🎯 CVE-2026-28607 HIGH 7.8 🔥 EPSS 19.4%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-28607: Schwachstellen-Eintrag (NVD)

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Klassifikation & Betroffenheit:
google android 15.0google android 16.0google android 17.0
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-28607 | Google Android 15/16/16-qpr2/17 privileges management
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.8
AV · Angriffsvektor Lokal
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:08.09.2026
Aktualisiert:15.09.2026 14:28
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
7 🔴 Critical im Radar
6 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
8 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 145 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.506 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-15
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
9.8 CRITICAL
⚠️ KEV
EPSS 96.5%
CVE-2026-15315 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

TP-Link Tapo C200 smart cameras were affected by two zero-day vulnerabilities that could allow attackers on the same network to bypass authentication or disrupt camera services. The flaws, tracked as CVE-2026-15315 and CVE-2026-15316, were

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 62.4%
CVE-2026-89026 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Issabel PBX JWT Key Flaw Enables Unauthenticated Remote Code Execution

A critical vulnerability in the Issabel Framework could allow unauthenticated remote attackers to execute arbitrary operating-system commands on affected Issabel PBX deployments by exploiting a hard-coded JSON Web Token signing key. Tracked

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2025-54073 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Known MCP Vulnerabilities and How an MCP Gateway Blocks Them

TL;DR The Model Context Protocol introduces security vectors including tool poisoning, STDIO command injection, tool shadowing, and credential exfiltration. Multiple high-severity vulnerabilities (such as CVE-2025-54073 and CVE-2026-33032)

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.4%
CVE-2026-89026 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild

A critical vulnerability in the Issabel Framework, which supports Issabel PBX deployments, is being actively exploited in the wild. The flaw, tracked as CVE-2026-89026, allows unauthenticated remote attackers to execute OS commands on vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 88.7%
CVE-2026-58704 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

Pixel Modem Zero-Day Exploited in Targeted Attacks

Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek. Weiterlesen

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-15315 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password

Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 25.8%
CVE-2026-73178 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

Apache Syncope Flaws Enable SQL Injection, JWT Token Takeover and Code Injection

Apache Syncope has disclosed three important vulnerabilities that could allow privileged administrators to execute arbitrary SQL commands, bypass Groovy sandbox protections to inject code, and hijack higher-privileged user sessions through

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-90894 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is hi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2026-58704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google schließt Pixel-Modem-Lücke CVE-2026-58704 nach ersten Ausnutzungszeichen

LONDON (IT BOLTWISE) – Google hat eine hochkritische Sicherheitslücke im Pixel Cellular Modem als ausnutzbar in freier Wildbahn eingestuft. Die Schwachstelle CVE-2026-58704 mit einem CVSS-Score von 8,0 ermöglicht eine Rechteausweitung über

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.3%
CVE-2026-87886 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Acronis warnt: cPanel-Backup-Plugin-Lücke (CVE-2026-87886) wird aktiv ausgenutzt

LONDON (IT BOLTWISE) – Acronis meldet eine hochkritische Schwachstelle im Backup-Plugin für cPanel und WHM, die bereits in gezielten Angriffen ausgenutzt wird. Betroffen sind Linux-Installationen vor bestimmten Build-Versionen, während Fixe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 84.8%
CVE-2026-76461 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution

Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems. This article has been indexed from eSecurity Planet Read the original article: Cisco

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] Ghostscript: Schwachstelle ermöglicht Codeausführung und Manipulation von Daten

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ghostscript ausnutzen, um beliebigen Programmcode auszuführen, und um Daten zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GIMP ausnutzen, um beliebigen Programmcode auszuführen und um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 88.7%
CVE-2026-58704 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. &quot;In Cellular M

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 94.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a c

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [niedrig] binutils: Schwachstelle ermöglicht Denial of Service

Ein lokaler Angreifer kann eine Schwachstelle in binutils ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] Netgate pfSense: Schwachstelle ermöglicht Codeausführung

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Netgate pfSense ausnutzen, um Sicherheitsmaßnahmen zu umgehen und beliebigen PHP-Code und Shell-Befehle auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] BigBlueButton: Schwachstelle ermöglicht Denial of Service

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in BigBlueButton ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] MikroTik RouterOS: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MikroTik RouterOS ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [hoch] BusyBox: Schwachstelle ermöglicht Codeausführung

Ein entfernter Angreifer kann eine Schwachstelle in BusyBox ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Camunda: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Camunda ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] Podman: Schwachstelle ermöglicht Manipulation von Dateien

Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in Podman ausnutzen, um Dateien zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] NGINX: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NGINX ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Octopus Deploy: Schwachstelle ermöglicht Manipulation von Dateien und potenziell Codeausführung

Ein Angreifer kann eine Schwachstelle in Octopus Deploy ausnutzen, um Dateien zu manipulieren und potenziell um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-1168 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-1168 | GitLab up to 19.1.7/19.2.5/19.3.1 GraphQL Complexity Calculation allocation of resources (WID-SEC-2026-3315)

