🎯 CVE-2026-55416 HIGH 8.8 🔥 EPSS 25.8%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-55416: Schwachstellen-Eintrag (NVD)

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these values into a database query, while a blacklist omits dangerous constructs such as additional data-manipulation statements, comments, subqueries, and multiple statements. The getData() method also previously interpolated offset and limit values into a LIMIT clause without integer casting. Executing the configured report reaches fetchAllAssociative() with the constructed query and can disclose, modify, or delete arbitrary database data. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 71b2af87d1a50027d7a59cb9f41da1ef807d892f (Commit) 🩹 ad60bad41946c33bebb4fd42e03b0a575759de02 (Commit)
📰 Eigene Berichterstattung: ➔ CVE-2026-55416 | Pimcore prior 11.5.19/12.3.10/2026.1.6 CustomReportsBundle Sql.
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:14.09.2026
Aktualisiert:14.09.2026 20:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
5 🔴 Critical im Radar
4 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
6 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 145 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.506 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-15
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

September-Updates schließen 180 Sicherheitslücken in Android – Pixel Update stopft 0-Day-Lücke

Mit dem Android Security Bulletin für September 2026 dokumentiert Google die Schwachstellen des Mobilbetriebssystems, die dessen Entwickler in den offenliegenden Quelltexten beseitigt haben. Üblicherweise geschieht dies am ersten Montag des

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+

Cisco zero-day goes straight to root BambooToken branches into Linux CenterPoint breach claim hits 7M+ Get the show notes here: https://cisoseries.com/cybersecurity-news-september-16-2026/ Huge thanks to our episode sponsor, Vanta Risk and

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.5 CRITICAL
EPSS 76.5%
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-42167: ProFTPD mod_sql RCE and How to Analyze the Exploit-DB PoC

A public exploit for CVE-2026-42167, a ProFTPD mod_sql vulnerability, is now available on Exploit-DB. The vulnerability has a CVSS v3.1 score of 8.1, and Exploit-DB published EDB-ID 52658 on August 25, 2026. But the interesting part isn&#03

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.4%
CVE-2026-28596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28596 | Google Android 14/15/16/16-qpr2 GameManagerService.java parseInterventionFromXml resource consumption

A vulnerability was found in Google Android 14/15/16/16-qpr2. It has been classified as problematic. The impacted element is the function parseInterventionFromXml of the file GameManagerService.java. Performing a manipulation results in res

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-28600 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28600 | Google Android 15/16/16-qpr2/17 PaymentDefaultDialog.java onCreate privileges management

A vulnerability was found in Google Android 15/16/16-qpr2/17 and classified as very critical. This impacts the function onCreate of the file PaymentDefaultDialog.java. Executing a manipulation can lead to improper privilege management. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2026-28602 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28602 | Google Android up to 17 ClipboardService ClipboardService.java setClipboardAccessNotificationsEnabledForUser isolation

A vulnerability classified as problematic was found in Google Android 14/15/16/16-qpr2/17. Impacted is the function setClipboardAccessNotificationsEnabledForUser of the file ClipboardService.java of the component ClipboardService. The manip

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-28599 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28599 | Google Android 16/16-qpr2/17 ActivityManagerService ActivityManagerService.java addCreatorToken privileges management

A vulnerability classified as problematic has been found in Google Android 16/16-qpr2/17. This issue affects the function addCreatorToken of the file ActivityManagerService.java of the component ActivityManagerService. The manipulation lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2026-28594 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28594 | Google Android 16-qpr2/17 use after free

A vulnerability described as very critical has been identified in Google Android 16-qpr2/17. This vulnerability affects unknown code. Executing a manipulation can lead to use after free. This vulnerability is handled as CVE-2026-28594. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2026-28590 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28590 | Google Android 14/15/16/16-qpr2 privileges management

A vulnerability marked as very critical has been reported in Google Android 14/15/16/16-qpr2. This affects an unknown part. Performing a manipulation results in improper privilege management. This vulnerability is known as CVE-2026-28590. R

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-28593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28593 | Google Android up to 17 Settings SettingsFragment.java getItemList privileges management

A vulnerability labeled as very critical has been found in Google Android 14/15/16/16-qpr2/17. Affected by this issue is the function getItemList of the file SettingsFragment.java of the component Settings. Such manipulation leads to improp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2026-28584 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28584 | Google Android 16-qpr2/17 Package Installer PackageInstallerService.java createSessionInternal behavioral workflow

