🎯 CVE-2026-104123
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

CVE-2026-104123: Schwachstellen-Eintrag (NVD)

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 🎯 High

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as…

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, consider using persistence layers such as Hibernate or Enterprise Java Beans, which can provide significant protection against SQL injection if used proper…
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-104123 | SourceCodester Online Reviewer Management System 1.0 btn_funct
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.3
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Gering
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Veröffentlicht:02.10.2026
Aktualisiert:02.10.2026 03:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🗨 Diskussion zu CVE-2026-104123 0 Beiträge
Antworten, Upvotes & Reaktionen — wie im Community-Feed. Markdown und ```Code``` unterstützt.

Noch keine Analyse zu CVE-2026-104123

Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.

↩️ Antworten auf:

Beitrag zu CVE-2026-104123 verfassen

Neu hier? Als Mitglied sammelst du Karma für Beiträge und Answers.
📧
Code-Formatierung: ```bash ... ``` oder `inline code` 0 / 2000
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

372k+ 🇪🇺 EUVD-Datenbank
1 🔴 Critical im Radar
2 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
4 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-10: 312 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 682 2026-06: 941 2026-07: 1327 2026-08: 1827 2026-09: 1504 2026-10: 46 9.393 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-09-182026-10-01
≥90 %0377
≥50 %01137
≥10 %02
<10 %300451
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 98.138 Einträge):
Quelle:
🔍
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91793 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91793 | Foxit PDF Editor/Reader Annotation use after free (EUVD-2026-85129)

A vulnerability categorized as critical has been discovered in Foxit PDF Editor and Reader. Impacted is an unknown function of the component Annotation. The manipulation results in use after free. This vulnerability is cataloged as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-47040 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47040 | Oracle Database Server up to 19.31/21.22/23.26.2 Net Services missing authentication (Nessus ID 330093)

A vulnerability labeled as critical has been found in Oracle Database Server up to 19.31/21.22/23.26.2. This affects an unknown part of the component Net Services. The manipulation results in missing authentication. This vulnerability is ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91790 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91790 | Foxit PDF Editor/PDF Reader use after free (EUVD-2026-85132)

A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-91790. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-47039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47039 | Oracle Database Server up to 19.31/21.22/23.26.2 Java VM improper authorization

A vulnerability described as problematic has been identified in Oracle Database Server up to 19.31/21.22/23.26.2. This vulnerability affects unknown code of the component Java VM. The manipulation results in improper authorization. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91792 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91792 | Foxit PDF Editor/PDF Reader use after free (EUVD-2026-85130)

A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in use after free. This vulnerability is identified as CVE-2026-91792. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-47045 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47045 | Oracle Database Server up to 19.31/21.22/23.26.2 JDBC redirect

A vulnerability described as very critical has been identified in Oracle Database Server up to 19.31/21.22/23.26.2. This issue affects some unknown processing of the component JDBC. Such manipulation leads to open redirect. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91817 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91817 | Foxit PDF Editor/PDF Reader out-of-bounds

A vulnerability, which was classified as problematic, has been found in Foxit PDF Editor and PDF Reader. This issue affects some unknown processing. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-83348 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-83348 | Oracle Database Server RDBMS privileges management

A vulnerability was found in Oracle Database Server. It has been classified as very critical. Affected by this issue is some unknown functionality of the component RDBMS. This manipulation causes improper privilege management. The identific

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91812 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91812 | Foxit PDF Editor/PDF Reader certificate validation

A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes improper certificate validation. This vulnerability is tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-83272 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-83272 | Oracle Database Server Oracle Text privileges management

A vulnerability classified as very critical has been found in Oracle Database Server. The affected element is an unknown function of the component Oracle Text. This manipulation causes improper privilege management. This vulnerability appea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91802 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91802 | Foxit PDF Editor/PDF Reader WebP image decoding heap-based overflow

A vulnerability marked as problematic has been reported in Foxit PDF Editor and PDF Reader. This affects an unknown function of the component WebP image decoding. Performing a manipulation results in heap-based buffer overflow. This vulnera

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91803 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91803 | Foxit PDF Editor/PDF Reader Updater privileges management

A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been classified as problematic. Impacted is an unknown function of the component Updater. The manipulation leads to improper privilege management. This vulnerability is re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91813 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91813 | Foxit PDF Editor/PDF Reader Update Mechanism race condition

