🎯 CVE-2025-8036
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

CVE-2025-8036: Schwachstellen-Eintrag (NVD)

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and Thunderbird 140.1.

Klassifikation & Betroffenheit:
mozilla firefox *mozilla thunderbird *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🇩🇪 BSI-Sicherheitshinweise: BSI · Mozilla Firefox , Firefox ESR und Thunderbird: Mehrere Schwachstellen ↗
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.1
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Erforderlich
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Veröffentlicht:22.07.2025
Aktualisiert:30.09.2026 18:10
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🗨 Diskussion zu CVE-2025-8036 0 Beiträge
Antworten, Upvotes & Reaktionen — wie im Community-Feed. Markdown und ```Code``` unterstützt.

Noch keine Analyse zu CVE-2025-8036

Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.

↩️ Antworten auf:

Beitrag zu CVE-2025-8036 verfassen

Neu hier? Als Mitglied sammelst du Karma für Beiträge und Answers.
📧
Code-Formatierung: ```bash ... ``` oder `inline code` 0 / 2000
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 312 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1508 2026-10: 69 9.420 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-182026-10-01
≥90 %0377
≥50 %01137
≥10 %02
<10 %300451
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.231 Einträge):
Quelle:
🔍
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-9894 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-9894 | Sync Feedly Plugin up to 1.0.1 on WordPress crsf_cron_job_func cross-site request forgery (EUVD-2025-31414)

A vulnerability, which was classified as problematic, was found in Sync Feedly Plugin up to 1.0.1 on WordPress. The impacted element is the function crsf_cron_job_func. Executing a manipulation can lead to cross-site request forgery. This v

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-60104 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-60104 | Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Jordy Meow Gallery Custom Links Plugin up to 2.2.5 on WordPress. Impacted is an unknown function. The manipulation results in cross site scripting. This vulnerability is cat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-59002 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-59002 | SeaTheme BM Content Builder Plugin prior 3.16.3.3 on WordPress path traversal

A vulnerability classified as critical has been found in SeaTheme BM Content Builder Plugin on WordPress. Affected by this issue is some unknown functionality. This manipulation causes path traversal. This vulnerability is registered as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11109 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11109 | Campcodes Computer Sales and Inventory System 1.0 us_edit.php?action=edit id sql injection (EUVD-2025-31466)

A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0 and classified as critical. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID lead

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.1%
CVE-2025-11098 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11098 | D-Link DIR-823X 250416 set_wifi_blacklists macList command injection (EUVD-2025-31453 / CNNVD-202509-4307)

A vulnerability was found in D-Link DIR-823X 250416. It has been declared as critical. The affected element is an unknown function of the file /goform/set_wifi_blacklists. The manipulation of the argument macList results in command injectio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.1%
CVE-2025-11095 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11095 | D-Link DIR-823X 250416 delete_offline_device delvalue command injection (EUVD-2025-31450 / CNNVD-202509-4310)

A vulnerability has been found in D-Link DIR-823X 250416 and classified as critical. This vulnerability affects unknown code of the file /goform/delete_offline_device. Performing a manipulation of the argument delvalue results in command in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-11081 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11081 | GNU Binutils 2.45 binutils/objdump.c dump_dwarf_section out-of-bounds (Bug 33406 / EUVD-2025-31443)

A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing a manipulation results in out-of-bounds read. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11080 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11080 | zhuimengshaonian wisdom-education up to 1.0.4 ExamInfoController.java selectStudentExamInfoList subjectId improper authorization (EUVD-2025-31441)

A vulnerability was found in zhuimengshaonian wisdom-education up to 1.0.4 and classified as problematic. This vulnerability affects the function selectStudentExamInfoList of the file src/main/java/com/education/api/controller/student/ExamI

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11069 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11069 | westboy CicadasCMS 1.0 Add Department /system/org/save name cross site scripting (EUVD-2025-31431)

A vulnerability was found in westboy CicadasCMS 1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department Handler. This manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11061 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-11061 | Campcodes Online Learning Management System 1.0 /admin/edit_student.php cys sql injection (EUVD-2025-31423)

A vulnerability identified as critical has been detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/edit_student.php. Performing a manipulation of the argument cys results in sql inje

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-11041 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-11041 | itsourcecode Open Source Job Portal 1.0 index.php?view=edit id sql injection (EUVD-2025-31389)

A vulnerability was found in itsourcecode Open Source Job Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-11037 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-11037 | code-projects E-Commerce Website 1.0 admin_index_search.php search sql injection (EUVD-2025-31383)