A vulnerability identified as critical has been detected in Google Android 16-qpr2/17. Affected by this vulnerability is the function createSessionInternal of the file PackageInstallerService.java of the component Package Installer. This ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-28583 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28583 | Google Android 14/15/16/16-qpr2 Camera Metadata Validation camera_metadata.c validate_camera_metadata_structure out-of-bounds write

A vulnerability categorized as problematic has been discovered in Google Android 14/15/16/16-qpr2. Affected is the function validate_camera_metadata_structure of the file camera_metadata.c of the component Camera Metadata Validation. The ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-28582 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28582 | Google Android up to 17 Permission Check ConfirmDeviceCredentialActivity.java onCreate permission

A vulnerability was found in Google Android 14/15/16/16-qpr2/17 and classified as problematic. The affected element is the function onCreate of the file ConfirmDeviceCredentialActivity.java of the component Permission Check. Such manipulati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.7%
CVE-2026-71269 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71269 | Node-RED Storage library.js getLibraryEntry/saveLibraryEntry path path traversal

This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google fixes actively exploited Android zero-day on Pixel devices

Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...] Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-27540 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

WooCommerce-Plugin CVE-2026-27540: Angreifer platzieren PHP-Webshells

LONDON (IT BOLTWISE) – Angreifer nutzen eine kritische Schwachstelle im WooCommerce-Plugin „Wholesale Lead Capture“, um ohne Login beliebige Dateien hochzuladen. Dabei können sie PHP-Webshells einschleusen und so auf dem Server der betroffe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
8.2 HIGH
EPSS 24.4%
CVE-2022-44139 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44139 | oretnom23 Apartment Visitor Management System 1.0 /avms/index.php sql injection (EUVD-2022-47089)

A vulnerability was found in oretnom23 Apartment Visitor Management System 1.0. It has been rated as critical. Impacted is an unknown function of the file /avms/index.php. Performing a manipulation results in sql injection. This vulnerabili

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 22.9%
CVE-2022-44137 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44137 | SourceCodester Sanitization Management System 1.0 sql injection (EUVD-2022-47087)

A vulnerability was found in SourceCodester Sanitization Management System 1.0. It has been rated as critical. Impacted is an unknown function. Performing a manipulation results in sql injection. This vulnerability is known as CVE-2022-4413

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 27.7%
CVE-2022-44120 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44120 | dedecmdv6 6.1.9 sys_sql_query.php sql injection (EUVD-2022-47071)

A vulnerability classified as critical has been found in dedecmdv6 6.1.9. The affected element is an unknown function of the file sys_sql_query.php. This manipulation causes sql injection. This vulnerability is tracked as CVE-2022-44120. Th

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-5430 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

WSO2 API Manager: JWT-Bypass über falsche Admin-Token (CVE-2026-5430)

LONDON (IT BOLTWISE) – Eine Sicherheitslücke in WSO2 API Manager und verwandten Komponenten wird laut aktuellen Beobachtungen bereits aktiv in der Praxis ausgenutzt. Die Ursache liegt in einer unzureichenden Prüfung kryptografischer Signatu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29.2%
CVE-2022-44118 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44118 | dedecmdv6 6.1.9 file_manage_control.php privilege escalation (EUVD-2022-47069)

A vulnerability labeled as critical has been found in dedecmdv6 6.1.9. This vulnerability affects unknown code of the file file_manage_control.php. Executing a manipulation can lead to privilege escalation. The identification of this vulner

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2022-44109 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44109 | pdftojson 94204bb Stream::makeFilter stack-based overflow (EUVD-2022-47060)

A vulnerability was found in pdftojson 94204bb. It has been declared as critical. Affected by this vulnerability is the function Stream::makeFilter. The manipulation results in stack-based buffer overflow. This vulnerability was named CVE-2

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2022-44108 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44108 | pdftojson 94204bb Object.cc Object::copy(Object*) stack-based overflow (EUVD-2022-47059)

A vulnerability was found in pdftojson 94204bb. It has been classified as critical. Affected is the function Object::copy(Object*) of the file Object.cc. The manipulation leads to stack-based buffer overflow. This vulnerability is uniquely

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.8%
CVE-2022-44097 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44097 | Book Store Management System 1.0 Admin Panel hard-coded credentials (EUVD-2022-47048)

