🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 256 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.617 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-05
≥90 %40
≥50 %40
≥10 %30
<10 %304222
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Microsoft 28
Generic Security 25
WordPress 4
Google 2
Apple 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 27.5%
CVE-2026-84774 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84774 | VeronaLabs WP Statistics Plugin up to 14.16.11 on WordPress cross site scripting (EUVD-2026-70575)

A vulnerability was found in VeronaLabs WP Statistics Plugin up to 14.16.11 on WordPress and classified as problematic. The affected element is an unknown function. The manipulation results in cross site scripting. This vulnerability is cat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 20.9%
CVE-2026-84812 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84812 | wordplus BP Better Messages Plugin up to 2.15.27 on WordPress cross site scripting (EUVD-2026-70570)

A vulnerability was found in wordplus BP Better Messages Plugin up to 2.15.27 on WordPress. It has been classified as problematic. The impacted element is an unknown function. This manipulation causes cross site scripting. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 27.3%
CVE-2026-84847 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-84847 | brightvesseldev Quick Event Manager Plugin up to 9.17 on WordPress access control (EUVD-2026-70567)

A vulnerability, which was classified as problematic, was found in brightvesseldev Quick Event Manager Plugin up to 9.17 on WordPress. This issue affects some unknown processing. Executing a manipulation can lead to improper access controls

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 32.3%
CVE-2026-79419 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79419 | EMX Tecnologia Gestao X Business Suite up to 8.4 Imagens.aspx mensagem cross site scripting (EUVD-2026-71456)

A vulnerability was found in EMX Tecnologia Gestao X Business Suite up to 8.4. It has been rated as problematic. Affected is an unknown function of the file /Configuracao/Imagens.aspx. This manipulation of the argument mensagem causes cross

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 21.2%
CVE-2026-85225 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85225 | code-projects Doctor Appointment System 1.0 /patient_login.php email sql injection (EUVD-2026-70820)

A vulnerability marked as critical has been reported in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. This

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-85207 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85207 | itsourcecode Online Medicine Delivery System 1.0 index.php?q=orderdetails location cross site scripting (EUVD-2026-70700)

A vulnerability, which was classified as problematic, was found in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-85434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85434 | MOOS-IvP up to 24.8.1 uFldShoreBroker redirect (EUVD-2026-70806)

A vulnerability categorized as problematic has been discovered in MOOS-IvP up to 24.8.1. Affected by this issue is some unknown functionality of the component uFldShoreBroker. Such manipulation leads to open redirect. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.3%
CVE-2026-85429 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85429 | MOOS-IvP up to 24.8.1 uFldNodeComms improper authentication (EUVD-2026-70811)

A vulnerability classified as problematic was found in MOOS-IvP up to 24.8.1. This issue affects some unknown processing of the component uFldNodeComms. The manipulation results in improper authentication. This vulnerability is reported as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85424 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85424 | themoos core-moos up to 10.4.0 improper authentication (EUVD-2026-70816)

A vulnerability classified as critical has been found in themoos core-moos up to 10.4.0. This vulnerability affects unknown code. The manipulation leads to improper authentication. This vulnerability is documented as CVE-2026-85424. The att

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-85439 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85439 | MOOS-IvP up to 24.8.1 SplitHandler handlePreCheckSplitDir dir os command injection (EUVD-2026-70801)

A vulnerability categorized as critical has been discovered in MOOS-IvP up to 24.8.1. This impacts the function SplitHandler::handlePreCheckSplitDir of the component SplitHandler. The manipulation of the argument dir results in os command i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.8%
CVE-2026-85444 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85444 | MOOS-IvP up to 24.8.1 isQuoted/isBraced/isChevroned buffer overflow (EUVD-2026-70778)

A vulnerability was found in MOOS-IvP up to 24.8.1. It has been rated as problematic. This vulnerability affects the function isQuoted/isBraced/isChevroned. Performing a manipulation results in buffer overflow. This vulnerability was named

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-14478 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14478 | Autodesk Installer up to 2.22 permission

