CVE-2025-8036: Schwachstellen-Eintrag (NVD)
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-18 | 2026-10-01 |
|---|---|---|
| ≥90 % | 0 | 377 |
| ≥50 % | 0 | 1137 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 451 |
CVE-2025-9894 | Sync Feedly Plugin up to 1.0.1 on WordPress crsf_cron_job_func cross-site request forgery (EUVD-2025-31414)
A vulnerability, which was classified as problematic, was found in Sync Feedly Plugin up to 1.0.1 on WordPress. The impacted element is the function crsf_cron_job_func. Executing a manipulation can lead to cross-site request forgery. This v
CVE-2025-60104 | Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress cross site scripting
A vulnerability, which was classified as problematic, was found in Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress. Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is cat
CVE-2025-59002 | SeaTheme BM Content Builder Plugin prior 3.16.3.3 on WordPress path traversal
A vulnerability classified as critical has been found in SeaTheme BM Content Builder Plugin on WordPress. Affected by this issue is some unknown functionality. This manipulation causes path traversal. This vulnerability is registered as CVE
CVE-2025-11109 | Campcodes Computer Sales and Inventory System 1.0 us_edit.php?action=edit id sql injection (EUVD-2025-31466)
A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0 and classified as critical. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID lead
CVE-2025-11098 | D-Link DIR-823X 250416 set_wifi_blacklists macList command injection (EUVD-2025-31453 / CNNVD-202509-4307)
A vulnerability was found in D-Link DIR-823X 250416. It has been declared as critical. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injectio
CVE-2025-11095 | D-Link DIR-823X 250416 delete_offline_device delvalue command injection (EUVD-2025-31450 / CNNVD-202509-4310)
A vulnerability has been found in D-Link DIR-823X 250416 and classified as critical. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing a manipulation of the argument delvalue results in command in
CVE-2025-11081 | GNU Binutils 2.45 binutils/objdump.c dump_dwarf_section out-of-bounds (Bug 33406 / EUVD-2025-31443)
A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing a manipulation results in out-of-bounds read. This vulnerab
CVE-2025-11080 | zhuimengshaonian wisdom-education up to 1.0.4 ExamInfoController.java selectStudentExamInfoList subjectId improper authorization (EUVD-2025-31441)
A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4 and classified as problematic. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamI
CVE-2025-11069 | westboy CicadasCMS 1.0 Add Department /system/org/save name cross site scripting (EUVD-2025-31431)
A vulnerability was found in westboy CicadasCMS 1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department Handler. This manipulation of the
CVE-2025-11061 | Campcodes Online Learning Management System 1.0 /admin/edit_student.php cys sql injection (EUVD-2025-31423)
A vulnerability identified as critical has been detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/edit_student.php. Performing a manipulation of the argument cys results in sql inje
CVE-2025-11041 | itsourcecode Open Source Job Portal 1.0 index.php?view=edit id sql injection (EUVD-2025-31389)
A vulnerability was found in itsourcecode Open Source Job Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads
CVE-2025-11037 | code-projects E-Commerce Website 1.0 admin_index_search.php search sql injection (EUVD-2025-31383)
A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. This impacts an unknown function of the file /pages/admin_index_search.php. Performing a manipulation of the argument Search results in sql in
Exchange Server Sicherheits-Updates vom 2.10.2026 schließen CVE-2026-96940
Microsoft hat zum 2. Oktober 2026 Sicherheits-Updates für Microsoft Exchange Server 2016, Microsoft Exchange Server 2019 und Microsoft Exchange Server SE veröffentlicht. Diese adressieren die Elevation of Privilege-Schwachstelle CVE-2026-96
CVE-2025-60249 | CIRCL vulnerability-lookup 2.16.0 bundle.py cross site scripting
A vulnerability categorized as problematic has been discovered in CIRCL vulnerability-lookup 2.16.0. The affected element is an unknown function of the file bundle.py. The manipulation results in cross site scripting. This vulnerability is
CVE-2025-59527 | FlowiseAI Flowise 3.0.5 /api/v1/fetch-links server-side request forgery
A vulnerability labeled as critical has been found in FlowiseAI Flowise 3.0.5. Affected is an unknown function of the file /api/v1/fetch-links. The manipulation results in server-side request forgery. This vulnerability is identified as CVE
CVE-2025-59434 | FlowiseAI Flowise Environment Variable information disclosure
A vulnerability was found in FlowiseAI Flowise and classified as problematic. This affects an unknown function of the component Environment Variable Handler. The manipulation results in information disclosure. This vulnerability is identifi
CVE-2025-10940 | Total.js CMS 1.0.0 Layout Page /admin/ layouts_save HTML cross site scripting (EUVD-2025-31081 / CNNVD-202509-4006)
A vulnerability, which was classified as problematic, has been found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing a manipulation of the argum
CVE-2025-10541 | iMonitor EAM 9.63.94 eamusbsrv64.exe permission assignment
A vulnerability was found in iMonitor EAM 9.63.94 and classified as critical. This issue affects some unknown processing of the file eamusbsrv64.exe. Such manipulation leads to incorrect permission assignment. This vulnerability is listed a
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4
CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What Apache disclosed The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.
