Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-11 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-46358 | OpenBao up to 2.5.3 Inline Auth Functionality missing encryption
A vulnerability was found in OpenBao up to 2.5.3. It has been declared as problematic. Impacted is an unknown function of the component Inline Auth Functionality. Executing a manipulation can lead to missing encryption of sensitive data. Th
CVE-2026-65819 | gopacket up to 1.7.0 Layer Decoders DecodeFromBytes buffer overflow (210f25f / Nessus ID 333523)
A vulnerability, which was classified as problematic, has been found in gopacket up to 1.7.0. This affects the function DecodeFromBytes of the component Layer Decoders. Performing a manipulation results in buffer overflow. This vulnerabilit
CVE-2026-61808 | HKUDS LightRAG up to 1.5.4 API Server improper authentication
A vulnerability, which was classified as critical, has been found in HKUDS LightRAG up to 1.5.4. Affected by this vulnerability is an unknown functionality of the component API Server. The manipulation leads to improper authentication. This
CVE-2026-62296 | hapifhir HAPI FHIR up to 6.9.10 Xhtml Parser XhtmlParser.java parseElementInner input validation
A vulnerability classified as problematic was found in hapifhir HAPI FHIR up to 6.9.10. Affected is the function parseElementInner of the file XhtmlParser.java of the component Xhtml Parser. Executing a manipulation can lead to improper inp
CVE-2026-47661 | aehrc Pathling up to 1.x Async Export File path traversal
A vulnerability classified as problematic has been found in aehrc Pathling up to 1.x. This impacts an unknown function of the component Async Export. Performing a manipulation of the argument File results in path traversal. This vulnerabili
CVE-2026-62293 | HAPI FHIR up to 6.9.10 Scanner Scanner.java cross site scripting
A vulnerability identified as problematic has been detected in HAPI FHIR up to 6.9.10. Impacted is an unknown function of the file Scanner.java of the component Scanner. The manipulation leads to cross site scripting. This vulnerability is
CVE-2026-47660 | aehrc Pathling up to 1.x Bulk Submit Operation oauthMetadataUrl insufficiently protected credentials
A vulnerability described as critical has been identified in aehrc Pathling up to 1.x. This affects an unknown function of the component Bulk Submit Operation. Such manipulation of the argument oauthMetadataUrl leads to insufficiently prote
CVE-2026-48039 | pipeboard-co meta-ads-mcp up to 1.0.108 Auth Injection Middleware http_auth_integration.py AuthInjectionMiddleware.dispatch improper authentication
A vulnerability was found in pipeboard-co meta-ads-mcp up to 1.0.108. It has been declared as critical. This affects the function AuthInjectionMiddleware.dispatch of the file http_auth_integration.py of the component Auth Injection Middlewa
CVE-2026-48007 | Element HQ Element Call up to 0.5.17/0.19.3 Analytics Reporting config.json information disclosure
A vulnerability categorized as problematic has been discovered in Element HQ Element Call up to 0.5.17/0.19.3. This issue affects some unknown processing of the file config.json of the component Analytics Reporting. Executing a manipulation
CVE-2026-71850 | honojs Hono up to 4.12.33 jsx memo information disclosure
A vulnerability classified as problematic has been found in honojs Hono up to 4.12.33. This vulnerability affects the function memo of the component jsx. The manipulation leads to information disclosure. This vulnerability is documented as
CVE-2026-47659 | aehrc Pathling up to 1.x Result Endpoint File path traversal
A vulnerability marked as problematic has been reported in aehrc Pathling up to 1.x. The impacted element is an unknown function of the component Result Endpoint Handler. This manipulation of the argument File causes path traversal. This vu
CVE-2026-48098 | 0x5t4l1n NexTor IP Changer up to 1.x privileges management
A vulnerability labeled as problematic has been found in 0x5t4l1n NexTor IP Changer up to 1.x. This vulnerability affects unknown code. Executing a manipulation can lead to improper privilege management. This vulnerability is tracked as CVE