A vulnerability has been found in Book Store Management System 1.0 and classified as critical. This issue affects some unknown processing of the component Admin Panel. Performing a manipulation results in hard-coded credentials. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2022-44096 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44096 | Sanitization Management System 1.0 Admin Panel hard-coded credentials (EUVD-2022-47047)

A vulnerability, which was classified as critical, was found in Sanitization Management System 1.0. This vulnerability affects unknown code of the component Admin Panel. Such manipulation leads to hard-coded credentials. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2022-44081 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44081 | Lodepng 20220717 pngdetail memory corruption (Issue 177 / EUVD-2022-47032)

A vulnerability classified as critical has been found in Lodepng 20220717. This affects the function pngdetail. The manipulation leads to memory corruption. This vulnerability is documented as CVE-2022-44081. The attack requires being on th

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2022-44079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44079 | zrax pycdc 44a730f3a889503014fec94ae6e62d8401cb75e5 StackDepotNode stack-based overflow (Issue 291 / EUVD-2022-47030)

A vulnerability identified as critical has been detected in zrax pycdc 44a730f3a889503014fec94ae6e62d8401cb75e5. This issue affects the function __sanitizer::StackDepotBase&amp;lt;__sanitizer::StackDepotNode. This manipulation causes stack-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2022-44039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44039 | Franklin Fueling Colibri 1.9.22.8925 fopen access control (EUVD-2022-47001)

A vulnerability classified as critical was found in Franklin Fueling Colibri 1.9.22.8925. Affected by this vulnerability is the function fopen. The manipulation results in improper access controls. This vulnerability is known as CVE-2022-44

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 30.7%
CVE-2022-44038 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44038 | Russound XSourcePlayer 777D 06.08.03 scriptRunner.cgi privilege escalation (EUVD-2022-47000)

A vulnerability classified as critical has been found in Russound XSourcePlayer 777D 06.08.03. This issue affects some unknown processing of the file scriptRunner.cgi. The manipulation leads to privilege escalation. This vulnerability is li

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2022-44037 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44037 | APsystems Energy Communication Unit up to W2.1NA access control (EUVD-2022-46999)

A vulnerability labeled as critical has been found in APsystems Energy Communication Unit V4.1NA/V3.11.4/W2.1NA/V4.1SAA/C1.2.2. Affected by this issue is some unknown functionality. Such manipulation leads to improper access controls. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 91%
CVE-2026-5430 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 18.3%
CVE-2025-65022 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-65022 | Portabilis i-Educar up to 2.10.0 agenda.php cod_agenda sql injection (GHSA-4hrj-5gwx-r4w4)

A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file ieducar/intranet/agenda.php. Such manipulation of the argument cod_agenda leads to

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2024-45058 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-45058 | portabilis i-educar up to 2.8 Setting educar_usuario_cad.php authorization

A vulnerability classified as problematic was found in portabilis i-educar up to 2.8. This issue affects some unknown processing of the file ieducar/intranet/educar_usuario_cad.php of the component Setting Handler. Such manipulation leads t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco-FMC-Sicherheitslücke ermöglicht Root-Zugriff ohne Anmeldung

Eine aktiv ausgenutzte Schwachstelle in Cisco Secure Firewall Management Center ermöglicht Angreifern die Umgehung der Anmeldung und Root-Zugriff. Cisco hat Hot Fixes veröffentlicht, die eine bestehende Kom­promittierung jedoch nicht beseit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 27.3%
CVE-2026-91721 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the browser, including three bugs rated Critical. The Stable channel is moving to 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
3.1 LOW
EPSS 2.8%
CVE-2026-49869 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869 CVE-2026-49869 is an authentication bypass in Kestra OSS that escalates to unauthenticated remote code execution, rated Critical at CVSS 3.1 10.0 and

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-28572 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28572 | Google Android 16-qpr2 Tapjacking InstallLaunch.kt OnCreate privileges management

A vulnerability was found in Google Android 16-qpr2. It has been rated as problematic. This impacts the function OnCreate of the file InstallLaunch.kt of the component Tapjacking. The manipulation leads to improper privilege management. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.4%
CVE-2026-0084 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-0084 | Google Android 16/16-qpr2 HostEmulationManager HostEmulationManager.java privileges management

