🎯 CVE-2026-28583
📄 .md Alle CVEs anzeigen ✕

CVE-2026-28583: Schwachstellen-Eintrag (NVD)

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Klassifikation & Betroffenheit:
google android 14.0google android 15.0google android 16.0
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-28583 | Google Android 14/15/16/16-qpr2 Camera Metadata Validation came
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.8
AV · Angriffsvektor Lokal
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:08.09.2026
Aktualisiert:15.09.2026 14:31
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
1 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 145 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.506 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-16
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 32.9%
CVE-2026-57173 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-57173 | vllm-project vLLM up to 0.23.x Audio Decoder /v1/chat/completions AudioMediaIO.load_bytes resource consumption (EUVD-2026-80880)

A vulnerability, which was classified as problematic, has been found in vllm-project vLLM up to 0.23.x. This affects the function AudioMediaIO.load_bytes of the file /v1/chat/completions of the component Audio Decoder. Performing a manipula

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.6%
CVE-2026-59193 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59193 | getgrav Grav up to 1.x ZIP Archive extractTo denial of service (EUVD-2026-42951)

A vulnerability identified as problematic has been detected in getgrav Grav up to 1.x. This affects the function extractTo of the component ZIP Archive Handler. The manipulation leads to denial of service. This vulnerability is documented a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-63128 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63128 | modelcontextprotocol rust-sdk up to 1.x Streamable HTTP Server tower.rs handle_post initialization (EUVD-2026-80823)

A vulnerability was found in modelcontextprotocol rust-sdk up to 1.x. It has been declared as problematic. This issue affects the function StreamableHttpService::handle_post of the file crates/rmcp/src/transport/streamable_http_server/tower

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2026-63127 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63127 | Model Context Protocol RMCP SDK up to 1.x OAuth Implementation auth.rs discover_oauth_server_via_resource_metadata improper authorization (EUVD-2026-80824)

A vulnerability classified as problematic was found in Model Context Protocol RMCP SDK up to 1.x. This impacts the function discover_oauth_server_via_resource_metadata of the file crates/rmcp/src/transport/auth.rs of the component OAuth Imp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-63671 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63671 | nuxt-content mdc up to 0.22.0 Sanitizer parseMarkdown allowDangerousHtml cross site scripting (EUVD-2026-80789)

A vulnerability, which was classified as problematic, has been found in nuxt-content mdc up to 0.22.0. The impacted element is the function parseMarkdown of the component Sanitizer. This manipulation of the argument allowDangerousHtml cause

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-61709 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61709 | OpenFGA up to 1.18.0 ListUsers API list_users_rpc.go expandIntersection improper authorization (EUVD-2026-80777)

A vulnerability categorized as problematic has been discovered in OpenFGA up to 1.18.0. This affects the function expandIntersection of the file pkg/server/commands/listusers/list_users_rpc.go of the component ListUsers API. Executing a man

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.9%
CVE-2026-58657 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58657 | Grav up to 2.0.0-rc.9 Media Action processMediaActions resize injection (EUVD-2026-42267)

A vulnerability labeled as problematic has been found in Grav up to 2.0.0-rc.9. This affects the function Excerpts::processMediaActions of the component Media Action Handler. The manipulation of the argument resize results in injection. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.5%
CVE-2026-65388 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65388 | Apple containerization up to 0.40.x information disclosure (EUVD-2026-81274)

A vulnerability classified as problematic has been found in Apple containerization up to 0.40.x. Impacted is an unknown function. This manipulation causes information disclosure. The identification of this vulnerability is CVE-2026-65388. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-92802 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92802 | kanbn kan up to 0.6.0 GitHub Project Import Endpoint improper authorization (EUVD-2026-81062)

A vulnerability identified as problematic has been detected in kanbn kan up to 0.6.0. This affects an unknown part of the component GitHub Project Import Endpoint. This manipulation causes improper authorization. This vulnerability is track

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-92804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92804 | NangoHQ Nango up to 0.70.4 input validation (EUVD-2026-81064)

A vulnerability labeled as critical has been found in NangoHQ Nango up to 0.70.4. This vulnerability affects unknown code. Such manipulation leads to improper input validation. This vulnerability is listed as CVE-2026-92804. The attack may