CVE-2026-48097 | 0x5t4l1n NexTor IP Changer up to 1.x os command injection
A vulnerability identified as problematic has been detected in 0x5t4l1n NexTor IP Changer up to 1.x. This affects an unknown part. Performing a manipulation results in os command injection. This vulnerability is identified as CVE-2026-48097
CVE-2026-71848 | Honojs Hono up to 4.12.33 languageDetector normalizeLanguage resource consumption
A vulnerability described as problematic has been identified in Honojs Hono up to 4.12.33. This affects the function normalizeLanguage of the component languageDetector. Executing a manipulation can lead to resource consumption. This vulner
CVE-2026-71849 | honojs Hono up to 4.12.33 Proxy Helper proxy information disclosure
A vulnerability marked as problematic has been reported in honojs Hono up to 4.12.33. Affected by this issue is the function proxy of the component Proxy Helper. Performing a manipulation results in information disclosure. This vulnerabilit
CVE-2026-56818 | Netty prior 4.1.136.Final/4.2.16.Final RedisArrayAggregator decodeRedisArrayHeader allocation of resources
A vulnerability categorized as problematic has been discovered in Netty. The affected element is the function decodeRedisArrayHeader of the component RedisArrayAggregator. Executing a manipulation can lead to allocation of resources. This v
CVE-2026-70591 | TryGhost up to 6.54.0 server-side request forgery
A vulnerability described as problematic has been identified in TryGhost Ghost up to 6.54.0. This affects an unknown part. The manipulation results in server-side request forgery. This vulnerability is reported as CVE-2026-70591. The attack
CVE-2026-45705 | OpenSIPS up to 3.6.5 Multipart Body Parser find_line_delimiter out-of-bounds
A vulnerability was found in OpenSIPS up to 3.6.5. It has been classified as critical. This impacts the function find_line_delimiter of the component Multipart Body Parser. This manipulation causes out-of-bounds read. The identification of
CVE-2026-45537 | OpenSIPS up to 3.6.5 URI Construction construct_uri Username buffer overflow
A vulnerability has been found in OpenSIPS up to 3.6.5 and classified as very critical. The impacted element is the function construct_uri of the component URI Construction. The manipulation of the argument Username leads to buffer overflow
CVE-2026-70593 | TryGhost up to 6.54.0 LocalStorageBase path traversal
A vulnerability classified as critical has been found in TryGhost Ghost up to 6.54.0. This vulnerability affects unknown code of the component LocalStorageBase. This manipulation causes path traversal. This vulnerability appears as CVE-2026
CVE-2026-70470 | FlowiseAI Flowise up to 3.1.2 Python Code Validator pythonCodeValidator.ts validatePythonCodeForDataFrame os command injection
A vulnerability was found in FlowiseAI Flowise up to 3.1.2 and classified as critical. Affected by this issue is the function validatePythonCodeForDataFrame of the file packages/components/src/pythonCodeValidator.ts of the component Python
CVE-2026-70594 | TryGhost up to 6.54.0 Admin session fixiation
A vulnerability marked as problematic has been reported in TryGhost Ghost up to 6.54.0. Affected by this issue is some unknown functionality of the component Admin. The manipulation leads to session fixiation. This vulnerability is document
CVE-2026-45103 | OpenSIPS prior 3.6.6/4.0.0-rc1 TCP Message Framing Layer integer overflow
A vulnerability identified as very critical has been detected in OpenSIPS. Affected is an unknown function of the component TCP Message Framing Layer. Performing a manipulation results in integer overflow. This vulnerability is cataloged as
CVE-2026-70592 | TryGhost up to 6.54.0 Database Export Endpoint path traversal
A vulnerability labeled as problematic has been found in TryGhost Ghost up to 6.54.0. Affected by this vulnerability is an unknown functionality of the component Database Export Endpoint. Executing a manipulation can lead to path traversal.
