CVE-2020-7200: Schwachstellen-Eintrag (NVD)
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-12 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-71964 | usmannasir CyberPanel up to 2.4.3 File Manager path traversal
A vulnerability, which was classified as problematic, has been found in usmannasir CyberPanel up to 2.4.3. This affects an unknown function of the component File Manager. The manipulation leads to path traversal. This vulnerability is uniqu
CVE-2026-72740 | Dokploy up to 0.29.12 Git Provider git.ts customGitUrl permission
A vulnerability classified as critical has been found in Dokploy up to 0.29.12. This vulnerability affects unknown code of the file packages/server/src/utils/providers/git.ts of the component Git Provider. This manipulation of the argument
CVE-2026-72731 | Discourse up to 2026.1.6/2026.6.1/2026.7.0 Data Explorer data_explorer.rb sql injection
A vulnerability was found in Discourse up to 2026.1.6/2026.6.1/2026.7.0. It has been classified as critical. Impacted is an unknown function of the file plugins/discourse-data-explorer/lib/discourse_data_explorer/data_explorer.rb of the com
CVE-2026-72730 | Discourse up to 2026.1.5/2026.5.1/2026.6.0 Rich Text Editor cross site scripting
A vulnerability identified as problematic has been detected in Discourse up to 2026.1.5/2026.5.1/2026.6.0. The impacted element is an unknown function of the component Rich Text Editor. This manipulation causes cross site scripting. This vu
CVE-2026-72739 | Dokploy up to 0.29.12 createCommand os command injection
A vulnerability described as very critical has been identified in Dokploy up to 0.29.12. This affects the function createCommand. The manipulation results in os command injection. This vulnerability is known as CVE-2026-72739. It is possibl
CVE-2026-48159 | dai-shi use-reducer-async Postinstall Script src/install.js code injection
A vulnerability labeled as critical has been found in dai-shi use-reducer-async. Affected by this vulnerability is an unknown functionality of the file src/install.js of the component Postinstall Script. Executing a manipulation can lead to
CVE-2026-72862 | Dokploy up to 0.29.12 mariadb.ts dockerImage os command injection
A vulnerability identified as very critical has been detected in Dokploy up to 0.29.12. Affected is an unknown function of the file mariadb.ts. Performing a manipulation of the argument dockerImage results in os command injection. This vuln
CVE-2026-72738 | Dokploy up to 0.29.12 Backup Endpoint backup.ts child_process.exec Search privileges management
A vulnerability was found in Dokploy up to 0.29.12. It has been declared as critical. The impacted element is the function child_process.exec of the file apps/dokploy/server/api/routers/backup.ts of the component Backup Endpoint. The manipu
CVE-2026-72736 | Dokploy up to 0.29.12 Registry Credential Testing os command injection
A vulnerability was found in Dokploy up to 0.29.12. It has been rated as critical. This affects an unknown function of the component Registry Credential Testing. This manipulation causes os command injection. This vulnerability is registere
CVE-2026-72735 | Dokploy up to 0.29.12 Traefik Configuration application.ts writeTraefikConfigRemote os command injection
A vulnerability was found in Dokploy up to 0.29.12 and classified as critical. Impacted is the function writeTraefikConfigRemote of the file packages/server/src/utils/traefik/application.ts of the component Traefik Configuration. Executing
CVE-2026-72737 | Dokploy up to 0.29.8 Backup backup.ts destinationId privileges management
A vulnerability was found in Dokploy up to 0.29.8. It has been classified as critical. The affected element is the function backup.create/backup.update/backup.restoreBackupWithLogs of the file apps/dokploy/server/api/routers/backup.ts of th
CVE-2026-72732 | Discourse prior 2026.1.6/2026.5.2/2026.6.1/2026.7.0 TemplatesSerializer templates_serializer.rb access control
A vulnerability, which was classified as problematic, has been found in Discourse. This affects an unknown part of the file plugins/discourse-templates/app/serializers/discourse_templates/templates_serializer.rb of the component TemplatesSe
CVE-2026-72734 | Dokploy up to 0.29.12 Server Removal server.ts server.remove serverId missing encryption
A vulnerability, which was classified as problematic, was found in Dokploy up to 0.29.12. This vulnerability affects the function server.remove of the file apps/dokploy/server/api/routers/server.ts of the component Server Removal. Such mani
CVE-2026-72733 | Dokploy up to 0.29.12 Backup Restore utils.ts backup.restoreBackupWithLogs databaseName/backupFile os command injection
A vulnerability classified as very critical was found in Dokploy up to 0.29.12. Affected by this issue is the function backup.restoreBackupWithLogs of the file packages/server/src/utils/restore/utils.ts of the component Backup Restore. The
CVE-2026-73262 | prowler-cloud Prowler up to 5.36.x HTML output formatter html.py parse_html_string resource_tags HTML injection
A vulnerability, which was classified as problematic, was found in prowler-cloud Prowler up to 5.36.x. This affects the function parse_html_string of the file prowler/lib/outputs/html/html.py of the component HTML output formatter. The mani
CVE-2026-49262 | Aimeos Pagible up to 0.10.3 Administrative Proxy Route server-side request forgery