A vulnerability has been found in Foxit PDF Editor and PDF Reader and classified as problematic. The affected element is an unknown function of the component Update Mechanism. The manipulation leads to race condition. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-86776 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86776 | KeePass up to 2.61.1 ReadHeaderField allocation of resources (EUVD-2026-74788)

A vulnerability, which was classified as problematic, has been found in KeePass up to 2.61.1. This issue affects the function ReadHeaderField. This manipulation causes allocation of resources. This vulnerability is tracked as CVE-2026-86776

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91814 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91814 | Foxit PDF Editor/PDF Reader Signature Validation data authenticity

A vulnerability classified as problematic was found in Foxit PDF Editor and PDF Reader. This vulnerability affects unknown code of the component Signature Validation. Such manipulation leads to insufficient verification of data authenticity

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91796 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91796 | Foxit PDF Editor/PDF Reader Secure Reading Mode permission (EUVD-2026-85126)

A vulnerability labeled as problematic has been found in Foxit PDF Editor and PDF Reader. The impacted element is an unknown function of the component Secure Reading Mode. Such manipulation leads to permission issues. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91811 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91811 | Foxit PDF Editor/PDF Reader PRC Parser out-of-bounds write

A vulnerability described as problematic has been identified in Foxit PDF Editor and PDF Reader. Affected by this issue is some unknown functionality of the component PRC Parser. The manipulation results in out-of-bounds write. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2026-91794 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91794 | Foxit PDF Editor/PDF Reader PDF Rendering out-of-bounds write (EUVD-2026-85128)

A vulnerability has been found in Foxit PDF Editor and PDF Reader and classified as critical. Affected by this vulnerability is an unknown functionality of the component PDF Rendering. This manipulation causes out-of-bounds write. The ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91805 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91805 | Foxit PDF Editor/PDF Reader PDF Page-Tree use after free (EUVD-2026-85123)

A vulnerability, which was classified as problematic, has been found in Foxit PDF Editor and PDF Reader. Affected by this issue is some unknown functionality of the component PDF Page-Tree Handler. This manipulation causes use after free. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91810 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91810 | Foxit PDF Editor/PDF Reader PDF Image Mask out-of-bounds

A vulnerability marked as problematic has been reported in Foxit PDF Editor and PDF Reader. Affected by this vulnerability is an unknown functionality of the component PDF Image Mask. The manipulation leads to out-of-bounds read. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91809 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91809 | Foxit PDF Editor/PDF Reader PDF Form Fields use after free

A vulnerability labeled as problematic has been found in Foxit PDF Editor and PDF Reader. Affected is an unknown function of the component PDF Form Fields. Executing a manipulation can lead to use after free. This vulnerability is registere

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91818 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91818 | Foxit PDF Editor/PDF Reader JavaScript use after free (EUVD-2026-85156)

A vulnerability, which was classified as problematic, was found in Foxit PDF Editor and PDF Reader. Impacted is an unknown function of the component JavaScript Handler. Executing a manipulation can lead to use after free. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91788 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91788 | Foxit PDF Editor/PDF Reader JavaScript Interface improper authorization (EUVD-2026-85133)

A vulnerability was found in Foxit PDF Editor and PDF Reader and classified as problematic. Affected by this issue is some unknown functionality of the component JavaScript Interface. Such manipulation leads to improper authorization. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.1%
CVE-2026-91799 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91799 | Foxit PDF Editor/PDF Reader JavaScript Array use after free (EUVD-2026-85124)

A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been declared as critical. This vulnerability affects unknown code of the component JavaScript Array Handler. Executing a manipulation can lead to use after free. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-85016 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-85016 | Elementor Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress Widget Parameter Processor icon cross site scripting (EUVD-2026-91192)

A vulnerability, which was classified as problematic, has been found in Elementor Unlimited Elements for Elementor Plugin up to 2.0.20 on WordPress. Impacted is an unknown function of the component Widget Parameter Processor. This manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-91023 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91023 | Motors Plugin up to 1.4.123 on WordPress authorization (EUVD-2026-91194)

A vulnerability has been found in Motors Plugin up to 1.4.123 on WordPress and classified as critical. The impacted element is an unknown function. Performing a manipulation results in missing authorization. This vulnerability is reported a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-91022 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-91022 | Motors Plugin up to 1.4.123 on WordPress cross site scripting (EUVD-2026-91193)

A vulnerability was found in Motors Plugin up to 1.4.123 on WordPress. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting. This vulnerability is handle

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-97317 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97317 | RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress Giveaway Settings information disclosure (EUVD-2026-91196)