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. This impacts an unknown function of the file /pages/admin_index_search.php. Performing a manipulation of the argument Search results in sql in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-96940 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Exchange Server Sicherheits-Updates vom 2.10.2026 schließen CVE-2026-96940

Microsoft hat zum 2. Oktober 2026 Sicherheits-Updates für Microsoft Exchange Server 2016, Microsoft Exchange Server 2019 und Microsoft Exchange Server SE veröffentlicht. Diese adressieren die Elevation of Privilege-Schwachstelle CVE-2026-96

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-60249 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-60249 | CIRCL vulnerability-lookup 2.16.0 bundle.py cross site scripting

A vulnerability categorized as problematic has been discovered in CIRCL vulnerability-lookup 2.16.0. The affected element is an unknown function of the file bundle.py. The manipulation results in cross site scripting. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 5%
CVE-2025-59527 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59527 | FlowiseAI Flowise 3.0.5 /api/v1/fetch-links server-side request forgery

A vulnerability labeled as critical has been found in FlowiseAI Flowise 3.0.5. Affected is an unknown function of the file /api/v1/fetch-links. The manipulation results in server-side request forgery. This vulnerability is identified as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.4%
CVE-2025-59434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59434 | FlowiseAI Flowise Environment Variable information disclosure

A vulnerability was found in FlowiseAI Flowise and classified as problematic. This affects an unknown function of the component Environment Variable Handler. The manipulation results in information disclosure. This vulnerability is identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-10940 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-10940 | Total.js CMS 1.0.0 Layout Page /admin/ layouts_save HTML cross site scripting (EUVD-2025-31081 / CNNVD-202509-4006)

A vulnerability, which was classified as problematic, has been found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file /admin/ of the component Layout Page. Performing a manipulation of the argum

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-10541 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10541 | iMonitor EAM 9.63.94 eamusbsrv64.exe permission assignment

A vulnerability was found in iMonitor EAM 9.63.94 and classified as critical. This issue affects some unknown processing of the file eamusbsrv64.exe. Such manipulation leads to incorrect permission assignment. This vulnerability is listed a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-63292 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4

CVE-2026-63292: A Configuration-Dependent Stack Overflow in Apache httpd 2.4 What Apache disclosed The Apache Software Foundation published CVE-2026-63292 as a stack-based buffer overflow in mod_vhost_alias, fixed in Apache HTTP Server 2.4.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-59573 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-59573 | CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress cross site scripting

A vulnerability was found in CozyThemes Cozy Blocks Plugin up to 2.1.29 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to basic cross site scripting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-59430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-59430 | FrontFin mesh-web-sdk up to 3.3.1 URL Protocol cross site scripting (GHSA-vh3f-qppr-j97f)

A vulnerability, which was classified as problematic, has been found in FrontFin mesh-web-sdk up to 3.3.1. The affected element is an unknown function of the component URL Protocol Handler. This manipulation causes cross site scripting. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58992 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58992 | impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress cross site scripting

A vulnerability marked as problematic has been reported in impleCode Product Catalog Simple Plugin up to 1.8.2 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58968 | Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress authorization

A vulnerability was found in Christiaan Pieterse MaxiBlocks Plugin up to 2.1.3 on WordPress. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to missing authorization. This vulnerability is list

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58960 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58960 | brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress cross site scripting

A vulnerability identified as problematic has been detected in brijeshk89 IP Based Login Plugin up to 2.4.3 on WordPress. This affects an unknown part. This manipulation causes cross site scripting. This vulnerability is tracked as CVE-2025

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58915 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58915 | Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress cross site scripting

A vulnerability described as problematic has been identified in Emarket-design YouTube Showcase Plugin up to 3.5.0 on WordPress. The impacted element is an unknown function. The manipulation results in cross site scripting. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58683 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58683 | Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress cross site scripting

A vulnerability classified as problematic has been found in Luke Mlsna Last Updated Shortcode Plugin up to 1.0.1 on WordPress. The impacted element is an unknown function. The manipulation leads to cross site scripting. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10846 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10846 | Portabilis i-Educar up to 2.10 edit id sql injection

A vulnerability, which was classified as critical, has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID causes sql inje

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-10845 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-10845 | Portabilis i-Educar up to 2.10 view id sql injection

A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/ComponenteCurricular/view. The manipulation of the argument ID results in sql injection. This vulnerability

