CVE-2021-31424: Schwachstellen-Eintrag (NVD)
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Open Tools Gate component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the hypervisor. Was ZDI-CAN-12848.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-11 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-47765 | Frappe Restore Endpoint privileges management
A vulnerability labeled as critical has been found in Frappe. Affected by this issue is some unknown functionality of the component Restore Endpoint. Such manipulation leads to improper privilege management. This vulnerability is documented
CVE-2026-48054 | OpenZeppelin Contracts Wizard up to 0.10.8 Test File Generation zip-hardhat.ts name/uri code injection
A vulnerability classified as critical was found in OpenZeppelin Contracts Wizard up to 0.10.8. Impacted is an unknown function of the file zip-hardhat.ts of the component Test File Generation. The manipulation of the argument name/uri resu
CVE-2026-71321 | Nuxt prior 3.21.10/4.5.1 Internal Island Renderer Endpoint /__nuxt_island/_.json resource consumption
A vulnerability was found in Nuxt. It has been rated as problematic. Impacted is an unknown function of the file /__nuxt_island/_.json of the component Internal Island Renderer Endpoint. The manipulation leads to resource consumption. This
CVE-2026-47185 | Frappe up to 16.17.x Workspace Save API injection
A vulnerability identified as critical has been detected in Frappe up to 16.17.x. Affected by this vulnerability is an unknown functionality of the component Workspace Save API. This manipulation causes injection. This vulnerability is regi
CVE-2026-45573 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Notification Subscription Flow server-side request forgery
A vulnerability categorized as critical has been discovered in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. Affected is an unknown function of the component Notification Subscription Flow. The manipulation results in server-side request forgery.
CVE-2026-45572 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 HtmlCell HtmlCell#html_content HTML injection
A vulnerability was found in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. It has been rated as problematic. This impacts the function Decidim::ContentBlocks::HtmlCell#html_content of the component HtmlCell. The manipulation leads to HTML injecti
CVE-2026-45378 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Identity-Document Verification Admin UI verification_attachment blobs improper authorization
A vulnerability was found in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. It has been classified as problematic. The impacted element is an unknown function of the file verification_attachment blobs of the component Identity-Document Verificatio
CVE-2026-45414 | Decidim up to 0.31.4/0.32.0.rc1 JWT Authentication proposal.answer improper authentication
A vulnerability was found in Decidim up to 0.31.4/0.32.0.rc1. It has been declared as critical. This affects the function proposal.answer of the component JWT Authentication. Executing a manipulation can lead to improper authentication. Thi
CVE-2026-45415 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Census Logs census_logs improper authorization
A vulnerability, which was classified as problematic, has been found in Decidim up to 0.30.8/0.31.4/0.32.0.rc1. This vulnerability affects unknown code of the file /admin/csv_census/census_logs of the component Census Logs. The manipulation
CVE-2026-47194 | Frappe up to 15.107.x/16.18.2 Magic Login Link Generation Host redirect
A vulnerability, which was classified as problematic, was found in Frappe up to 15.107.x/16.18.2. This issue affects some unknown processing of the component Magic Login Link Generation. The manipulation of the argument Host results in open
CVE-2026-50058 | Siemens Solid Edge DFT file out-of-bounds
A vulnerability was found in Siemens Solid Edge. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component DFT file Handler. Performing a manipulation results in out-of-bounds read. This
CVE-2026-50062 | Siemens Solid Edge PAR file out-of-bounds
A vulnerability classified as critical has been found in Siemens Solid Edge. Affected by this vulnerability is an unknown functionality of the component PAR file Handler. This manipulation causes out-of-bounds read. This vulnerability is re