CVE-2026-70590 | TryGhost up to 6.54.0 Admin API privileges management
A vulnerability, which was classified as problematic, has been found in TryGhost Ghost up to 6.54.0. This affects an unknown part of the component Admin API. This manipulation causes improper privilege management. This vulnerability is hand
CVE-2026-45100 | OpenSIPS prior 3.6.6/4.0.0-rc1 Base64 Encoding s.b64encode buffer overflow
A vulnerability categorized as very critical has been discovered in OpenSIPS. This impacts the function s.b64encode of the component Base64 Encoding. Such manipulation leads to buffer overflow. This vulnerability is listed as CVE-2026-45100
CVE-2026-45084 | OpenSIPS up to 3.6.5 Presence handle_publish denial of service
A vulnerability labeled as problematic has been found in OpenSIPS up to 3.6.5. This affects the function handle_publish of the component Presence Module. Such manipulation leads to denial of service. This vulnerability is documented as CVE-
CVE-2026-70589 | TryGhost up to 6.54.0 input validation
A vulnerability classified as problematic was found in TryGhost Ghost up to 6.54.0. Affected by this issue is some unknown functionality. The manipulation results in improper input validation. This vulnerability is known as CVE-2026-70589.
CVE-2026-64835 | FFmpeg up to 8.1.2 ADX Decoder libavcodec/adxdec.c adx_decode_frame prev out-of-bounds (Nessus ID 333552 / WID-SEC-2026-2491)
A vulnerability categorized as critical has been discovered in FFmpeg up to 8.1.2. This affects the function adx_decode_frame of the file libavcodec/adxdec.c of the component ADX Decoder. Executing a manipulation of the argument prev can le
CVE-2026-64833 | FFmpeg up to 8.1.2 SPDIF Muxer spdif_header_dts4 core_size out-of-bounds (Nessus ID 344622 / WID-SEC-2026-2491)
A vulnerability labeled as critical has been found in FFmpeg up to 8.1.2. Affected is the function spdif_header_dts4 of the component SPDIF Muxer. The manipulation of the argument core_size results in out-of-bounds read. This vulnerability
CVE-2026-64832 | FFmpeg up to 8.1.2 NVIDIA NVDEC hardware decoder libavcodec/nvdec.c ff_nvdec_start_frame_sep_ref memory corruption (Nessus ID 333552 / WID-SEC-2026-2491)
A vulnerability identified as critical has been detected in FFmpeg up to 8.1.2. This impacts the function ff_nvdec_start_frame_sep_ref of the file libavcodec/nvdec.c of the component NVIDIA NVDEC hardware decoder. The manipulation leads to
CVE-2026-64834 | FFmpeg up to 8.1.2 ASF Demuxer libavformat/rtpdec_asf.c rtp_asf_fix_header infinite loop (Nessus ID 344622 / WID-SEC-2026-2491)
A vulnerability was found in FFmpeg up to 8.1.2. It has been rated as problematic. The impacted element is the function rtp_asf_fix_header of the file libavformat/rtpdec_asf.c of the component ASF Demuxer. Performing a manipulation results
CVE-2026-64831 | FFmpeg up to 8.1.2 Vulkan HEVC hardware decoder vk_hevc_end_frame vps_num_hrd_parameters stack-based overflow (WID-SEC-2026-2491)
A vulnerability was found in FFmpeg up to 8.1.2. It has been classified as critical. Impacted is the function vk_hevc_end_frame of the component Vulkan HEVC hardware decoder. This manipulation of the argument vps_num_hrd_parameters causes s
CVE-2026-64830 | FFmpeg up to 8.1.2 VobSub subtitle demuxer libavformat/mpeg.c ff_subtitles_queue_insert q heap-based overflow (Nessus ID 333552 / WID-SEC-2026-2491)
A vulnerability was found in FFmpeg up to 8.1.2. It has been declared as critical. The affected element is the function ff_subtitles_queue_insert of the file libavformat/mpeg.c of the component VobSub subtitle demuxer. Such manipulation of
CVE-2026-66062 | SvelteJS Kit up to 2.70.1 Content Negotiation Header Parser resource consumption
A vulnerability was found in SvelteJS Kit up to 2.70.1. It has been declared as problematic. This issue affects some unknown processing of the component Content Negotiation Header Parser. Such manipulation leads to resource consumption. Thi
CVE-2026-48093 | dartiss Code Embed Plugin up to 2.6.0 on WordPress External URL Embed Feature cross site scripting
A vulnerability described as problematic has been identified in dartiss Code Embed Plugin up to 2.6.0 on WordPress. This issue affects some unknown processing of the component External URL Embed Feature. Executing a manipulation can lead to
CVE-2026-62996 | smarty-php Smarty up to 5.8.3 Stream information disclosure