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-92803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92803 | LibreTranslate up to 1.9.6 improper authorization (EUVD-2026-81063)

A vulnerability classified as problematic was found in LibreTranslate up to 1.9.6. This issue affects some unknown processing. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2026-92803. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-92806 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92806 | phpList up to 3.6.16 Mass Subscriber Removal Form cross-site request forgery (EUVD-2026-81066)

A vulnerability categorized as problematic has been discovered in phpList up to 3.6.16. This impacts an unknown function of the component Mass Subscriber Removal Form Handler. Executing a manipulation can lead to cross-site request forgery.

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-92805 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92805 | UVdesk Community Skeleton up to 1.1.8 Installation Wizard improper authentication (EUVD-2026-81065)

A vulnerability has been found in UVdesk Community Skeleton up to 1.1.8 and classified as critical. The impacted element is an unknown function of the component Installation Wizard. This manipulation causes improper authentication. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-92809 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92809 | PrestaShop psgdpr up to 1.4.3 privileges management (EUVD-2026-81067)

A vulnerability, which was classified as problematic, has been found in PrestaShop psgdpr up to 1.4.3. Impacted is an unknown function. The manipulation leads to improper privilege management. This vulnerability is traded as CVE-2026-92809.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.5%
CVE-2026-76438 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-76438 | Cisco BroadWorks Web-based Management Interface improper authorization (EUVD-2026-81161)

A vulnerability classified as problematic has been found in Cisco BroadWorks. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to improper authorization. This vulnerability is referenced a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 29.8%
CVE-2026-88765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-88765 | GitLab up to 19.1.7/19.2.5/19.3.1 Advanced Search buffer overflow (WID-SEC-2026-3315)

A vulnerability has been found in GitLab up to 19.1.7/19.2.5/19.3.1 and classified as critical. Affected by this issue is some unknown functionality of the component Advanced Search. This manipulation causes buffer overflow. The identificat

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.4%
CVE-2026-87719 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87719 | GitLab EE up to 19.1.7/19.2.5/19.3.1 GraphQL Subscription subscription information disclosure (WID-SEC-2026-3315)

A vulnerability categorized as problematic has been discovered in GitLab EE up to 19.1.7/19.2.5/19.3.1. This affects an unknown function of the component GraphQL Subscription. The manipulation of the argument subscription results in informa

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-86341 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86341 | GitLab up to 19.1.7/19.2.5/19.3.1 access control (WID-SEC-2026-3315)

A vulnerability classified as problematic was found in GitLab up to 19.1.7/19.2.5/19.3.1. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper access controls. This vulnerability appears as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-82837 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82837 | GitLab up to 19.1.7/19.2.5/19.3.1 improper authorization (WID-SEC-2026-3315)

A vulnerability classified as problematic was found in GitLab up to 19.1.7/19.2.5/19.3.1. This vulnerability affects unknown code. The manipulation results in improper authorization. This vulnerability was named CVE-2026-82837. The attack m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-8030 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-8030 | GitLab up to 19.1.7/19.2.5/19.3.1 Namespace Transfer input validation (WID-SEC-2026-3315)

A vulnerability marked as problematic has been reported in GitLab up to 19.1.7/19.2.5/19.3.1. This vulnerability affects unknown code of the component Namespace Transfer. Performing a manipulation results in improper input validation. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-79708 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79708 | GitLab up to 19.1.7/19.2.5/19.3.1 CI/CD Variables improper authorization (WID-SEC-2026-3315)

A vulnerability described as problematic has been identified in GitLab up to 19.1.7/19.2.5/19.3.1. This issue affects some unknown processing of the component CI/CD Variables. Executing a manipulation can lead to improper authorization. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-7514 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-7514 | GitLab up to 19.1.7/19.2.5/19.3.1 Generic Package Registry improper authorization (WID-SEC-2026-3315)

A vulnerability labeled as critical has been found in GitLab up to 19.1.7/19.2.5/19.3.1. This affects an unknown part of the component Generic Package Registry. Such manipulation leads to improper authorization. This vulnerability is docume