A vulnerability was found in Autodesk Installer up to 2.22. It has been declared as critical. This issue affects some unknown processing. The manipulation results in permission issues. This vulnerability is reported as CVE-2026-14478. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.8%
CVE-2026-19481 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19481 | fastify busboy up to 3.2.0 Header Parser prototype pollution

A vulnerability, which was classified as critical, was found in fastify busboy up to 3.2.0. Affected by this vulnerability is an unknown functionality of the component Header Parser. Executing a manipulation can lead to improperly controlle

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23%
CVE-2026-0299 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-0299 | Palo Alto Networks GlobalProtect App privileges management (EUVD-2026-57713)

A vulnerability was found in Palo Alto Networks GlobalProtect App and classified as very critical. The impacted element is an unknown function. Such manipulation leads to improper privilege management. This vulnerability is referenced as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.4%
CVE-2026-65370 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65370 | Apple servicetalk up to 0.42.64 Transfer-Encoding request smuggling

A vulnerability classified as problematic has been found in Apple servicetalk up to 0.42.64. Affected by this issue is some unknown functionality of the component Transfer-Encoding. This manipulation causes http request smuggling. The ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2026-63293 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63293 | Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9 Image Import metadata.yaml symlink

A vulnerability was found in Canonical LXD up to 4.0.11/5.0.7/5.21.5/6.9. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file metadata.yaml of the component Image Import. Performing a manipu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-64639 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64639 | WebPros Plesk up to 18.0.79.5/18.0.80.1 Database Cloning privileges management

A vulnerability labeled as very critical has been found in WebPros Plesk up to 18.0.79.5/18.0.80.1. Affected by this vulnerability is an unknown functionality of the component Database Cloning. The manipulation results in improper privilege

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2025-41769 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-41769 | Phoenix Contact EPC 1522 up to 2026.0.2 PROFINET service buffer overflow

A vulnerability has been found in Phoenix Contact AXC F 1152, AXC F 1252, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNEXT CONTROL 1000, VPLCNEXT CONTROL 2000, VPLCNEXT CONTROL 3000, VPLCNEXT C

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-14479 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14479 | Autodesk Installer up to 2.22.x IPC frame parser resource consumption

A vulnerability was found in Autodesk Installer up to 2.22.x and classified as critical. This affects an unknown part of the component IPC frame parser. Executing a manipulation can lead to resource consumption. This vulnerability is regist

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 21.2%
CVE-2025-41771 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-41771 | Phoenix Contact EPC 1522 up to 2026.0.2 Web Interface sql injection

A vulnerability was found in Phoenix Contact AXC F 1152, AXC F 1252, AXC F 2000 EA, AXC F 2152, AXC F 3152, BPC 9102S, BPC 9202S, RFC 4072R, RFC 4072S, VL3 UPC 2440 EDGE, VPLCNEXT CONTROL 1000, VPLCNEXT CONTROL 2000, VPLCNEXT CONTROL 3000,

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.8%
CVE-2025-41770 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-41770 | Phoenix Contact PLCnext Engineer up to 2026.0.2 Communication Interface denial of service

A vulnerability was found in Phoenix Contact PLCnext Engineer up to 2026.0.2 and classified as problematic. The affected element is an unknown function of the component Communication Interface. Executing a manipulation can lead to denial of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.8%
CVE-2026-65675 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-65675 | Microsoft Visual Studio Code CoPilot Chat Extension up to 1.132.0 improper authorization (EUVD-2026-56437 / WID-SEC-2026-2761)

A vulnerability classified as critical has been found in Microsoft Visual Studio Code CoPilot Chat Extension up to 1.132.0. This vulnerability affects unknown code of the component CoPilot Chat. This manipulation causes improper authorizati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
5.8 MEDIUM
EPSS 3.3%
CVE-2026-16253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-16253 | Total Upkeep Plugin up to 1.17.2 on WordPress information disclosure (EUVD-2026-57087)

