulation leads to improper authorization. This vulnerab
CVE-2026-82722 | ash-project ash_admin up to 1.3.0 LiveView Event AshAdmin.Components.Resource.Show Module.concat/String.to_atom allocation of resources (EUVD-2026-68325)
A vulnerability, which was classified as problematic, was found in ash-project ash_admin up to 1.3.0. Affected by this vulnerability is the function Module.concat/String.to_atom of the file AshAdmin.PageLive/AshAdmin.Components.Resource.Sho
CVE-2026-82605 | BareBones BBEdit up to 15.5.5 Lasso Language Tokenizer infinite loop (EUVD-2026-68323)
A vulnerability labeled as problematic has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. This vulnerability is d
CVE-2026-82722 | ash-project ash_admin up to 1.3.0 LiveView Event AshAdmin.Components.Resource.Show Module.concat/String.to_atom allocation of resources (EUVD-2026-68325)
A vulnerability, which was classified as problematic, was found in ash-project ash_admin up to 1.3.0. Affected by this vulnerability is the function Module.concat/String.to_atom of the file AshAdmin.PageLive/AshAdmin.Components.Resource.Sho
CVE-2026-82605 | BareBones BBEdit up to 15.5.5 Lasso Language Tokenizer infinite loop (EUVD-2026-68323)
A vulnerability labeled as problematic has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. This vulnerability is d
CVE-2026-82607 | Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress Avatar Simple Upload AJAX /wp-admin/admin-ajax.php wppb_ajax_simple_avatar unrestricted upload (EUVD-2026-68329)
A vulnerability marked as critical has been reported in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar S
CVE-2026-81852 | ash-project ash_admin up to 1.3.0 CSP Nonce Generation AshAdmin.Router.ash_admin csp_nonce_assign_key random values (EUVD-2026-68328)
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been classified as problematic. This vulnerability affects the function AshAdmin.Router.ash_admin of the component CSP Nonce Generation. This manipulation of the argumen
CVE-2026-82607 | Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress Avatar Simple Upload AJAX /wp-admin/admin-ajax.php wppb_ajax_simple_avatar unrestricted upload (EUVD-2026-68329)
A vulnerability marked as critical has been reported in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar S
CVE-2026-81852 | ash-project ash_admin up to 1.3.0 CSP Nonce Generation AshAdmin.Router.ash_admin csp_nonce_assign_key random values (EUVD-2026-68328)
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been classified as problematic. This vulnerability affects the function AshAdmin.Router.ash_admin of the component CSP Nonce Generation. This manipulation of the argumen
CVE-2026-82681 | ash-project ash_admin up to 1.3.0 Table/DataTable/Show injection (EUVD-2026-68327)
A vulnerability was found in ash-project ash_admin up to 1.3.0 and classified as problematic. This affects an unknown part of the component Table/DataTable/Show. The manipulation results in injection. This vulnerability is reported as CVE-2
CVE-2026-82681 | ash-project ash_admin up to 1.3.0 Table/DataTable/Show injection (EUVD-2026-68327)
A vulnerability was found in ash-project ash_admin up to 1.3.0 and classified as problematic. This affects an unknown part of the component Table/DataTable/Show. The manipulation results in injection. This vulnerability is reported as CVE-2
CVE-2026-82673 | ash-project ash_admin 0.13.7/1.3.0 File Upload client_name path traversal (EUVD-2026-68331)
A vulnerability categorized as problematic has been discovered in ash-project ash_admin 0.13.7/1.3.0. The affected element is the function AshAdmin.Components.Resource.Form.consume_file_uploads of the component File Upload. Executing a mani
CVE-2026-82673 | ash-project ash_admin 0.13.7/1.3.0 File Upload client_name path traversal (EUVD-2026-68331)
A vulnerability categorized as problematic has been discovered in ash-project ash_admin 0.13.7/1.3.0. The affected element is the function AshAdmin.Components.Resource.Form.consume_file_uploads of the component File Upload. Executing a mani
CVE-2026-81853 | ash-project ash_admin up to 1.3.0 Helpers AshAdmin.Helpers.decode_primary_key authorization (EUVD-2026-68330)
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been rated as problematic. Impacted is the function AshAdmin.Helpers.decode_primary_key of the component Helpers. Performing a manipulation results in authorization bypa
CVE-2026-81853 | ash-project ash_admin up to 1.3.0 Helpers AshAdmin.Helpers.decode_primary_key authorization (EUVD-2026-68330)
A vulnerability was found in ash-project ash_admin up to 1.3.0. It has been rated as problematic. Impacted is the function AshAdmin.Helpers.decode_primary_key of the component Helpers. Performing a manipulation results in authorization bypa