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-78252 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78252 | GitLab up to 19.1.7/19.2.5/19.3.1 Markdown JSON Table Renderer cross-site request forgery (WID-SEC-2026-3315)

A vulnerability identified as problematic has been detected in GitLab up to 19.1.7/19.2.5/19.3.1. Affected by this issue is some unknown functionality of the component Markdown JSON Table Renderer. This manipulation causes cross-site reques

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.5%
CVE-2026-19619 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19619 | GitLab up to 19.1.7/19.2.5/19.3.1 Content Editor cross site scripting (WID-SEC-2026-3315)

A vulnerability was found in GitLab up to 19.1.7/19.2.5/19.3.1. It has been rated as problematic. Affected is an unknown function of the component Content Editor. The manipulation leads to cross site scripting. This vulnerability is listed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-3855 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-3855 | GitLab up to 19.1.7/19.2.5/19.3.1 Terraform State Upload privileges management (WID-SEC-2026-3315)

A vulnerability categorized as critical has been discovered in GitLab up to 19.1.7/19.2.5/19.3.1. Affected by this vulnerability is an unknown functionality of the component Terraform State Upload. The manipulation results in improper privi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.9%
CVE-2026-16794 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-16794 | GitLab up to 19.1.7/19.2.5/19.3.1 Compliance Framework Management improper authorization (WID-SEC-2026-3315)

A vulnerability was found in GitLab up to 19.1.7/19.2.5/19.3.1. It has been declared as problematic. This impacts an unknown function of the component Compliance Framework Management. Executing a manipulation can lead to improper authorizat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.0 CRITICAL
EPSS 61.9%
CVE-2026-16723 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-16723: Pre-Auth RCE in Fastjson 1.x via the @JSONType Trust Branch

Overview CVE ID CVE-2026-16723 Affected Fastjson 1.2.68 – 1.2.83 (every 1.x release still receiving use) Preconditions Spring Boot executable fat-JAR, safeMode disabled (default), AutoType disabled (default) Auth required None (pre-authenti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.3%
CVE-2026-92811 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92811 | Browserless up to 2.56.7 Playwright Websocket Endpoint ALLOW_FILE_PROTOCOL information disclosure (EUVD-2026-81069)

A vulnerability, which was classified as problematic, was found in Browserless up to 2.56.7. Affected by this issue is some unknown functionality of the component Playwright Websocket Endpoint. Executing a manipulation of the argument ALLOW

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.1%
CVE-2026-92810 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92810 | PrestaShop blockwishlist up to 3.0.2 getUrlByIdWishListAction privileges management (EUVD-2026-81068)

A vulnerability marked as problematic has been reported in PrestaShop blockwishlist up to 3.0.2. This issue affects the function getUrlByIdWishListAction. Performing a manipulation results in improper privilege management. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-92812 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92812 | Decap Server Local Proxy Containment Guard path traversal (EUVD-2026-81070)

A vulnerability categorized as critical has been discovered in Decap Server. The impacted element is an unknown function of the component Local Proxy Containment Guard. Executing a manipulation can lead to path traversal. The identification

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-92813 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92813 | Metabase up to 0.63.18 GeoJSON server-side request forgery (EUVD-2026-81071)

A vulnerability was found in Metabase up to 0.63.18. It has been classified as problematic. This issue affects some unknown processing of the component GeoJSON Handler. This manipulation causes server-side request forgery. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-92814 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92814 | dgtlmoon changedetection.io up to 0.60.6 HTML Notifications watch_title HTML injection (EUVD-2026-81072)

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.6. It has been declared as problematic. Impacted is an unknown function of the component HTML Notifications. Such manipulation of the argument watch_title leads to HTML inj

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-92815 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92815 | dgtlmoon changedetection.io up to 0.60.6 Browser Steps optional_value server-side request forgery (EUVD-2026-81073)

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.6. It has been rated as problematic. The affected element is an unknown function of the component Browser Steps. Performing a manipulation of the argument optional_value re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-92816 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92816 | Comfy-Org ComfyUI up to 0.29.x Dataset Save Nodes folder_name path traversal (EUVD-2026-81074)