A vulnerability categorized as problematic has been discovered in Total Upkeep Plugin up to 1.17.2 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to information disclosure. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 29.7%
CVE-2026-69278 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69278 | Microsoft Visual Studio Code up to 1.132.0 improper authorization (WID-SEC-2026-2761)

A vulnerability has been found in Microsoft Visual Studio Code up to 1.132.0 and classified as problematic. The affected element is an unknown function. This manipulation causes improper authorization. This vulnerability is tracked as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 18.9%
CVE-2026-70336 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-70336 | Microsoft Visual Studio Code up to 1.132.0 code injection (WID-SEC-2026-2761)

A vulnerability described as critical has been identified in Microsoft Visual Studio Code up to 1.132.0. Affected by this issue is some unknown functionality. Such manipulation leads to code injection. This vulnerability is uniquely identif

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 21.3%
CVE-2026-69320 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69320 | Microsoft Visual Studio Code up to 1.132.0 os command injection (WID-SEC-2026-2761)

A vulnerability marked as critical has been reported in Microsoft Visual Studio Code up to 1.132.0. Affected by this vulnerability is an unknown functionality. This manipulation causes os command injection. This vulnerability is handled as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 28%
CVE-2026-69306 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69306 | Microsoft Visual Studio Code up to 1.132.0 improper authorization (WID-SEC-2026-2761)

A vulnerability labeled as critical has been found in Microsoft Visual Studio Code up to 1.132.0. Affected is an unknown function. The manipulation results in improper authorization. This vulnerability is known as CVE-2026-69306. It is poss

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 27.7%
CVE-2026-65789 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-65789 | Microsoft Windows up to Server 2025 DNS use after free

A vulnerability classified as very critical has been found in Microsoft Windows up to Server 2025. This issue affects some unknown processing of the component DNS. Performing a manipulation results in use after free. This vulnerability is i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 23.3%
CVE-2026-66098 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-66098 | Quanovate Tech Mira/Mira Android App BLE improper authentication

A vulnerability identified as critical has been detected in Quanovate Tech Mira and Mira Android App. Affected is an unknown function of the component BLE. Performing a manipulation results in improper authentication. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.1%
CVE-2026-71475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71475 | Red Hat Advanced Cluster Management for Kubernetes Insights API URL Path ClusterID redirect (EUVD-2026-56899)

A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been classified as problematic. This issue affects some unknown processing of the component Insights API URL Path. Performing a manipulation of the argu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.6%
CVE-2026-62893 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62893 | Microsoft Windows up to Server 2025 Deployment Services use after free

A vulnerability classified as very critical has been found in Microsoft Windows up to Server 2025. This vulnerability affects unknown code of the component Deployment Services. Performing a manipulation results in use after free. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 19%
CVE-2026-66875 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-66875 | Quanovate Tech Mira/Mira Android App 1.7.1.47 missing encryption

A vulnerability categorized as problematic has been discovered in Quanovate Tech Mira and Mira Android App 1.7.1.47. This impacts an unknown function. Such manipulation leads to missing encryption of sensitive data. This vulnerability is re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.9%
CVE-2026-71474 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71474 | Red Hat Advanced Cluster Management for Kubernetes Logging information disclosure (EUVD-2026-56902)

A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been rated as problematic. The affected element is an unknown function of the component Logging. The manipulation leads to information disclosure. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-62878 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62878 | Microsoft Windows up to Server 2025 DNS buffer overflow

A vulnerability was found in Microsoft Windows up to Server 2025. It has been rated as very critical. This affects an unknown part of the component DNS. The manipulation leads to buffer overflow. This vulnerability is uniquely identified as

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.1%
CVE-2026-62745 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62745 | Microsoft Windows up to Server 2025 DHCP Server integer underflow (EUVD-2026-56370)

A vulnerability, which was classified as problematic, was found in Microsoft Windows up to Server 2025. Impacted is an unknown function of the component DHCP Server. The manipulation results in integer underflow. This vulnerability is catal