CVE-2026-72914 | Mastodon up to 4.4.20/4.5.13/4.6.3 RetentionController keys/start_at/end_at improper authorization
A vulnerability identified as problematic has been detected in Mastodon up to 4.4.20/4.5.13/4.6.3. The affected element is the function Api::V1::Admin::MeasuresController/Api::V1::Admin::RetentionController. Performing a manipulation of the
CVE-2026-72916 | Mastodon up to 4.4.20/4.5.13/4.6.3 PrivateAddressCheck private_address_check.rb PrivateAddressCheck.private_address? infinite loop
A vulnerability labeled as critical has been found in Mastodon up to 4.4.20/4.5.13/4.6.3. The impacted element is the function PrivateAddressCheck.private_address? of the file app/lib/private_address_check.rb of the component PrivateAddress
CVE-2026-73033 | Sucuri Security Plugin up to 2.7.3 on WordPress src/integrity.lib.php pageIntegritySubmission sucuriscan_integrity path traversal
A vulnerability marked as problematic has been reported in Sucuri Security Plugin up to 2.7.3 on WordPress. This affects the function pageIntegritySubmission of the file src/integrity.lib.php. This manipulation of the argument sucuriscan_in
CVE-2026-50063 | Siemens Solid Edge PAR file out-of-bounds
A vulnerability identified as critical has been detected in Siemens Solid Edge. This issue affects some unknown processing of the component PAR file Handler. This manipulation causes out-of-bounds read. This vulnerability is tracked as CVE-
CVE-2026-50061 | Siemens Solid Edge DFT file use after free
A vulnerability categorized as critical has been discovered in Siemens Solid Edge. This vulnerability affects unknown code of the component DFT file Handler. The manipulation results in use after free. This vulnerability is identified as CV
CVE-2026-50060 | Siemens Solid Edge DFT file use after free
A vulnerability was found in Siemens Solid Edge. It has been rated as critical. This affects an unknown part of the component DFT file Handler. The manipulation leads to use after free. This vulnerability is referenced as CVE-2026-50060. Re
CVE-2026-50059 | Siemens Solid Edge prior 225.0 Update 15/226.0 Update 7 DFT File Parser out-of-bounds write
A vulnerability was found in Siemens Solid Edge. It has been declared as problematic. Affected by this issue is some unknown functionality of the component DFT File Parser. Executing a manipulation can lead to out-of-bounds write. The ident
CVE-2026-13738 | Commvault up to 11.36.113/11.40.62/11.44.10/11.46.9 CommServe authorization
A vulnerability, which was classified as very critical, has been found in Commvault up to 11.36.113/11.40.62/11.44.10/11.46.9. This vulnerability affects unknown code of the component CommServe/Webserver/Command Center/Media Agents/Clients/
CVE-2026-72919 | RocketChat Rocket.Chat up to 8.6.0 channels.convertToTeam channelName/channelId permission
A vulnerability marked as critical has been reported in RocketChat Rocket.Chat up to 8.6.0. Affected by this vulnerability is an unknown functionality of the component channels.convertToTeam. This manipulation of the argument channelName/ch
CVE-2026-72918 | RocketChat Rocket.Chat up to 8.6.0 Stream-Notify-User Stream privileges management
A vulnerability identified as problematic has been detected in RocketChat Rocket.Chat up to 8.6.0. This impacts an unknown function of the component Stream-Notify-User Stream. The manipulation leads to improper privilege management. This vu
CVE-2026-72915 | Mastodon up to 4.6.3 Collections collections_controller.rb show information disclosure
A vulnerability was found in Mastodon up to 4.6.3. It has been classified as problematic. Impacted is the function show of the file app/controllers/admin/collections_controller.rb of the component Collections. This manipulation causes infor
CVE-2026-71320 | Nuxt up to 3.21.9/4.5.0 Dynamic __nuxt_island__ injection
A vulnerability identified as critical has been detected in Nuxt up to 3.21.9/4.5.0. This issue affects some unknown processing of the component Dynamic Component. The manipulation of the argument __nuxt_island__ leads to injection. This vu
CVE-2026-71319 | Nuxt devtools up to 3.3.0 nuxt:devtools:rpc plugin updateOptions/clearOptions/openInEditor missing authentication
A vulnerability labeled as critical has been found in Nuxt devtools up to 3.3.0. Impacted is the function updateOptions/clearOptions/openInEditor of the component nuxt:devtools:rpc plugin. The manipulation results in missing authentication.