A vulnerability categorized as problematic has been discovered in RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress. Affected by this issue is some unknown functionality of the component Giveaway Settings.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-94298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-94298 | BuildKit Plugin up to 1.0.28 on WordPress sql injection (EUVD-2026-91195)

A vulnerability, which was classified as critical, was found in BuildKit Plugin up to 1.0.28 on WordPress. The affected element is an unknown function. Such manipulation leads to sql injection. This vulnerability is documented as CVE-2026-9

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-81740 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-81740 | Paytm Payment Gateway Plugin up to 2.8.8 on WordPress Payment Callback improper authentication (EUVD-2026-91201)

A vulnerability was found in Paytm Payment Gateway Plugin up to 2.8.8 on WordPress and classified as critical. This affects an unknown function of the component Payment Callback Handler. Executing a manipulation can lead to improper authent

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-97318 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97318 | RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress Parent Page URL Validation redirect (EUVD-2026-91197)

A vulnerability identified as problematic has been detected in RafflePress Giveaways and Contests by RafflePress Plugin up to 1.12.26 on WordPress. This affects an unknown part of the component Parent Page URL Validation. Performing a manip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-38724 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

USN-8864-1: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS
CVE-2026-93698 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93698 | Webpros cPanel/WP Squared adminbin os command injection (WID-SEC-2026-3698)

A vulnerability marked as critical has been reported in Webpros cPanel and WP Squared. This issue affects some unknown processing of the component adminbin. The manipulation leads to os command injection. This vulnerability is referenced as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-93697 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93697 | Webpros cPanel/WP Squared Mass Modify Accounts Interface cross site scripting (WID-SEC-2026-3698)

A vulnerability described as problematic has been identified in Webpros cPanel and WP Squared. Impacted is an unknown function of the component Mass Modify Accounts Interface. The manipulation results in cross site scripting. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-93029 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-93029 | Webpros cPanel/WP Squared Manage SSL Hosts Interface cross site scripting (WID-SEC-2026-3698)

A vulnerability labeled as problematic has been found in Webpros cPanel and WP Squared. This vulnerability affects unknown code of the component Manage SSL Hosts Interface. Executing a manipulation can lead to cross site scripting. The iden

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-102490 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-102490 | Zammad privileges management (WID-SEC-2026-3694)

A vulnerability was found in Zammad. It has been rated as problematic. This issue affects some unknown processing. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-102490. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-102489 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-102489 | Zammad up to 6.5.4/7.1.3 session fixiation (WID-SEC-2026-3694)

A vulnerability, which was classified as critical, has been found in Zammad up to 6.5.4/7.1.3. This impacts an unknown function. Performing a manipulation results in session fixiation. This vulnerability is known as CVE-2026-102489. Remote

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

Angriffe auf FortiMail-Zero-Day-Lücke beobachtet

Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

FortiMail: Angriffe auf Zero-Day-Lücke laufen, Workaround verfügbar

Fortinet warnt vor Angriffen auf eine Zero-Day-Sicherheitslücke in FortiMail. Sie ermöglicht die Übernahme der Geräte aus dem Netz. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-2026-92820 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92820 | SaturdayDrive Ninja Forms Plugin up to 3.3.34 on WordPress External File Upload file_path path traversal (EUVD-2026-91175)

A vulnerability categorized as critical has been discovered in SaturdayDrive Ninja Forms Plugin up to 3.3.34 on WordPress. This impacts an unknown function of the component External File Upload. The manipulation of the argument file_path re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-15897 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-15897 | WebRehab Super Forms Plugin up to 6.3.316 on WordPress Register/Login Add-on before_email_success_msg user_id privileges management (EUVD-2026-91176)

A vulnerability marked as critical has been reported in WebRehab Super Forms Plugin up to 6.3.316 on WordPress. Affected by this issue is the function before_email_success_msg of the component Register/Login Add-on. Performing a manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-92174 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-92174 | SiteOrigin Widgets Bundle Plugin up to 1.73.2 on WordPress REST Endpoint previews update_fields theme unrestricted upload (EUVD-2026-91178)

A vulnerability was found in SiteOrigin Widgets Bundle Plugin up to 1.73.2 on WordPress. It has been declared as critical. The impacted element is the function update_fields of the file /wp-json/sowb/v1/widgets/previews of the component RES

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-90438 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-90438 | Ninja Forms Plugin up to 3.15.4 on WordPress cross site scripting (EUVD-2026-91177)