CVE-2025-59573 | CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress cross site scripting
A vulnerability was found in CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to basic cross site scripting
CVE-2025-59430 | FrontFin mesh-web-sdk up to 3.3.1 URL Protocol cross site scripting (GHSA-vh3f-qppr-j97f)
A vulnerability, which was classified as problematic, has been found in FrontFin mesh-web-sdk up to 3.3.1. The affected element is an unknown function of the component URL Protocol Handler. This manipulation causes cross site scripting. Thi
CVE-2025-58992 | impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress cross site scripting
A vulnerability marked as problematic has been reported in impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting. This vulnera
CVE-2025-58968 | Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress authorization
A vulnerability was found in Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to missing authorization. This vulnerability is list
CVE-2025-58960 | brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress cross site scripting
A vulnerability identified as problematic has been detected in brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress. This affects an unknown part. This manipulation causes cross site scripting. This vulnerability is tracked as CVE-2025
CVE-2025-58915 | Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress cross site scripting
A vulnerability described as problematic has been identified in Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress. The impacted element is an unknown function. The manipulation results in cross site scripting. This vulnerabili
CVE-2025-58683 | Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress cross site scripting
A vulnerability classified as problematic has been found in Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress. The impacted element is an unknown function. The manipulation leads to cross site scripting. This vulnerability i
CVE-2025-10846 | Portabilis i-Educar up to 2.10 edit id sql injection
A vulnerability, which was classified as critical, has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID causes sql inje
CVE-2025-10845 | Portabilis i-Educar up to 2.10 view id sql injection
A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/ComponenteCurricular/view. The manipulation of the argument ID results in sql injection. This vulnerability
CVE-2025-10839 | SourceCodester Pet Grooming Management Software 1.0 /admin/inv-print.php id sql injection
A vulnerability categorized as critical has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an unknown function of the file /admin/inv-print.php. The manipulation of the argument ID results in
CVE-2025-58665 | tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress cross site scripting
A vulnerability classified as problematic was found in tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulner
CVE-2025-58662 | awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress deserialization
A vulnerability has been found in awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress and classified as problematic. This affects an unknown function. This manipulation causes deserialization. This vulnerability is handled as CVE
CVE-2025-58269 | weDevs WP Project Manager Plugin up to 2.6.25 on WordPress hard-coded credentials
A vulnerability, which was classified as critical, has been found in weDevs WP Project Manager Plugin up to 2.6.25 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in hard-coded credentials. This vuln
CVE-2025-58268 | WPMK PDF Generator Plugin up to 1.0.1 on WordPress cross-site request forgery
A vulnerability was found in WPMK PDF Generator Plugin up to 1.0.1 on WordPress. It has been classified as problematic. Impacted is an unknown function. This manipulation causes cross-site request forgery. This vulnerability is handled as C
CVE-2025-58266 | Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress cross site scripting
A vulnerability classified as problematic was found in Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress. This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is traded as CVE-2025-58266.