CVE-2026-71318 | Nuxt up to 3.21.9/4.5.0 Dynamic Component Resolution resolveDynamicComponent as input validation
A vulnerability categorized as critical has been discovered in Nuxt up to 3.21.9/4.5.0. This vulnerability affects the function resolveDynamicComponent of the component Dynamic Component Resolution. Executing a manipulation of the argument
CVE-2026-71316 | Nuxt up to 4.5.0 Runtime Cache information disclosure
A vulnerability was found in Nuxt up to 4.5.0. It has been rated as problematic. This affects an unknown part of the component Runtime Cache. Performing a manipulation results in information disclosure. This vulnerability is identified as C
CVE-2026-71315 | Nuxt up to 3.21.9/4.5.0 Route Rules improper authorization
A vulnerability has been found in Nuxt up to 3.21.9/4.5.0 and classified as critical. This impacts an unknown function of the component Route Rules. The manipulation leads to improper authorization. This vulnerability is uniquely identified
CVE-2026-18411 | Acrisure KARR BT-DR-100 improper authorization
A vulnerability marked as critical has been reported in Acrisure KARR BT-DR-100. This vulnerability affects unknown code. The manipulation leads to improper authorization. This vulnerability is documented as CVE-2026-18411. The attack can b
CVE-2026-71314 | Nuxt up to 3.21.9/4.5.0 allocation of resources
A vulnerability, which was classified as problematic, was found in Nuxt up to 3.21.9/4.5.0. This affects an unknown function. Executing a manipulation can lead to allocation of resources. This vulnerability is handled as CVE-2026-71314. The
CVE-2023-4611 | Linux Kernel Memory Management Subsystem mm/mempolicy.c mbind use after free
A vulnerability was found in Linux Kernel. It has been declared as problematic. This issue affects the function mbind of the file mm/mempolicy.c of the component Memory Management Subsystem. Such manipulation leads to use after free. This v
CVE-2026-72903 | Eugeny Tabby up to 1.0.234 SFTP sftp.ts SFTPSession.readdir Name path traversal
A vulnerability was found in Eugeny Tabby up to 1.0.234. It has been rated as critical. The impacted element is the function SFTPSession.readdir of the file tabby-ssh/src/session/sftp.ts of the component SFTP Handler. Performing a manipulat
CVE-2026-72912 | GCHQ CyberChef up to 11.2.x Pretty-Recipe Parser src/core/Utils.mjs Utils.parseRecipeConfig resource consumption
A vulnerability was found in GCHQ CyberChef up to 11.2.x. It has been declared as problematic. This vulnerability affects the function Utils.parseRecipeConfig of the file src/core/Utils.mjs of the component Pretty-Recipe Parser. The manipul
CVE-2026-48160 | dai-shi react-tracked Postinstall Script src/install.js code injection
A vulnerability has been found in dai-shi react-tracked and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/install.js of the component Postinstall Script. Performing a manipulation results
CVE-2026-72909 | Frappe ERPNext up to 15.111.x/16.22.x ReceivablePayableReport accounts_receivable.py prepare_conditions permission
A vulnerability classified as problematic was found in Frappe ERPNext up to 15.111.x/16.22.x. This affects the function prepare_conditions of the file erpnext/accounts/report/accounts_receivable/accounts_receivable.py of the component Recei
CVE-2026-72913 | kovidgoyal Kitty up to 0.48.1 DCS Handlers kitty/window.py handle_remote_echo os command injection
A vulnerability labeled as critical has been found in kovidgoyal Kitty up to 0.48.1. This issue affects the function handle_remote_echo of the file kitty/window.py of the component DCS Handlers. Such manipulation leads to os command injecti
CVE-2026-72910 | Frappe ErpNext up to 15.111.x/16.21.x Accounts account.py permission
A vulnerability categorized as problematic has been discovered in Frappe ErpNext up to 15.111.x/16.21.x. This affects the function merge_account/pause_job_for_doc/trigger_job_for_doc/change_release_date/update_cost_center of the file erpnex
CVE-2026-72911 | Frappe ERPNext up to 15.117.x/16.28.x Template Rendering process_statement_of_accounts.py render_template pdf_name code injection
A vulnerability identified as critical has been detected in Frappe ERPNext up to 15.117.x/16.28.x. This vulnerability affects the function render_template of the file erpnext/accounts/doctype/process_statement_of_accounts/process_statement_
CVE-2026-72718 | aaif-goose up to 1.43.x Review Command handler.rs git_command os command injection
A vulnerability classified as critical was found in aaif-goose goose up to 1.43.x. This affects the function git_command of the file crates/goose-cli/src/commands/review/handler.rs of the component Review Command. Executing a manipulation c
CVE-2026-44401 | Typemill CMS up to 2.23.0 Markdown parser extension ParsedownExtension.php cross site scripting
A vulnerability was found in Typemill CMS up to 2.23.0. It has been rated as problematic. This impacts an unknown function of the file ParsedownExtension.php of the component Markdown parser extension. Performing a manipulation results in c
CVE-2026-28384 | Canonical LXD up to 4.12/5.0.5/5.21.3/6.6 API compression_algorithm os command injection (GHSA-4rmf-rcp8-2r9g / Nessus ID 302534)
A vulnerability identified as critical has been detected in Canonical LXD up to 4.12/5.0.5/5.21.3/6.6. This impacts an unknown function of the component API. Performing a manipulation of the argument compression_algorithm results in os comm
CVE-2026-72719 | Chatwoot up to 4.8.x account_id improper authorization
A vulnerability classified as problematic has been found in Chatwoot up to 4.8.x. Affected by this issue is some unknown functionality. Performing a manipulation of the argument account_id results in improper authorization. This vulnerabili
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security &amp; Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz R
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added th
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Google fixes the seventh actively exploited Chrome zero-day of 2026
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already expl
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at