A vulnerability described as problematic has been identified in Ninja Forms Plugin up to 3.15.4 on WordPress. This affects an unknown part. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-78471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-78471 | optimizingmatters Autoptimize Plugin up to 3.1.15.1 on WordPress w3-total-cache.php Comment Author Name cross site scripting (EUVD-2026-91179)

A vulnerability was found in optimizingmatters Autoptimize Plugin up to 3.1.15.1 on WordPress. It has been rated as problematic. This affects an unknown function of the file w3-total-cache/w3-total-cache.php. The manipulation of the argumen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-15896 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-15896 | WebRehab Super Forms Plugin up to 6.3.316 on WordPress parse_request path traversal (EUVD-2026-91180)

A vulnerability identified as problematic has been detected in WebRehab Super Forms Plugin up to 6.3.316 on WordPress. Affected is the function parse_request. This manipulation causes path traversal. The identification of this vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.8%
CVE-2022-45498 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45498 | Tenda W6-S 1.0.0.4 /goform/SysToolReboot tpi_systool_handle denial of service (EUVD-2022-48364)

A vulnerability described as problematic has been identified in Tenda W6-S 1.0.0.4. The impacted element is the function tpi_systool_handle of the file /goform/SysToolReboot. The manipulation results in denial of service. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 2.5%
CVE-2022-45497 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45497 | Tenda W6-S 1.0.0.4 /goform/exeCommand tpi_get_ping_output command injection (EUVD-2022-48363)

A vulnerability was found in Tenda W6-S 1.0.0.4. It has been rated as critical. The impacted element is the function tpi_get_ping_output of the file /goform/exeCommand. Performing a manipulation results in command injection. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.6%
CVE-2022-45496 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45496 | json.h json_parse_string buffer overflow (ID 92 / 0825301a07cbf51653882bf2b153cc81fdadf41)

A vulnerability, which was classified as critical, has been found in json.h. This vulnerability affects the function json_parse_string. Performing a manipulation results in buffer overflow. This vulnerability is cataloged as CVE-2022-45496.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2025-38724 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

USN-8851-2: Linux kernel (Raspberry Pi) vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2022-45494 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45494 | sheredom json.h json_parse_object heap-based overflow (ID 93 / EUVD-2022-48360)

A vulnerability classified as critical has been found in sheredom json.h. Affected by this issue is the function json_parse_object. The manipulation leads to heap-based buffer overflow. This vulnerability is traded as CVE-2022-45494. Access

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2022-45493 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45493 | json.h json_parse_key buffer overflow (GHSA-r2mm-2f4c-6243 / 0825301a07cbf51653882bf2b153cc81fdadf41)

A vulnerability classified as critical was found in json.h. This affects the function json_parse_key. Such manipulation leads to buffer overflow. This vulnerability is listed as CVE-2022-45493. The attack must be carried out from within the

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.2%
CVE-2022-45492 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45492 | json.h json_parse_number buffer overflow (ID 95 / 0825301a07cbf51653882bf2b153cc81fdadf41)

A vulnerability classified as critical has been found in json.h. Affected by this issue is the function json_parse_number. This manipulation causes buffer overflow. This vulnerability is tracked as CVE-2022-45492. The attack is only possibl

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2022-45491 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-45491 | json.h json_parse_value buffer overflow (ID 94 / 0825301a07cbf51653882bf2b153cc81fdadf41)

A vulnerability described as critical has been identified in json.h. Affected by this vulnerability is the function json_parse_value. The manipulation results in buffer overflow. This vulnerability is identified as CVE-2022-45491. The attac

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-104054 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
calcom

CVE-2026-104054 | A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.

A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in mis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-104053 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
itsourcecode

CVE-2026-104053 | A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
EPSS
CVE-2026-21140 💻 Lokal 🔓 Keine Authentifizierung nötig
Samsung Mobile

CVE-2026-21140 | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-104052 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
itsourcecode

CVE-2026-104052 | A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.4 CRITICAL
EPSS
CVE-2026-104480 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Discord

CVE-2026-104480 | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected clients to accept an unauthorized member into the end-to-end encrypted media session, compromising the confidentiality and integrity of audio a

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS
CVE-2026-103098 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
GeoVision Inc.

CVE-2026-103098 | Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor networ

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS
CVE-2026-103097 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
GeoVision Inc.

CVE-2026-103097 | An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
60 von ~0 Einträgen geladen Ende der Trefferliste — 60 Einträge geladen. Tipp: Filter leichtern für tieferes Blättern.