🎯 CVE-2021-31424 HIGH 8.8 🔥 EPSS 23.6%
📄 .md Alle CVEs anzeigen ✕

CVE-2021-31424: Schwachstellen-Eintrag (NVD)

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Open Tools Gate component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-12848.

Klassifikation & Betroffenheit:
parallels parallels_desktop 15.1.5-47309
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.8
AV · Angriffsvektor Lokal
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Verändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Veröffentlicht:29.04.2021
Aktualisiert:17.06.2026 03:51
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
12 🔴 Critical im Radar
6 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
2 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 186 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.547 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-11
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 47
Microsoft 3
Cisco 2
BareBones 2
WordPress 1
Linux 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 23.7%
CVE-2026-47765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47765 | Frappe Restore Endpoint privileges management

A vulnerability labeled as critical has been found in Frappe. Affected by this issue is some unknown functionality of the component Restore Endpoint. Such manipulation leads to improper privilege management. This vulnerability is documented

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.3%
CVE-2026-48054 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48054 | OpenZeppelin Contracts Wizard up to 0.10.8 Test File Generation zip-hardhat.ts name/uri code injection

A vulnerability classified as critical was found in OpenZeppelin Contracts Wizard up to 0.10.8. Impacted is an unknown function of the file zip-hardhat.ts of the component Test File Generation. The manipulation of the argument name/uri resu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.2%
CVE-2026-71321 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71321 | Nuxt prior 3.21.10/4.5.1 Internal Island Renderer Endpoint /__nuxt_island/_.json resource consumption

A vulnerability was found in Nuxt. It has been rated as problematic. Impacted is an unknown function of the file /__nuxt_island/_.json of the component Internal Island Renderer Endpoint. The manipulation leads to resource consumption. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2026-47185 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47185 | Frappe up to 16.17.x Workspace Save API injection

A vulnerability identified as critical has been detected in Frappe up to 16.17.x. Affected by this vulnerability is an unknown functionality of the component Workspace Save API. This manipulation causes injection. This vulnerability is regi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-45573 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45573 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Notification Subscription Flow server-side request forgery

A vulnerability categorized as critical has been discovered in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. Affected is an unknown function of the component Notification Subscription Flow. The manipulation results in server-side request forgery.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.6%
CVE-2026-45572 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45572 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 HtmlCell HtmlCell#html_content HTML injection

A vulnerability was found in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. It has been rated as problematic. This impacts the function Decidim::ContentBlocks::HtmlCell#html_content of the component HtmlCell. The manipulation leads to HTML injecti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-45378 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-45378 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Identity-Document Verification Admin UI verification_attachment blobs improper authorization

A vulnerability was found in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. It has been classified as problematic. The impacted element is an unknown function of the file verification_attachment blobs of the component Identity-Document Verificatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-45414 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45414 | Decidim up to 0.31.4/0.32.0.rc1 JWT Authentication proposal.answer improper authentication

A vulnerability was found in Decidim up to 0.31.4/0.32.0.rc1. It has been declared as critical. This affects the function proposal.answer of the component JWT Authentication. Executing a manipulation can lead to improper authentication. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-45415 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-45415 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Census Logs census_logs improper authorization

A vulnerability, which was classified as problematic, has been found in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. This vulnerability affects unknown code of the file /admin/csv_census/census_logs of the component Census Logs. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2026-47194 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47194 | Frappe up to 15.107.x/16.18.2 Magic Login Link Generation Host redirect

A vulnerability, which was classified as problematic, was found in Frappe up to 15.107.x/16.18.2. This issue affects some unknown processing of the component Magic Login Link Generation. The manipulation of the argument Host results in open

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2026-50058 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50058 | Siemens Solid Edge DFT file out-of-bounds

A vulnerability was found in Siemens Solid Edge. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component DFT file Handler. Performing a manipulation results in out-of-bounds read. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-50062 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50062 | Siemens Solid Edge PAR file out-of-bounds

A vulnerability classified as critical has been found in Siemens Solid Edge. Affected by this vulnerability is an unknown functionality of the component PAR file Handler. This manipulation causes out-of-bounds read. This vulnerability is re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-72914 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-72914 | Mastodon up to 4.4.20/4.5.13/4.6.3 RetentionController keys/start_at/end_at improper authorization

A vulnerability identified as problematic has been detected in Mastodon up to 4.4.20/4.5.13/4.6.3. The affected element is the function Api::V1::Admin::MeasuresController/Api::V1::Admin::RetentionController. Performing a manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2026-72916 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72916 | Mastodon up to 4.4.20/4.5.13/4.6.3 PrivateAddressCheck private_address_check.rb PrivateAddressCheck.private_address? infinite loop

A vulnerability labeled as critical has been found in Mastodon up to 4.4.20/4.5.13/4.6.3. The impacted element is the function PrivateAddressCheck.private_address? of the file app/lib/private_address_check.rb of the component PrivateAddress

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.5%
CVE-2026-73033 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-73033 | Sucuri Security Plugin up to 2.7.3 on WordPress src/integrity.lib.php pageIntegritySubmission sucuriscan_integrity path traversal