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 30.9%
CVE-2026-62823 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62823 | Microsoft Windows up to Server 2025 buffer overflow

A vulnerability was found in Microsoft Windows up to Server 2025. It has been classified as very critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.9%
CVE-2026-62817 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62817 | Microsoft Windows up to Server 2025 DNS out-of-bounds write

A vulnerability, which was classified as very critical, was found in Microsoft Windows up to Server 2025. Impacted is an unknown function of the component DNS. Executing a manipulation can lead to out-of-bounds write. This vulnerability app

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 29.5%
CVE-2026-62820 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62820 | Microsoft Windows up to Server 2025 DNS race condition (EUVD-2026-56397)

A vulnerability classified as very critical was found in Microsoft Windows up to Server 2025. This vulnerability affects unknown code of the component DNS. Such manipulation leads to race condition. This vulnerability is documented as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 25.4%
CVE-2026-62812 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62812 | Microsoft Windows up to Server 2025 DHCP Server improper authorization

A vulnerability has been found in Microsoft Windows up to Server 2025 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component DHCP Server. This manipulation causes improper authorization.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 20.7%
CVE-2026-62803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62803 | Microsoft Windows up to Server 2025 DHCP Server improper authorization

A vulnerability classified as very critical was found in Microsoft Windows up to Server 2025. This affects an unknown function of the component DHCP Server. Executing a manipulation can lead to improper authorization. This vulnerability app

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 19.8%
CVE-2026-62807 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62807 | Microsoft Windows up to Server 2025 DHCP Server privileges management

A vulnerability, which was classified as very critical, has been found in Microsoft Windows up to Server 2025. This impacts an unknown function of the component DHCP Server. The manipulation leads to improper privilege management. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 20.7%
CVE-2026-62814 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62814 | Microsoft Windows up to Server 2025 DHCP Server integer underflow

A vulnerability classified as problematic was found in Microsoft Windows up to Server 2025. Impacted is an unknown function of the component DHCP Server. Such manipulation leads to integer underflow. This vulnerability is traded as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 21.1%
CVE-2026-62787 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62787 | Microsoft Windows up to Server 2025 DNS use after free

A vulnerability, which was classified as very critical, was found in Microsoft Windows up to Server 2025. The impacted element is an unknown function of the component DNS. Executing a manipulation can lead to use after free. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 19.6%
CVE-2026-62761 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62761 | Microsoft Windows up to Server 2025 DHCP Server privileges management

A vulnerability described as very critical has been identified in Microsoft Windows up to Server 2025. Affected is an unknown function of the component DHCP Server. Such manipulation leads to improper privilege management. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.6%
CVE-2026-62776 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62776 | Microsoft Windows up to Server 2025 DHCP Server privileges management

A vulnerability was found in Microsoft Windows up to Server 2025. It has been rated as very critical. This vulnerability affects unknown code of the component DHCP Server. Performing a manipulation results in improper privilege management.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 20.4%
CVE-2026-62716 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62716 | Microsoft Windows up to Server 2025 DHCP Server integer underflow

A vulnerability identified as problematic has been detected in Microsoft Windows up to Server 2025. This affects an unknown part of the component DHCP Server. The manipulation leads to integer underflow. This vulnerability is listed as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.2%
CVE-2026-62742 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62742 | Microsoft Windows up to Server 2025 DHCP Server integer underflow (EUVD-2026-56369)

A vulnerability, which was classified as critical, has been found in Microsoft Windows up to Server 2025. This issue affects some unknown processing of the component DHCP Server. The manipulation leads to integer underflow. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 23.8%
CVE-2026-62720 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62720 | Microsoft Windows up to Server 2025 DHCP Server integer underflow

A vulnerability labeled as problematic has been found in Microsoft Windows up to Server 2025. Affected by this issue is some unknown functionality of the component DHCP Server. The manipulation results in integer underflow. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 22.7%
CVE-2026-62718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62718 | Microsoft Windows up to Server 2025 DHCP Server integer underflow

A vulnerability identified as critical has been detected in Microsoft Windows up to Server 2025. Affected by this vulnerability is an unknown functionality of the component DHCP Server. The manipulation leads to integer underflow. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
8.2 HIGH
EPSS 18.8%
CVE-2026-72775 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72775 | n8n-io n8n prior 1.123.67/2.31.5/2.32.1 PostgresTrigger node channel/function/trigger sql injection

A vulnerability was found in n8n-io n8n. It has been declared as critical. This issue affects some unknown processing of the component PostgresTrigger node. The manipulation of the argument channel/function/trigger results in sql injection.