A vulnerability has been found in GitLab up to 19.1.7/19.2.5/19.3.1 and classified as problematic. The affected element is an unknown function of the component GraphQL Complexity Calculation. This manipulation causes allocation of resources

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.1%
CVE-2026-13210 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13210 | GitLab up to 19.1.7/19.2.5/19.3.1 Environment Scope Pattern Matcher input validation (WID-SEC-2026-3315)

A vulnerability classified as problematic has been found in GitLab up to 19.1.7/19.2.5/19.3.1. This affects an unknown part of the component Environment Scope Pattern Matcher. The manipulation leads to improper input validation. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.9%
CVE-2026-12910 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12910 | GitLab prior 19.1.8/19.2.6/19.3.2 SAML SSO missing authentication (WID-SEC-2026-3315)

A vulnerability categorized as critical has been discovered in GitLab. This affects an unknown function of the component SAML SSO. The manipulation results in missing authentication. This vulnerability is reported as CVE-2026-12910. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.4%
CVE-2024-11222 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-11222 | GitLab up to 19.1.7/19.2.5/19.3.1 Pipeline Creation race condition (WID-SEC-2026-3315)

A vulnerability was found in GitLab up to 19.1.7/19.2.5/19.3.1. It has been classified as critical. This affects an unknown function of the component Pipeline Creation. Performing a manipulation results in race condition. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2025-14871 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-14871 | GitLab up to 19.1.7/19.2.5/19.3.1 GraphQL allocation of resources (WID-SEC-2026-3315)

A vulnerability, which was classified as critical, was found in GitLab up to 19.1.7/19.2.5/19.3.1. Impacted is an unknown function of the component GraphQL. The manipulation results in allocation of resources. This vulnerability was named C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.8%
CVE-2026-19248 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19248 | Qt QDomDocument denial of service (WID-SEC-2026-3332)

A vulnerability classified as problematic was found in Qt. The affected element is an unknown function of the component QDomDocument. The manipulation results in denial of service. This vulnerability is known as CVE-2026-19248. It is possib

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.3%
CVE-2026-89787 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89787 | Linux Kernel up to 7.2.5 ext4 fs/ext4/namei.c ext4_match name_len use after free (EUVD-2026-80308)

A vulnerability was found in Linux Kernel up to 7.2.5. It has been classified as very critical. This impacts the function ext4_match of the file fs/ext4/namei.c of the component ext4. The manipulation of the argument name_len leads to use a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24%
CVE-2026-89789 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89789 | Linux Kernel up to 7.2.5 gtp gtp.c gtp_newlink use after free (EUVD-2026-80310)

A vulnerability classified as very critical was found in Linux Kernel up to 7.2.5. The impacted element is the function gtp_newlink of the file gtp.c of the component gtp. Such manipulation leads to use after free. This vulnerability is doc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.4%
CVE-2026-89788 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89788 | Linux Kernel up to 7.2.5/7.3-rc1 ksmbd fs/smb/server/smb2pdu.c smb2_tree_connect use after free (EUVD-2026-80309)

A vulnerability was found in Linux Kernel up to 7.2.5/7.3-rc1 and classified as very critical. This affects the function smb2_tree_connect of the file fs/smb/server/smb2pdu.c of the component ksmbd. Executing a manipulation can lead to use

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.7%
CVE-2026-89791 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89791 | Linux Kernel up to 6.18.51/7.2.4/7.3-rc1 perf perf_mmap_close use after free (EUVD-2026-80312)

A vulnerability was found in Linux Kernel up to 6.18.51/7.2.4/7.3-rc1 and classified as very critical. Affected by this vulnerability is the function perf_mmap_close of the component perf. The manipulation results in use after free. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.5%
CVE-2026-89792 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89792 | Linux Kernel up to 7.2.5/7.3-rc1 ksmbd out-of-bounds (EUVD-2026-80314)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.2.5/7.3-rc1. This impacts an unknown function of the component ksmbd. Executing a manipulation can lead to out-of-bounds read. This vulnerability appears a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.3%
CVE-2026-89790 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89790 | Linux Kernel up to 6.18.51/7.2.5 IPv6 net/ipv6/route.c rt6_upper_bound_set divide by zero (EUVD-2026-80311)

A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.18.51/7.2.5. This affects the function rt6_upper_bound_set of the file net/ipv6/route.c of the component IPv6. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.2%
CVE-2026-18140 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18140 | AWS aws-smithy-json up to 0.62.6 Unknown-Key Skip Path recursion (Nessus ID 346043)

A vulnerability was found in AWS aws-smithy-json up to 0.62.6. It has been declared as problematic. The impacted element is an unknown function of the component Unknown-Key Skip Path. Such manipulation leads to uncontrolled recursion. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-53939 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53939 | OpenIDC cjose up to 0.6.1/0.6.2.5 _cjose_jwe_set_cek_aes_cbc random values (Nessus ID 346044)