A vulnerability has been found in smarty-php Smarty up to 5.8.3 and classified as problematic. The affected element is an unknown function of the component Stream Handler. This manipulation causes information disclosure. The identification
CVE-2026-62992 | smarty-php Smarty up to 4.5.6/5.8.1 Directory Validation Security::_checkDir path traversal
A vulnerability, which was classified as problematic, was found in smarty-php Smarty up to 4.5.6/5.8.1. Impacted is the function Security::_checkDir of the component Directory Validation. The manipulation results in path traversal. This vul
CVE-2026-48094 | dartiss ShareOpenly Plugin up to 1.2.0 on WordPress esc_url cross site scripting
A vulnerability, which was classified as problematic, has been found in dartiss ShareOpenly Plugin up to 1.2.0 on WordPress. Affected by this issue is the function esc_url. Performing a manipulation of the argument url results in cross site
CVE-2026-71497 | jhy jsoup up to 1.23.0 HTML Parser HTML injection (WID-SEC-2026-2698)
A vulnerability was found in jhy jsoup up to 1.23.0. It has been declared as problematic. The impacted element is an unknown function of the component HTML Parser. The manipulation results in HTML injection. This vulnerability is known as C
CVE-2026-71555 | THM-Health PILOS up to 4.14.0 cross-domain policy
A vulnerability, which was classified as problematic, has been found in THM-Health PILOS up to 4.14.0. This affects an unknown part. This manipulation causes permissive cross-domain policy with untrusted domains. This vulnerability is regis
CVE-2026-71433 | langchain-ai langgraph-checkpoint-postgres up to 3.1.0 information disclosure
A vulnerability identified as problematic has been detected in langchain-ai langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite up to 3.1.0. The impacted element is an unknown function. This manipulation causes information disclos
CVE-2026-71430 | uhop node-re2 up to 1.25.0 Replace WrappedRE2::Replace return value
A vulnerability was found in uhop node-re2 up to 1.25.0. It has been rated as problematic. This affects the function WrappedRE2::Replace of the component Replace. This manipulation causes unchecked return value. This vulnerability is handle
CVE-2026-67434 | PHPCSStandards PHP_CodeSniffer up to 3.13.5/4.0.1 command injection
A vulnerability classified as critical has been found in PHPCSStandards PHP_CodeSniffer up to 3.13.5/4.0.1. Affected by this vulnerability is an unknown functionality. This manipulation causes command injection. The identification of this v
CVE-2026-19127 | Gitroomhq Postiz up to 2.21.9 Billing improper authorization
A vulnerability marked as problematic has been reported in Gitroomhq Postiz up to 2.21.9. Affected by this issue is some unknown functionality of the component Billing. This manipulation causes improper authorization. This vulnerability is
CVE-2026-63637 | dgraph-io Dgraph up to 25.3.7 Query Rewriter query_rewriter.go maybeQuoteArg sql injection
A vulnerability labeled as critical has been found in dgraph-io Dgraph up to 25.3.7. This affects the function maybeQuoteArg of the file graphql/resolve/query_rewriter.go of the component Query Rewriter. Executing a manipulation can lead to
CVE-2026-39924 | Flarum up to 1.8.15 Session Invalidation clearPasswordTokens session expiration
A vulnerability was found in Flarum up to 1.8.15. It has been classified as problematic. This affects the function TokensClearer::clearPasswordTokens of the component Session Invalidation. This manipulation causes session expiration. This v
CVE-2025-63822 | SirenGPS 2.19.44 user identifier access control
A vulnerability classified as critical has been found in SirenGPS 2.19.44. This affects an unknown function. Performing a manipulation of the argument user identifier results in improper access controls. This vulnerability is reported as CV
CVE-2025-63823 | My Safetipin 5.2.1 Authentication hard-coded credentials
A vulnerability described as critical has been identified in My Safetipin 5.2.1. The impacted element is an unknown function of the component Authentication Module. Such manipulation leads to hard-coded credentials. This vulnerability is do
CVE-2026-71192 | OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0 S3API Middleware improper authorization
A vulnerability has been found in OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0 and classified as problematic. This affects an unknown part of the component S3API Middleware. Performing a manipulation results in improper authorization.