A vulnerability was found in Comfy-Org ComfyUI up to 0.29.x and classified as critical. This vulnerability affects unknown code of the component Dataset Save Nodes. The manipulation of the argument folder_name results in path traversal. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2026-87931 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-87931 | Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707 Apple Notification Center Service Event buffer overflow

A vulnerability classified as very critical has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handl

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-91998 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91998 | Casdoor up to 4.4.0 /api/mcp authorization (CNNVD-2026-98861437)

A vulnerability identified as critical has been detected in Casdoor up to 4.4.0. The impacted element is an unknown function of the file /api/mcp. The manipulation leads to authorization bypass. This vulnerability is uniquely identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-91972 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-91972 | go-vikunja Vikunja up to 2.5.x Rate Limiting excessive authentication (CNNVD-2026-99323983)

A vulnerability marked as problematic has been reported in go-vikunja Vikunja up to 2.5.x. The affected element is an unknown function of the component Rate Limiting. Performing a manipulation results in improper restriction of excessive au

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2026-86465 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-86465 | Apache Airflow Akeyless Provider privileges management (WID-SEC-2026-3385)

A vulnerability identified as critical has been detected in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Akeyless Provider. Performing a manipulation results in improper privilege management. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-86462 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-86462 | Apache Airflow FAB provider session fixiation (WID-SEC-2026-3385)

A vulnerability was found in Apache Airflow. It has been classified as critical. This issue affects some unknown processing of the component FAB provider. Performing a manipulation results in session fixiation. This vulnerability is identif

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-86466 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-86466 | Apache Airflow FAB Authentik provider data authenticity (WID-SEC-2026-3385)

A vulnerability classified as critical was found in Apache Airflow. Affected by this issue is some unknown functionality of the component FAB Authentik provider. Executing a manipulation can lead to insufficient verification of data authent

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 19.6%
CVE-2026-82311 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-82311 | Apache Airflow FAB Provider _user_id type confusion (WID-SEC-2026-3385)

A vulnerability categorized as critical has been discovered in Apache Airflow FAB Provider. Affected is an unknown function of the component FAB Provider. Such manipulation of the argument _user_id leads to type confusion. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 24.2%
CVE-2026-82310 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-82310 | Apache Airflow FAB Auth Manager improper authentication (WID-SEC-2026-3385)

A vulnerability was found in Apache Airflow. It has been rated as critical. This impacts an unknown function of the component FAB Auth Manager. This manipulation causes improper authentication. This vulnerability is tracked as CVE-2026-8231

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 22.1%
CVE-2026-86792 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-86792 | Apache Airflow Connection Editor code injection (WID-SEC-2026-3385)

A vulnerability classified as critical has been found in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Connection Editor. Performing a manipulation results in code injection. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-76187 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-76187 | Apache Airflow Keycloak Provider improper authentication (WID-SEC-2026-3385)

A vulnerability has been found in Apache Airflow and classified as critical. This affects an unknown part of the component Keycloak Provider. This manipulation causes improper authentication. The identification of this vulnerability is CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-82720 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82720 | NLnet Labs Unbound up to 1.26.0 use after free (WID-SEC-2026-3392)

A vulnerability, which was classified as critical, was found in NLnet Labs Unbound up to 1.26.0. Affected by this issue is some unknown functionality. The manipulation results in use after free. This vulnerability is reported as CVE-2026-82

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23%
CVE-2026-76186 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-76186 | Apache Airflow Keycloak Provider session fixiation (WID-SEC-2026-3385)

A vulnerability was found in Apache Airflow. It has been declared as critical. Impacted is an unknown function of the component Keycloak Provider. Executing a manipulation can lead to session fixiation. This vulnerability is tracked as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 27%
CVE-2026-85501 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85501 | NLnet Labs Unbound up to 1.26.0 DNSSEC Validation resource consumption (WID-SEC-2026-3392)

A vulnerability described as critical has been identified in NLnet Labs Unbound up to 1.26.0. This affects an unknown function of the component DNSSEC Validation. Such manipulation leads to resource consumption. This vulnerability is listed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-81642 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81642 | NLnet Labs Unbound up to 1.26.0 DNSSEC Validator buffer overflow (WID-SEC-2026-3392)