A vulnerability labeled as problematic has been found in Aimeos Pagible up to 0.10.3. This affects an unknown part of the component Administrative Proxy Route. The manipulation results in server-side request forgery. This vulnerability was
CVE-2026-50561 | xerrors Yuxi up to 0.6.1 improper authorization
A vulnerability identified as critical has been detected in xerrors Yuxi up to 0.6.1. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. This vulnerability is uniquely identified as CVE-2
CVE-2026-49349 | regclient up to 0.11.4 Registry information disclosure
A vulnerability was found in regclient up to 0.11.4. It has been rated as problematic. Affected is an unknown function of the component Registry Handler. Performing a manipulation results in information disclosure. This vulnerability is kno
CVE-2026-47234 | Admidio up to 5.0.9 Session start debug log file
A vulnerability was found in Admidio up to 5.0.9. It has been classified as problematic. This affects the function Session::setCookie/Session::start of the component Session. This manipulation causes information exposure through debug log f
CVE-2026-47233 | Admidio up to 5.0.9 Inventory modules/inventory.php delete privileges management
A vulnerability, which was classified as problematic, was found in Admidio up to 5.0.9. Impacted is the function Admidio\Inventory\Entity\ItemField::delete of the file modules/inventory.php of the component Inventory. Executing a manipulati
CVE-2026-47232 | Admidio up to 5.0.9 SSO Key Management modules/sso/keys.php cross-site request forgery (EUVD-2026-57209)
A vulnerability described as problematic has been identified in Admidio up to 5.0.9. This impacts an unknown function of the file modules/sso/keys.php of the component SSO Key Management. Executing a manipulation can lead to cross-site requ
CVE-2026-47229 | Admidio up to 5.0.9 SSO Client modules/sso/clients.php enable enabled cross-site request forgery
A vulnerability marked as problematic has been reported in Admidio up to 5.0.9. This affects the function enable of the file modules/sso/clients.php of the component SSO Client. Performing a manipulation of the argument enabled results in c
CVE-2026-47231 | Admidio up to 5.0.9 Move documents-files.php File::moveToFolder folder_uuid/file_uuid unrestricted upload
A vulnerability categorized as critical has been discovered in Admidio up to 5.0.9. Impacted is the function File::moveToFolder of the file modules/documents-files.php of the component Move. The manipulation of the argument folder_uuid/file
CVE-2026-47230 | Admidio up to 5.0.9 File Rename documents-files.php renameFile folder_uuid/file_uuid resource injection
A vulnerability was found in Admidio up to 5.0.9. It has been rated as critical. This issue affects the function DocumentsService::renameFile of the file modules/documents-files.php of the component File Rename. The manipulation of the argu
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep
Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots
Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker in close physical proximity to run unauthorized code on the device or pull data stored on it, simply
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV
CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
[UPDATE] [hoch] Red Hat Enterprise Linux (lxml): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen
[UPDATE] [mittel] Red Hat OpenShift: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [niedrig] Red Hat Enterprise Linux (GNU coreutils unexpand): Schwachstelle ermöglicht DoS und Manipulation von Dateien
Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen oder möglicherweise den Speicher zu manipulieren. Weiterlesen
[NEU] [UNGEPATCHT] [niedrig] GNU libc: Schwachstelle ermöglicht Denial of Service
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in GNU libc ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [hoch] libvirt: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in libvirt ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [mittel] QT (NFC-Modul): Schwachstelle ermöglicht DoS and die Offenlegung von Informationen
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in QT ausnutzen, um angrenzenden Speicher offenzulegen oder einen Denial-of-Service-Zustand zu verursachen. Weiterlesen
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
Critical ConfigServer Security & Firewall Flaw Lets Remote Attackers Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands on vulnerable servers. Tracked as CVE-2026-65638, the flaw affects CSF versions 14.00 thro
[UPDATE] [mittel] Snipe-IT: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Snipe-IT ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[UPDATE] [mittel] CyberPanel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in CyberPanel ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
Cisco warnt: Ausnutzung von FMC-Sicherheitslücken ermöglicht Qilin-Ransomware
LONDON (IT BOLTWISE) – Cisco meldet, dass Angreifende zwei kürzlich gepatchte Schwachstellen im Secure Firewall Management Center (FMC) nutzen, um erst Credentials zu stehlen und anschließend Qilin-Ransomware auszurollen. Besonders kritisch
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
[UPDATE] [mittel] Golang Go "FIPS OpenSSL": Schwachstelle ermöglicht nicht spezifizierten Angriff
Ein lokaler Angreifer kann eine Schwachstelle in der Golang Go Komponente "FIPS OpenSSL" ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. Weiterlesen