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-62715 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62715 | Microsoft Windows up to Server 2025 DHCP Server integer underflow

A vulnerability categorized as problematic has been discovered in Microsoft Windows up to Server 2025. Affected by this issue is some unknown functionality of the component DHCP Server. Executing a manipulation can lead to integer underflow

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 25.7%
CVE-2026-58641 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-58641 | Microsoft .NET 8.0/9.0/10.0 integer overflow (WID-SEC-2026-2761)

A vulnerability has been found in Microsoft .NET 8.0/9.0/10.0 and classified as problematic. This issue affects some unknown processing. Performing a manipulation results in integer overflow. This vulnerability was named CVE-2026-58641. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 29.6%
CVE-2026-62714 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-62714 | Microsoft Windows up to Server 2025 DHCP Server integer underflow

A vulnerability was found in Microsoft Windows up to Server 2025. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component DHCP Server. Performing a manipulation results in integer underf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 31.4%
CVE-2026-61920 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-61920 | Microsoft Windows up to Server 2025 race condition

A vulnerability categorized as very critical has been discovered in Microsoft Windows up to Server 2025. This vulnerability affects unknown code. Executing a manipulation can lead to race condition. This vulnerability is registered as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 30.6%
CVE-2026-59113 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-59113 | Microsoft Visual Studio Code up to 1.132.0 improper authorization (WID-SEC-2026-2761)

A vulnerability marked as critical has been reported in Microsoft Visual Studio Code up to 1.132.0. The affected element is an unknown function. This manipulation causes improper authorization. This vulnerability appears as CVE-2026-59113.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.8%
CVE-2026-18247 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18247 | BlackBerry AtHoc IWS up to 7.21 HF-733 Web Portals cross site scripting

A vulnerability marked as problematic has been reported in BlackBerry AtHoc IWS up to 7.21 HF-733. This affects an unknown part of the component Web Portals. Performing a manipulation results in cross site scripting. This vulnerability was

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.8%
CVE-2026-67397 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67397 | WebPros Plesk up to 18.0.79.9/18.0.80.5 path traversal (EUVD-2026-70851 / CNNVD-2026-78040743)

A vulnerability identified as very critical has been detected in WebPros Plesk up to 18.0.79.9/18.0.80.5. This affects an unknown function. This manipulation causes path traversal. The identification of this vulnerability is CVE-2026-67397.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.2%
CVE-2026-85149 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85149 | Lightstar SmartIT Desktop Manager up to 10 SFTP Service hard-coded credentials (CNNVD-2026-73395286)

A vulnerability, which was classified as problematic, was found in Lightstar SmartIT Desktop Manager up to 10. This issue affects some unknown processing of the component SFTP Service. Such manipulation leads to hard-coded credentials. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.8%
CVE-2026-45200 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45200 | Imagination Graphics DDK up to 26.1 RTM1 Allocation Interface double free (EUVD-2026-70857 / CNNVD-2026-83951171)

A vulnerability described as critical has been identified in Imagination Graphics DDK up to 1.18 RTM1/23.2 RTM1/24.2 RTM2/25.3 RTM/26.1 RTM1. Affected by this vulnerability is an unknown functionality of the component Allocation Interface.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 21.5%
CVE-2026-85379 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85379 | light0011 cms Query Builder ChapterController.class.php searchChapter content sql injection (CNNVD-2026-84667025)

A vulnerability categorized as critical has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterModel::searchChapter of the file App/Home/Contr

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.