A vulnerability was found in Google Android 16/16-qpr2. It has been declared as very critical. This affects an unknown function of the file HostEmulationManager.java of the component HostEmulationManager. Executing a manipulation can lead t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.2%
CVE-2026-0065 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-0065 | Google Android 14/15/16/16-qpr2 Background Launch Process Controller BackgroundLaunchProcessController.java areBackgroundActivityStartsAllowed privileges management

A vulnerability has been found in Google Android 14/15/16/16-qpr2 and classified as very critical. Impacted is the function areBackgroundActivityStartsAllowed of the file BackgroundLaunchProcessController.java of the component Background La

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2026-0054 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-0054 | Google Android 14/15/16/16-qpr2 WalletContextualLocationsService.kt isCallerAllowed permission

A vulnerability, which was classified as problematic, was found in Google Android 14/15/16/16-qpr2. This issue affects the function isCallerAllowed of the file WalletContextualLocationsService.kt. The manipulation results in permission issu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2026-75015 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-75015 | Apache Syncope missing encryption (CNNVD-2026-93574773)

A vulnerability was found in Apache Syncope. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to missing encryption of sensitive data. This vulnerability is handled as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 18.1%
CVE-2022-44031 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44031 | Redmine up to 4.2.8/5.0.3 Textile Formatter cross site scripting (EUVD-2022-46993 / Nessus ID 257919)

A vulnerability identified as problematic has been detected in Redmine up to 4.2.8/5.0.3. The affected element is an unknown function of the component Textile Formatter. This manipulation causes cross site scripting. This vulnerability is t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2022-44030 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44030 | Redmine up to 5.0.3 permission (EUVD-2022-46992)

A vulnerability was found in Redmine up to 5.0.3. It has been rated as critical. This affects an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2022-44030. The attack is only possible with

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2022-44029 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44029 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46991)

A vulnerability identified as problematic has been detected in NetScout nGeniusONE up to 6.3.2 P9. This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulnerability is documented as CVE-2022-4402

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2022-44028 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44028 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46990)

A vulnerability was found in NetScout nGeniusONE up to 6.3.2 P9. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability is cataloged as CVE-2022-44028. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-92298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92298 | EspoCRM up to 10.0.8 rand random values (EUVD-2026-80078)

A vulnerability classified as problematic has been found in EspoCRM up to 10.0.8. This affects the function rand. Performing a manipulation results in insufficiently random values. This vulnerability is cataloged as CVE-2026-92298. It is po

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-92216 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92216 | a2ui-project a2ui up to 0.10.7 Binder generic-binder.ts openUrl redirect (Issue 2296 / EUVD-2026-80077)

A vulnerability classified as problematic was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-92299 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92299 | Jitsi Electron SDK up to 10.0.4 Screen Sharing IPC Route getDesktopSources permission (EUVD-2026-80079)

A vulnerability classified as problematic was found in Jitsi Electron SDK up to 10.0.4. This impacts the function getDesktopSources of the component Screen Sharing IPC Route. Executing a manipulation can lead to permission issues. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-92220 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92220 | vllm-project vLLM 0.26.0/0.27.0 MoRIIO Acknowledgement moriio_connector.py request_id/kv_transfer_params resource consumption (ID 50674 / EUVD-2026-80081)

A vulnerability identified as problematic has been detected in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-92217 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92217 | a2ui-project a2ui up to 0.10.6 Message Parsing message-processor.ts processMessages dynamically-determined object attributes (Issue 2297 / EUVD-2026-80080)

A vulnerability, which was classified as critical, has been found in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20.6%
CVE-2026-92221 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92221 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 app_global_admin_model.php generate_index_pasien cari sql injection (EUVD-2026-80082)

A vulnerability labeled as problematic has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-73450 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73450 | Arista EOS up to 4.36.1F state issue (EUVD-2026-80083)

A vulnerability was found in Arista EOS up to 4.32.x/4.33.9M/4.34.7.1M/4.35.5M/4.36.1F and classified as critical. Impacted is an unknown function. Executing a manipulation can lead to state issue. This vulnerability appears as CVE-2026-734

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 22.1%
CVE-2026-75757 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 ash-project

CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 6.7%
CVE-2026-82604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-82603 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 n/a

CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
🇪🇺 EUVD
EPSS 4.8%
CVE-2026-82602 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.8%
CVE-2026-82601 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 23.5%
CVE-2026-75760 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82580 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.