CVE-2026-82608 | Kamailio up to 5.5.0/6.0.7 AVP cxdx_avp.c get_4bytes out-of-bounds (Issue 4816 / EUVD-2026-68332)
A vulnerability described as critical has been identified in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can
CVE-2026-82608 | Kamailio up to 5.5.0/6.0.7 AVP cxdx_avp.c get_4bytes out-of-bounds (Issue 4816 / EUVD-2026-68332)
A vulnerability described as critical has been identified in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
Originally published at HOL CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation TL;DR: HiveServer2's SAML HTTP path accepted a forged Authorization: Bearer token as a real session. An unauthenticated attacker who can reac
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
Originally published at HOL CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation TL;DR: HiveServer2's SAML HTTP path accepted a forged Authorization: Bearer token as a real session. An unauthenticated attacker who can reac
Gitea-Fix gegen RCE: 8.393 exponierte Server nach CISA-Frist im Angriff
LONDON (IT BOLTWISE) – Angreifer nutzen offenbar aktiv eine kritische RCE-Schwachstelle in Gitea über den diffpatch-Endpunkt. CISA hat CVE-2026-60004 bereits am 25. August in das Known-Exploited-Vulnerabilities-Katalogwerk aufgenommen, doch
CVE-2026-62878: <b>Windows</b>-DNS-Lücke, CVSS 9,8, wurmfähig - Tech Insider
Windows DNS Server: CVE-2026-62878 mit CVSS 9,8 gilt als wurmfähig. Fakten, betroffene Versionen und Sofortmaßnahmen für Admins. Weiterlesen
CVE-2026-62878: <b>Windows</b>-DNS-Lücke, CVSS 9,8, wurmfähig - Tech Insider
Windows DNS Server: CVE-2026-62878 mit CVSS 9,8 gilt als wurmfähig. Fakten, betroffene Versionen und Sofortmaßnahmen für Admins. Weiterlesen
CISA warnt: Ausnutzung kritischer ownCloud-Schwachstelle bei Datenabzug aus Forschungseinrichtungen
PHILIPPINEN / LONDON (IT BOLTWISE) – Die US-Behörde CISA hat die ownCloud-Schwachstelle CVE-2023-49105 in den Known Exploited Vulnerabilities (KEV)-Katalog aufgenommen, nachdem Berichte von aktiver Ausnutzung bekannt wurden. Die Lücke ermög
Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversal during creation. Tracked as CVE-2026-52813, the flaw was reported by Aikido secur
Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversal during creation. Tracked as CVE-2026-52813, the flaw was reported by Aikido secur
Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversal during creation. Tracked as CVE-2026-52813, the flaw was reported by Aikido secur
Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversal during creation. Tracked as CVE-2026-52813, the flaw was reported by Aikido secur
Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks
A critical path traversal vulnerability in Gogs, the self-hosted Git service, could let authenticated attackers achieve remote code execution by planting malicious Git hooks outside the intended repository storage directory. Tracked as CVE-
CISA nimmt ownCloud-Sicherheitslücke in KEV auf: Angriff auf PH-Labor
LONDON (IT BOLTWISE) – Die US-Behörde CISA hat die ownCloud-Schwachstelle CVE-2023-49105 in den KEV-Katalog (Known Exploited Vulnerabilities) aufgenommen. Die Lücke (CVSS 9,8) betrifft einen WebDAV-Authentifizierungs-Bypass und kann Dateien
CVE-2021-41259 | DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Notes: None.
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Notes: None.
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the
U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the
Unitree G1 EDU: Zwei RCE-Ketten per Chat-Interface und BLE bedrohen Root-Rechte
LONDON (IT BOLTWISE) – Zwei getrennte Root-Remote-Code-Execution-Ketten gefährden offenbar die Unitree G1 EDU. Eine der Routen nutzt einen netznahen Weg über chat_go und bashrunner, die andere startet über BLE-Nähe und führt später bis in d
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. W
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. W
CVE-2026-5953 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
CVE-2026-5800 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 280820
CVE-2026-82324 | A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited informatio
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlan
CVE-2026-15603 | morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-awar
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), an
CVE-2026-19412 | This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit this vulnerability by obtaining the hardcoded authentication information from the firmware. Successful exploitation of this vulnerability could allow the attacker to gain unauthorize
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with acces
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sig
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sig