A vulnerability marked as problematic has been reported in Sucuri Security Plugin up to 2.7.3 on WordPress. This affects the function pageIntegritySubmission of the file src/integrity.lib.php. This manipulation of the argument sucuriscan_in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 21.6%
CVE-2026-50063 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50063 | Siemens Solid Edge PAR file out-of-bounds

A vulnerability identified as critical has been detected in Siemens Solid Edge. This issue affects some unknown processing of the component PAR file Handler. This manipulation causes out-of-bounds read. This vulnerability is tracked as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2026-50061 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50061 | Siemens Solid Edge DFT file use after free

A vulnerability categorized as critical has been discovered in Siemens Solid Edge. This vulnerability affects unknown code of the component DFT file Handler. The manipulation results in use after free. This vulnerability is identified as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-50060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50060 | Siemens Solid Edge DFT file use after free

A vulnerability was found in Siemens Solid Edge. It has been rated as critical. This affects an unknown part of the component DFT file Handler. The manipulation leads to use after free. This vulnerability is referenced as CVE-2026-50060. Re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-50059 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-50059 | Siemens Solid Edge prior 225.0 Update 15/226.0 Update 7 DFT File Parser out-of-bounds write

A vulnerability was found in Siemens Solid Edge. It has been declared as problematic. Affected by this issue is some unknown functionality of the component DFT File Parser. Executing a manipulation can lead to out-of-bounds write. The ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-13738 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13738 | Commvault up to 11.36.113/11.40.62/11.44.10/11.46.9 CommServe authorization

A vulnerability, which was classified as very critical, has been found in Commvault up to 11.36.113/11.40.62/11.44.10/11.46.9. This vulnerability affects unknown code of the component CommServe/Webserver/Command Center/Media Agents/Clients/

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-72919 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72919 | RocketChat Rocket.Chat up to 8.6.0 channels.convertToTeam channelName/channelId permission

A vulnerability marked as critical has been reported in RocketChat Rocket.Chat up to 8.6.0. Affected by this vulnerability is an unknown functionality of the component channels.convertToTeam. This manipulation of the argument channelName/ch

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-72918 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72918 | RocketChat Rocket.Chat up to 8.6.0 Stream-Notify-User Stream privileges management

A vulnerability identified as problematic has been detected in RocketChat Rocket.Chat up to 8.6.0. This impacts an unknown function of the component Stream-Notify-User Stream. The manipulation leads to improper privilege management. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.6%
CVE-2026-72915 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-72915 | Mastodon up to 4.6.3 Collections collections_controller.rb show information disclosure

A vulnerability was found in Mastodon up to 4.6.3. It has been classified as problematic. Impacted is the function show of the file app/controllers/admin/collections_controller.rb of the component Collections. This manipulation causes infor

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.6%
CVE-2026-71320 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71320 | Nuxt up to 3.21.9/4.5.0 Dynamic __nuxt_island__ injection

A vulnerability identified as critical has been detected in Nuxt up to 3.21.9/4.5.0. This issue affects some unknown processing of the component Dynamic Component. The manipulation of the argument __nuxt_island__ leads to injection. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.1%
CVE-2026-71319 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71319 | Nuxt devtools up to 3.3.0 nuxt:devtools:rpc plugin updateOptions/clearOptions/openInEditor missing authentication

A vulnerability labeled as critical has been found in Nuxt devtools up to 3.3.0. Impacted is the function updateOptions/clearOptions/openInEditor of the component nuxt:devtools:rpc plugin. The manipulation results in missing authentication.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-71318 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71318 | Nuxt up to 3.21.9/4.5.0 Dynamic Component Resolution resolveDynamicComponent as input validation

A vulnerability categorized as critical has been discovered in Nuxt up to 3.21.9/4.5.0. This vulnerability affects the function resolveDynamicComponent of the component Dynamic Component Resolution. Executing a manipulation of the argument

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.2%
CVE-2026-71316 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71316 | Nuxt up to 4.5.0 Runtime Cache information disclosure

A vulnerability was found in Nuxt up to 4.5.0. It has been rated as problematic. This affects an unknown part of the component Runtime Cache. Performing a manipulation results in information disclosure. This vulnerability is identified as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.8%
CVE-2026-71315 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71315 | Nuxt up to 3.21.9/4.5.0 Route Rules improper authorization

A vulnerability has been found in Nuxt up to 3.21.9/4.5.0 and classified as critical. This impacts an unknown function of the component Route Rules. The manipulation leads to improper authorization. This vulnerability is uniquely identified

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.6%
CVE-2026-18411 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18411 | Acrisure KARR BT-DR-100 improper authorization

A vulnerability marked as critical has been reported in Acrisure KARR BT-DR-100. This vulnerability affects unknown code. The manipulation leads to improper authorization. This vulnerability is documented as CVE-2026-18411. The attack can b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-71314 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71314 | Nuxt up to 3.21.9/4.5.0 allocation of resources