A vulnerability classified as very critical has been found in NLnet Labs Unbound up to 1.26.0. This impacts an unknown function of the component DNSSEC Validator. Performing a manipulation results in buffer overflow. This vulnerability is c

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-82717 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82717 | NLnet Labs Unbound up to 1.26.0 heap-based overflow (WID-SEC-2026-3392)

A vulnerability marked as very critical has been reported in NLnet Labs Unbound up to 1.26.0. The impacted element is an unknown function. This manipulation causes heap-based buffer overflow. This vulnerability is tracked as CVE-2026-82717.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-81634 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81634 | NLnet Labs Unbound up to 1.26.0 RRSet Canonicalisation heap-based overflow (WID-SEC-2026-3392)

A vulnerability, which was classified as critical, has been found in NLnet Labs Unbound up to 1.26.0. Affected by this vulnerability is an unknown functionality of the component RRSet Canonicalisation. The manipulation leads to heap-based b

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-80225 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80225 | NLnet Labs Unbound up to 1.26.0 TCP/DoT Reading Procedure resource consumption (WID-SEC-2026-3392)

A vulnerability classified as critical was found in NLnet Labs Unbound up to 1.26.0. Affected is an unknown function of the component TCP/DoT Reading Procedure. Executing a manipulation can lead to resource consumption. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2023-23931 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8776-1: python-cryptography vulnerabilities

It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.2%
CVE-2026-76104 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-76104 | Dell ObjectScale 3.8.1.7/4.1.0.3/4.2.0.0/4.3.0.1 permission (EUVD-2026-80834)

A vulnerability categorized as problematic has been discovered in Dell ObjectScale 3.8.1.7/4.1.0.3/4.2.0.0/4.3.0.1. The affected element is an unknown function. Executing a manipulation can lead to permission issues. The identification of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-18212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18212 | Keycloak Saml Redirect Helper state issue (EUVD-2026-80828)

A vulnerability was found in Keycloak and classified as problematic. Affected by this issue is some unknown functionality of the component Saml Redirect Helper. Executing a manipulation can lead to state issue. The identification of this vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-77411 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77411 | RabbitMQ amqp091-go up to 1.12.x AMQP Parser read.go readLongstr input validation (EUVD-2026-80821)

A vulnerability classified as problematic has been found in RabbitMQ amqp091-go up to 1.12.x. This affects the function readLongstr of the file read.go of the component AMQP Parser. This manipulation causes improper input validation. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22%
CVE-2026-77406 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77406 | RabbitMQ amqp091-go up to 1.12.x QoS channel.go Channel.Qos prefetchCount/prefetchSize integer overflow (EUVD-2026-80808)

A vulnerability identified as problematic has been detected in RabbitMQ amqp091-go up to 1.12.x. Affected by this issue is the function Channel.Qos of the file channel.go of the component QoS. This manipulation of the argument prefetchCount

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18%
CVE-2026-92139 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92139 | Jenkins Project Bitbucket Push and Pull Request Plugin up to 4.0.1 Webhook input validation (EUVD-2026-80763)

A vulnerability classified as problematic was found in Jenkins Project Bitbucket Push and Pull Request Plugin up to 4.0.1. Affected by this vulnerability is an unknown functionality of the component Webhook Handler. Such manipulation leads

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-18690 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18690 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 improper authorization

A vulnerability, which was classified as critical, was found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. This vulnerability affects unknown code. The manipulation results in improper authorization. This vulnerability is identified as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-18688 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18688 | MongoDB up to 7.0.39/8.0.28/8.3.7 Aggregation Pipeline out-of-bounds

A vulnerability, which was classified as critical, has been found in MongoDB up to 7.0.39/8.0.28/8.3.7. This affects an unknown part of the component Aggregation Pipeline. The manipulation leads to out-of-bounds read. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.6%
CVE-2026-18687 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18687 | MongoDB Server up to 8.0.28/8.3.7 Queryable Encryption integer underflow

A vulnerability labeled as problematic has been found in MongoDB Server up to 8.0.28/8.3.7. Impacted is an unknown function of the component Queryable Encryption. Executing a manipulation can lead to integer underflow. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.