CVE-2025-58256 | Jonathan Brinley DOAJ Export Plugin up to 1.0.4 on WordPress cross site scripting
A vulnerability described as problematic has been identified in Jonathan Brinley DOAJ Export Plugin up to 1.0.4 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting. This
CVE-2025-58255 | yonisink Custom Post Type Images Plugin up to 0.5 on WordPress cross-site request forgery
A vulnerability was found in yonisink Custom Post Type Images Plugin up to 0.5 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. This vulnerability is un
CVE-2025-58244 | Anps Constructo Plugin up to 4.3.9 on WordPress cross-site request forgery
A vulnerability described as problematic has been identified in Anps Constructo Plugin up to 4.3.9 on WordPress. This impacts an unknown function. The manipulation results in cross-site request forgery. This vulnerability is cataloged as CV
CVE-2025-58240 | xiligroup xili-tidy-tags Plugin up to 1.12.06 on WordPress cross site scripting
A vulnerability has been found in xiligroup xili-tidy-tags Plugin up to 1.12.06 on WordPress and classified as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability was name
CVE-2025-58239 | Chandrika Sista WP Category Dropdown Plugin up to 1.9 on WordPress cross site scripting
A vulnerability, which was classified as problematic, was found in Chandrika Sista WP Category Dropdown Plugin up to 1.9 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. Th
CVE-2025-58223 | Chris Taylor VoucherPress Plugin up to 1.5.7 on WordPress cross site scripting
A vulnerability described as problematic has been identified in Chris Taylor VoucherPress Plugin up to 1.5.7 on WordPress. Affected is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is han
CVE-2025-58222 | Maidul Team Manager Plugin up to 2.3.14 on WordPress authorization
A vulnerability described as problematic has been identified in Maidul Team Manager Plugin up to 2.3.14 on WordPress. This impacts an unknown function. Such manipulation leads to missing authorization. This vulnerability is referenced as CV
CVE-2026-102490 | Zammad privileges management (WID-SEC-2026-3694)
A vulnerability was found in Zammad. It has been rated as problematic. This issue affects some unknown processing. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-102490. The
CVE-2026-102489 | Zammad up to 6.5.4/7.1.3 session fixiation (WID-SEC-2026-3694)
A vulnerability, which was classified as critical, has been found in Zammad up to 6.5.4/7.1.3. This impacts an unknown function. Performing a manipulation results in session fixiation. This vulnerability is known as CVE-2026-102489. Remote
Meta Muse security: a Mac zero-day and a 6.8 GB filesystem export
Meta Muse, the personal AI agent Meta announced on September 8, had a bad Monday. Patrick Wardle disclosed a zero-day in the Muse Mac app that hands the account token to anyone who can run one terminal command, and developer Peter James ask
CVE-2026-51914 | TransformerOptimus SuperAGI 0.0.14 Agent Template Controller agent_template.py save_agent_as_template/publish_template agent_id/agent_execution_id access control (EUVD-2026-91759)
A vulnerability classified as critical has been found in TransformerOptimus SuperAGI 0.0.14. This issue affects the function save_agent_as_template/publish_template of the file superagi/controllers/agent_template.py of the component Agent T
CVE-2026-51911 | vanna-ai vanna 2.0.2 base.py VannaBase.get_plotly_figure code injection (EUVD-2026-91760)
A vulnerability, which was classified as critical, was found in vanna-ai vanna 2.0.2. The impacted element is the function VannaBase.get_plotly_figure of the file src/vanna/legacy/base/base.py. Such manipulation leads to code injection. Thi
CVE-2026-102795 | Apache Traffic Server up to 9.2.14/10.1.3 access control (EUVD-2026-91766)
A vulnerability described as critical has been identified in Apache Traffic Server up to 9.2.14/10.1.3. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper access controls. The identification
CVE-2026-102626 | LimeSurvey 7.4.0 Date/Time Question date_min cross site scripting (EUVD-2026-91763)