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-10839 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2025-10839 | SourceCodester Pet Grooming Management Software 1.0 /admin/inv-print.php id sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an unknown function of the file /admin/inv-print.php. The manipulation of the argument ID results in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58665 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58665 | tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in tmontg1 Form Generator for WordPress Plugin up to 1.5.2 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2025-58662 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58662 | awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress deserialization

A vulnerability has been found in awesomesupport Awesome Support Plugin up to 6.3.4 on WordPress and classified as problematic. This affects an unknown function. This manipulation causes deserialization. This vulnerability is handled as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58269 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58269 | weDevs WP Project Manager Plugin up to 2.6.25 on WordPress hard-coded credentials

A vulnerability, which was classified as critical, has been found in weDevs WP Project Manager Plugin up to 2.6.25 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in hard-coded credentials. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2025-58268 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58268 | WPMK PDF Generator Plugin up to 1.0.1 on WordPress cross-site request forgery

A vulnerability was found in WPMK PDF Generator Plugin up to 1.0.1 on WordPress. It has been classified as problematic. Impacted is an unknown function. This manipulation causes cross-site request forgery. This vulnerability is handled as C

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58266 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58266 | Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in Fumiki Takahashi Gianism Plugin up to 5.2.2 on WordPress. This affects an unknown part. Such manipulation leads to cross site scripting. This vulnerability is traded as CVE-2025-58266.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58256 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58256 | Jonathan Brinley DOAJ Export Plugin up to 1.0.4 on WordPress cross site scripting

A vulnerability described as problematic has been identified in Jonathan Brinley DOAJ Export Plugin up to 1.0.4 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58255 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58255 | yonisink Custom Post Type Images Plugin up to 0.5 on WordPress cross-site request forgery

A vulnerability was found in yonisink Custom Post Type Images Plugin up to 0.5 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. This vulnerability is un

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58244 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58244 | Anps Constructo Plugin up to 4.3.9 on WordPress cross-site request forgery

A vulnerability described as problematic has been identified in Anps Constructo Plugin up to 4.3.9 on WordPress. This impacts an unknown function. The manipulation results in cross-site request forgery. This vulnerability is cataloged as CV

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58240 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58240 | xiligroup xili-tidy-tags Plugin up to 1.12.06 on WordPress cross site scripting

A vulnerability has been found in xiligroup xili-tidy-tags Plugin up to 1.12.06 on WordPress and classified as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability was name

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58239 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58239 | Chandrika Sista WP Category Dropdown Plugin up to 1.9 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Chandrika Sista WP Category Dropdown Plugin up to 1.9 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2025-58223 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58223 | Chris Taylor VoucherPress Plugin up to 1.5.7 on WordPress cross site scripting

A vulnerability described as problematic has been identified in Chris Taylor VoucherPress Plugin up to 1.5.7 on WordPress. Affected is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is han

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2025-58222 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2025-58222 | Maidul Team Manager Plugin up to 2.3.14 on WordPress authorization

A vulnerability described as problematic has been identified in Maidul Team Manager Plugin up to 2.3.14 on WordPress. This impacts an unknown function. Such manipulation leads to missing authorization. This vulnerability is referenced as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-102490 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-102490 | Zammad privileges management (WID-SEC-2026-3694)

A vulnerability was found in Zammad. It has been rated as problematic. This issue affects some unknown processing. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-102490. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.7%
CVE-2026-102489 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-102489 | Zammad up to 6.5.4/7.1.3 session fixiation (WID-SEC-2026-3694)

A vulnerability, which was classified as critical, has been found in Zammad up to 6.5.4/7.1.3. This impacts an unknown function. Performing a manipulation results in session fixiation. This vulnerability is known as CVE-2026-102489. Remote

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Meta Muse security: a Mac zero-day and a 6.8 GB filesystem export

Meta Muse, the personal AI agent Meta announced on September 8, had a bad Monday. Patrick Wardle disclosed a zero-day in the Muse Mac app that hands the account token to anyone who can run one terminal command, and developer Peter James ask

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-51914 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-51914 | TransformerOptimus SuperAGI 0.0.14 Agent Template Controller agent_template.py save_agent_as_template/publish_template agent_id/agent_execution_id access control (EUVD-2026-91759)

A vulnerability classified as critical has been found in TransformerOptimus SuperAGI 0.0.14. This issue affects the function save_agent_as_template/publish_template of the file superagi/controllers/agent_template.py of the component Agent T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-51911 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-51911 | vanna-ai vanna 2.0.2 base.py VannaBase.get_plotly_figure code injection (EUVD-2026-91760)