CVE-2026-39923 | Flarum Framework up to 1.8.15 Password Reset handle password recovery
A vulnerability was found in Flarum Framework up to 1.8.15 and classified as critical. The impacted element is the function SavePasswordController::handle of the component Password Reset. The manipulation results in weak password recovery.
CVE-2025-70962 | Zosi Camera 4.2.8.823C01 hard-coded credentials
A vulnerability described as problematic has been identified in Zosi Camera 4.2.8.823C01. This impacts an unknown function. Executing a manipulation can lead to hard-coded credentials. This vulnerability is registered as CVE-2025-70962. It
CVE-2026-66747 | Zbtlink Router Firmware Command librctl.so popen improper authentication
A vulnerability was found in Zbtlink Router Firmware. It has been declared as very critical. Affected is the function popen of the file librctl.so of the component Command Handler. The manipulation results in improper authentication. This v
CVE-2026-47682 | cvat-ai CVAT up to 2.64.0 path traversal
A vulnerability was found in cvat-ai CVAT up to 2.64.0. It has been declared as critical. This impacts an unknown function. The manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-47682. The attack may be lau
CVE-2026-52370 | O2OA 10 Forum Posting cross site scripting
A vulnerability was found in O2OA 10. It has been declared as problematic. The impacted element is an unknown function of the component Forum Posting. The manipulation results in cross site scripting. This vulnerability is identified as CVE
CVE-2026-70619 | odysseus-dev Odysseus Embedding Backend improper authorization
A vulnerability marked as critical has been reported in odysseus-dev Odysseus. This impacts an unknown function of the component Embedding Backend. Performing a manipulation results in improper authorization. This vulnerability is reported
CVE-2026-70620 | odysseus-dev Odysseus Embedding Endpoint server-side request forgery
A vulnerability was found in odysseus-dev Odysseus and classified as problematic. Impacted is an unknown function of the component Embedding Endpoint. Executing a manipulation can lead to server-side request forgery. The identification of t
CVE-2026-48154 | pilinux GoRest up to 1.12.1 2FA twoFA.go race condition
A vulnerability marked as problematic has been reported in pilinux GoRest up to 1.12.1. This vulnerability affects unknown code of the file handler/login.go/handler/twoFA.go of the component 2FA. The manipulation leads to race condition. Th
CVE-2026-73282 | OpenBSD OpenSSH up to 10.4 use after free (Nessus ID 344614 / WID-SEC-2026-2747)
A vulnerability was found in OpenBSD OpenSSH up to 10.4 and classified as very critical. This vulnerability affects unknown code. Such manipulation leads to use after free. This vulnerability is referenced as CVE-2026-73282. It is possible
CVE-2026-73281 | OpenBSD OpenSSH up to 10.4 ssh-agent locking (Nessus ID 344614 / WID-SEC-2026-2747)
A vulnerability described as critical has been identified in OpenBSD OpenSSH up to 10.4. This affects an unknown function of the component ssh-agent. Such manipulation leads to improper locking. This vulnerability is traded as CVE-2026-7328