A vulnerability identified as problematic has been detected in LimeSurvey 7.4.0. This impacts an unknown function of the component Date/Time Question. This manipulation of the argument date_min causes cross site scripting. This vulnerabilit
CVE-2026-59265 | Apache OpenOffice up to 4.1.16 Java Integration code injection (EUVD-2026-91764)
A vulnerability marked as critical has been reported in Apache OpenOffice up to 4.1.16. Affected by this vulnerability is an unknown functionality of the component Java Integration. Performing a manipulation results in code injection. This
CVE-2022-45509 | Tenda W30E 1.0.1.25 /goform/addUserName account stack-based overflow (EUVD-2022-48375)
A vulnerability classified as critical has been found in Tenda W30E 1.0.1.25. This affects an unknown part of the file /goform/addUserName. Performing a manipulation of the argument Account results in stack-based buffer overflow. This vulne
CVE-2022-45508 | Tenda W30E 1.0.1.25 /goform/editUserName new_account stack-based overflow (EUVD-2022-48374)
A vulnerability described as critical has been identified in Tenda W30E 1.0.1.25. Affected by this issue is some unknown functionality of the file /goform/editUserName. Such manipulation of the argument new_account leads to stack-based buff
CVE-2022-45507 | Tenda W30E 1.0.1.25 /goform/editFileName editNameMit stack-based overflow (EUVD-2022-48373)
A vulnerability classified as critical was found in Tenda W30E 1.0.1.25. Affected by this vulnerability is an unknown functionality of the file /goform/editFileName. Such manipulation of the argument editNameMit leads to stack-based buffer
CVE-2022-45506 | Tenda W30E 1.0.1.25 /goform/delFileName fileNameMit command injection (EUVD-2022-48372)
A vulnerability classified as critical has been found in Tenda W30E 1.0.1.25. Affected is an unknown function of the file /goform/delFileName. This manipulation of the argument fileNameMit causes command injection. This vulnerability is tra
CVE-2026-59669 | Repasat 203336 name cross site scripting (EUVD-2026-91319)
A vulnerability, which was classified as problematic, was found in Repasat. Affected is an unknown function of the file /es/attachmenttypes/update/203336. The manipulation of the argument Name results in cross site scripting. This vulnerabi
CVE-2026-96292 | Apache Thrift THttpTransport THttpTransport._parseHeaders denial of service (EUVD-2026-91412)
A vulnerability has been found in Apache Thrift and classified as problematic. This vulnerability affects the function THttpTransport._parseHeaders of the component THttpTransport. The manipulation leads to denial of service. This vulnerabi
CVE-2026-85087 | Apache Thrift Python input validation (EUVD-2026-91417)
A vulnerability described as critical has been identified in Apache Thrift. This impacts an unknown function of the component Python. The manipulation results in improper input validation. This vulnerability is reported as CVE-2026-85087. T
CVE-2026-91784 | cjbassi gotop 3.0.0 Process Termination argument injection (EUVD-2026-91318)
A vulnerability has been found in cjbassi gotop 3.0.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Process Termination. This manipulation causes argument injection. This vulnerab
CVE-2026-85086 | Apache Thrift certificate validation (EUVD-2026-91416)
A vulnerability marked as problematic has been reported in Apache Thrift. Affected by this vulnerability is an unknown functionality. This manipulation causes improper certificate validation. This vulnerability is registered as CVE-2026-850
CVE-2026-82459 | Apache Thrift THeaderTransport integer underflow (EUVD-2026-91415)
A vulnerability was found in Apache Thrift. It has been classified as problematic. Impacted is an unknown function of the component THeaderTransport. This manipulation causes integer underflow. The identification of this vulnerability is CV
CVE-2026-82458 | Apache Thrift buffer overflow (EUVD-2026-91414)
A vulnerability categorized as critical has been discovered in Apache Thrift. This affects an unknown function. Executing a manipulation can lead to buffer overflow. This vulnerability is tracked as CVE-2026-82458. The attack can be launche
Noch keine Analyse zu CVE-2025-8036
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.