A vulnerability labeled as problematic has been found in OpenIDC cjose up to 0.6.1/0.6.2.5. Affected by this vulnerability is the function _cjose_jwe_set_cek_aes_cbc. Such manipulation leads to insufficiently random values. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.2%
CVE-2026-53938 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53938 | OpenIDC cjose 0.6.2.2 JWE Decryption cjose_jwe_import/cjose_jwe_decrypt encrypted_key heap-based overflow (Nessus ID 346044)

A vulnerability identified as critical has been detected in OpenIDC cjose 0.6.2.2. Affected is the function cjose_jwe_import/cjose_jwe_decrypt of the component JWE Decryption. This manipulation of the argument encrypted_key causes heap-base

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18%
CVE-2026-28627 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28627 | Google Android 16-qpr2/17 btm_sec.cc btm_sec_encrypt_change downgrade

A vulnerability labeled as problematic has been found in Google Android 16-qpr2/17. The impacted element is the function btm_sec_encrypt_change of the file btm_sec.cc. The manipulation results in algorithm downgrade. This vulnerability is r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-28642 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28642 | Google Android 14/15/16/16-qpr2 ActivityStarter ActivityStarter.java executeRequest privileges management

A vulnerability categorized as very critical has been discovered in Google Android 14/15/16/16-qpr2. This affects the function executeRequest of the file ActivityStarter.java of the component ActivityStarter. The manipulation results in imp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.2%
CVE-2026-28639 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28639 | Google Android up to 17 rw_mfc.cc rw_mfc_handle_read_op out-of-bounds write

A vulnerability was found in Google Android 14/15/16/16-qpr2/17. It has been rated as very critical. The impacted element is the function rw_mfc_handle_read_op of the file rw_mfc.cc. The manipulation leads to out-of-bounds write. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2026-28634 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28634 | Google Android up to 17 PhoneInterfaceManager PhoneInterfaceManager.java handleUssdRequest privileges management

A vulnerability was found in Google Android 14/15/16/16-qpr2/17. It has been declared as problematic. The affected element is the function handleUssdRequest of the file PhoneInterfaceManager.java of the component PhoneInterfaceManager. Exec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.9%
CVE-2026-28636 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28636 | Google Android 14/15/16/16-qpr2 PickActivity.java setupLayout privileges management

A vulnerability was found in Google Android 14/15/16/16-qpr2. It has been classified as very critical. Impacted is the function setupLayout of the file PickActivity.java. Performing a manipulation results in improper privilege management. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-28624 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28624 | Google Android 16/16-qpr2/17 privileges management

A vulnerability has been found in Google Android 16/16-qpr2/17 and classified as very critical. This vulnerability affects unknown code. This manipulation causes improper privilege management. The identification of this vulnerability is CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-28626 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28626 | Google Android up to 17 Intent Redirection SetupPassthroughActivity.java onCreate redirect

A vulnerability, which was classified as problematic, was found in Google Android 14/15/16/16-qpr2/17. This affects the function onCreate of the file SetupPassthroughActivity.java of the component Intent Redirection. The manipulation result

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.6%
CVE-2026-28638 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28638 | Google Android up to 17 XmpDataParser XmpDataParser.java information disclosure

A vulnerability, which was classified as problematic, has been found in Google Android 14/15/16/16-qpr2/17. Affected by this issue is some unknown functionality of the file XmpDataParser.java of the component XmpDataParser. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.8%
CVE-2026-28630 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28630 | Google Android 17 ContactsPickerActivity ContactsPickerActivity.kt onCreate information disclosure

A vulnerability classified as problematic has been found in Google Android 17. Affected is the function onCreate of the file ContactsPickerActivity.kt of the component ContactsPickerActivity. Performing a manipulation results in information

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.9%
CVE-2026-28622 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28622 | Google Android 17 MediaProvider MediaProvider.java getQueryBuilderInternal permission

A vulnerability described as problematic has been identified in Google Android 17. This impacts the function getQueryBuilderInternal of the file MediaProvider.java of the component MediaProvider. Such manipulation leads to permission issues

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-28623 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28623 | Google Android 16/16-qPR2/17 Bluetooth BleRssiRangingCapabilities.java writeToParcel permission

A vulnerability marked as problematic has been reported in Google Android 16/16-qPR2/17. This affects the function writeToParcel of the file BleRssiRangingCapabilities.java of the component Bluetooth. This manipulation causes permission iss

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 22.1%
CVE-2026-75757 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 ash-project

CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 6.7%
CVE-2026-82604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-82603 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 n/a

CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
🇪🇺 EUVD
EPSS 4.8%
CVE-2026-82602 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.8%
CVE-2026-82601 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 23.5%
CVE-2026-75760 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82580 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.0 MEDIUM
🇪🇺 EUVD
EPSS 5.2%
CVE-2026-82579 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul

Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 20.8%
CVE-2026-82564 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression

Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.