A vulnerability, which was classified as problematic, was found in Nuxt up to 3.21.9/4.5.0. This affects an unknown function. Executing a manipulation can lead to allocation of resources. This vulnerability is handled as CVE-2026-71314. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2023-4611 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2023-4611 | Linux Kernel Memory Management Subsystem mm/mempolicy.c mbind use after free

A vulnerability was found in Linux Kernel. It has been declared as problematic. This issue affects the function mbind of the file mm/mempolicy.c of the component Memory Management Subsystem. Such manipulation leads to use after free. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.2%
CVE-2026-72903 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72903 | Eugeny Tabby up to 1.0.234 SFTP sftp.ts SFTPSession.readdir Name path traversal

A vulnerability was found in Eugeny Tabby up to 1.0.234. It has been rated as critical. The impacted element is the function SFTPSession.readdir of the file tabby-ssh/src/session/sftp.ts of the component SFTP Handler. Performing a manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.3%
CVE-2026-72912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72912 | GCHQ CyberChef up to 11.2.x Pretty-Recipe Parser src/core/Utils.mjs Utils.parseRecipeConfig resource consumption

A vulnerability was found in GCHQ CyberChef up to 11.2.x. It has been declared as problematic. This vulnerability affects the function Utils.parseRecipeConfig of the file src/core/Utils.mjs of the component Pretty-Recipe Parser. The manipul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2026-48160 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-48160 | dai-shi react-tracked Postinstall Script src/install.js code injection

A vulnerability has been found in dai-shi react-tracked and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/install.js of the component Postinstall Script. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-72909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72909 | Frappe ERPNext up to 15.111.x/16.22.x ReceivablePayableReport accounts_receivable.py prepare_conditions permission

A vulnerability classified as problematic was found in Frappe ERPNext up to 15.111.x/16.22.x. This affects the function prepare_conditions of the file erpnext/accounts/report/accounts_receivable/accounts_receivable.py of the component Recei

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2026-72913 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72913 | kovidgoyal Kitty up to 0.48.1 DCS Handlers kitty/window.py handle_remote_echo os command injection

A vulnerability labeled as critical has been found in kovidgoyal Kitty up to 0.48.1. This issue affects the function handle_remote_echo of the file kitty/window.py of the component DCS Handlers. Such manipulation leads to os command injecti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2026-72910 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72910 | Frappe ErpNext up to 15.111.x/16.21.x Accounts account.py permission

A vulnerability categorized as problematic has been discovered in Frappe ErpNext up to 15.111.x/16.21.x. This affects the function merge_account/pause_job_for_doc/trigger_job_for_doc/change_release_date/update_cost_center of the file erpnex

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.1%
CVE-2026-72911 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72911 | Frappe ERPNext up to 15.117.x/16.28.x Template Rendering process_statement_of_accounts.py render_template pdf_name code injection

A vulnerability identified as critical has been detected in Frappe ERPNext up to 15.117.x/16.28.x. This vulnerability affects the function render_template of the file erpnext/accounts/doctype/process_statement_of_accounts/process_statement_

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-72718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72718 | aaif-goose up to 1.43.x Review Command handler.rs git_command os command injection

A vulnerability classified as critical was found in aaif-goose goose up to 1.43.x. This affects the function git_command of the file crates/goose-cli/src/commands/review/handler.rs of the component Review Command. Executing a manipulation c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2026-44401 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-44401 | Typemill CMS up to 2.23.0 Markdown parser extension ParsedownExtension.php cross site scripting

A vulnerability was found in Typemill CMS up to 2.23.0. It has been rated as problematic. This impacts an unknown function of the file ParsedownExtension.php of the component Markdown parser extension. Performing a manipulation results in c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2026-28384 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-28384 | Canonical LXD up to 4.12/5.0.5/5.21.3/6.6 API compression_algorithm os command injection (GHSA-4rmf-rcp8-2r9g / Nessus ID 302534)

A vulnerability identified as critical has been detected in Canonical LXD up to 4.12/5.0.5/5.21.3/6.6. This impacts an unknown function of the component API. Performing a manipulation of the argument compression_algorithm results in os comm

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.5%
CVE-2026-72719 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72719 | Chatwoot up to 4.8.x account_id improper authorization

A vulnerability classified as problematic has been found in Chatwoot up to 4.8.x. Affected by this issue is some unknown functionality. Performing a manipulation of the argument account_id results in improper authorization. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

cPanel ConfigServer Security &amp; Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

A critical vulnerability in ConfigServer Security &amp;amp; Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security &amp;amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 74.6%
CVE-2026-85102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.8 CRITICAL
⚠️ KEV
EPSS 89.1%
CVE-2026-42016 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz R

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 56.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source

TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.8 CRITICAL
⚠️ KEV
EPSS 90.1%
CVE-2026-87491 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google fixes the seventh actively exploited Chrome zero-day of 2026

Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already expl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 87.1%
CVE-2026-81963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as &quot;critical.&quot;Microsoft notes that 2 of the vulnerabiliti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 22.1%
CVE-2026-75757 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 ash-project

CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 6.7%
CVE-2026-82604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-82603 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 n/a

CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.