A vulnerability, which was classified as critical, was found in vanna-ai vanna 2.0.2. The impacted element is the function VannaBase.get_plotly_figure of the file src/vanna/legacy/base/base.py. Such manipulation leads to code injection. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-102795 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-102795 | Apache Traffic Server up to 9.2.14/10.1.3 access control (EUVD-2026-91766)

A vulnerability described as critical has been identified in Apache Traffic Server up to 9.2.14/10.1.3. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper access controls. The identification

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-102626 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-102626 | LimeSurvey 7.4.0 Date/Time Question date_min cross site scripting (EUVD-2026-91763)

A vulnerability identified as problematic has been detected in LimeSurvey 7.4.0. This impacts an unknown function of the component Date/Time Question. This manipulation of the argument date_min causes cross site scripting. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-59265 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-59265 | Apache OpenOffice up to 4.1.16 Java Integration code injection (EUVD-2026-91764)

A vulnerability marked as critical has been reported in Apache OpenOffice up to 4.1.16. Affected by this vulnerability is an unknown functionality of the component Java Integration. Performing a manipulation results in code injection. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS 0.9%
CVE-2022-45509 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45509 | Tenda W30E 1.0.1.25 /goform/addUserName account stack-based overflow (EUVD-2022-48375)

A vulnerability classified as critical has been found in Tenda W30E 1.0.1.25. This affects an unknown part of the file /goform/addUserName. Performing a manipulation of the argument Account results in stack-based buffer overflow. This vulne

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.9%
CVE-2022-45508 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45508 | Tenda W30E 1.0.1.25 /goform/editUserName new_account stack-based overflow (EUVD-2022-48374)

A vulnerability described as critical has been identified in Tenda W30E 1.0.1.25. Affected by this issue is some unknown functionality of the file /goform/editUserName. Such manipulation of the argument new_account leads to stack-based buff

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2022-45507 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45507 | Tenda W30E 1.0.1.25 /goform/editFileName editNameMit stack-based overflow (EUVD-2022-48373)

A vulnerability classified as critical was found in Tenda W30E 1.0.1.25. Affected by this vulnerability is an unknown functionality of the file /goform/editFileName. Such manipulation of the argument editNameMit leads to stack-based buffer

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 2.5%
CVE-2022-45506 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45506 | Tenda W30E 1.0.1.25 /goform/delFileName fileNameMit command injection (EUVD-2022-48372)

A vulnerability classified as critical has been found in Tenda W30E 1.0.1.25. Affected is an unknown function of the file /goform/delFileName. This manipulation of the argument fileNameMit causes command injection. This vulnerability is tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-59669 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59669 | Repasat 203336 name cross site scripting (EUVD-2026-91319)

A vulnerability, which was classified as problematic, was found in Repasat. Affected is an unknown function of the file /es/attachmenttypes/update/203336. The manipulation of the argument Name results in cross site scripting. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-96292 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-96292 | Apache Thrift THttpTransport THttpTransport._parseHeaders denial of service (EUVD-2026-91412)

A vulnerability has been found in Apache Thrift and classified as problematic. This vulnerability affects the function THttpTransport._parseHeaders of the component THttpTransport. The manipulation leads to denial of service. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-85087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-85087 | Apache Thrift Python input validation (EUVD-2026-91417)

A vulnerability described as critical has been identified in Apache Thrift. This impacts an unknown function of the component Python. The manipulation results in improper input validation. This vulnerability is reported as CVE-2026-85087. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-91784 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91784 | cjbassi gotop 3.0.0 Process Termination argument injection (EUVD-2026-91318)

A vulnerability has been found in cjbassi gotop 3.0.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Process Termination. This manipulation causes argument injection. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-85086 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-85086 | Apache Thrift certificate validation (EUVD-2026-91416)

A vulnerability marked as problematic has been reported in Apache Thrift. Affected by this vulnerability is an unknown functionality. This manipulation causes improper certificate validation. This vulnerability is registered as CVE-2026-850

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-82459 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-82459 | Apache Thrift THeaderTransport integer underflow (EUVD-2026-91415)

A vulnerability was found in Apache Thrift. It has been classified as problematic. Impacted is an unknown function of the component THeaderTransport. This manipulation causes integer underflow. The identification of this vulnerability is CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-82458 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-82458 | Apache Thrift buffer overflow (EUVD-2026-91414)

A vulnerability categorized as critical has been discovered in Apache Thrift. This affects an unknown function. Executing a manipulation can lead to buffer overflow. This vulnerability is tracked as CVE-2026-82458. The attack can be launche

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.