CVE-2026-65669: Schwachstellen-Eintrag (NVD)
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users
TP-Link Tapo C200 smart cameras were affected by two zero-day vulnerabilities that could allow attackers on the same network to bypass authentication or disrupt camera services. The flaws, tracked as CVE-2026-15315 and CVE-2026-15316, were
Issabel PBX JWT Key Flaw Enables Unauthenticated Remote Code Execution
A critical vulnerability in the Issabel Framework could allow unauthenticated remote attackers to execute arbitrary operating-system commands on affected Issabel PBX deployments by exploiting a hard-coded JSON Web Token signing key. Tracked
Known MCP Vulnerabilities and How an MCP Gateway Blocks Them
TL;DR The Model Context Protocol introduces security vectors including tool poisoning, STDIO command injection, tool shadowing, and credential exfiltration. Multiple high-severity vulnerabilities (such as CVE-2025-54073 and CVE-2026-33032)
Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild
A critical vulnerability in the Issabel Framework, which supports Issabel PBX deployments, is being actively exploited in the wild. The flaw, tracked as CVE-2026-89026, allows unauthenticated remote attackers to execute OS commands on vulne
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek. Weiterlesen
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do f
Apache Syncope Flaws Enable SQL Injection, JWT Token Takeover and Code Injection
Apache Syncope has disclosed three important vulnerabilities that could allow privileged administrators to execute arbitrary SQL commands, bypass Groovy sandbox protections to inject code, and hijack higher-privileged user sessions through
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is hi
Google schließt Pixel-Modem-Lücke CVE-2026-58704 nach ersten Ausnutzungszeichen
LONDON (IT BOLTWISE) – Google hat eine hochkritische Sicherheitslücke im Pixel Cellular Modem als ausnutzbar in freier Wildbahn eingestuft. Die Schwachstelle CVE-2026-58704 mit einem CVSS-Score von 8,0 ermöglicht eine Rechteausweitung über
Acronis warnt: cPanel-Backup-Plugin-Lücke (CVE-2026-87886) wird aktiv ausgenutzt
LONDON (IT BOLTWISE) – Acronis meldet eine hochkritische Schwachstelle im Backup-Plugin für cPanel und WHM, die bereits in gezielten Angriffen ausgenutzt wird. Betroffen sind Linux-Installationen vor bestimmten Build-Versionen, während Fixe
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems. This article has been indexed from eSecurity Planet Read the original article: Cisco
[NEU] [hoch] Ghostscript: Schwachstelle ermöglicht Codeausführung und Manipulation von Daten
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ghostscript ausnutzen, um beliebigen Programmcode auszuführen, und um Daten zu manipulieren. Weiterlesen
[NEU] [hoch] GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GIMP ausnutzen, um beliebigen Programmcode auszuführen und um einen Denial of Service Angriff durchzuführen. Weiterlesen
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular M
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a c
[NEU] [niedrig] binutils: Schwachstelle ermöglicht Denial of Service
Ein lokaler Angreifer kann eine Schwachstelle in binutils ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [hoch] Netgate pfSense: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Netgate pfSense ausnutzen, um Sicherheitsmaßnahmen zu umgehen und beliebigen PHP-Code und Shell-Befehle auszuführen. Weiterlesen
[NEU] [mittel] BigBlueButton: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in BigBlueButton ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [hoch] MikroTik RouterOS: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MikroTik RouterOS ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen. Weiterlesen
[UPDATE] [hoch] BusyBox: Schwachstelle ermöglicht Codeausführung
Ein entfernter Angreifer kann eine Schwachstelle in BusyBox ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] Camunda: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Camunda ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] Podman: Schwachstelle ermöglicht Manipulation von Dateien
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in Podman ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [mittel] NGINX: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NGINX ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Octopus Deploy: Schwachstelle ermöglicht Manipulation von Dateien und potenziell Codeausführung
Ein Angreifer kann eine Schwachstelle in Octopus Deploy ausnutzen, um Dateien zu manipulieren und potenziell um beliebigen Programmcode auszuführen. Weiterlesen
CVE-2026-1168 | GitLab up to 19.1.7/19.2.5/19.3.1 GraphQL Complexity Calculation allocation of resources (WID-SEC-2026-3315)
A vulnerability has been found in GitLab up to 19.1.7/19.2.5/19.3.1 and classified as problematic. The affected element is an unknown function of the component GraphQL Complexity Calculation. This manipulation causes allocation of resources
CVE-2026-13210 | GitLab up to 19.1.7/19.2.5/19.3.1 Environment Scope Pattern Matcher input validation (WID-SEC-2026-3315)
A vulnerability classified as problematic has been found in GitLab up to 19.1.7/19.2.5/19.3.1. This affects an unknown part of the component Environment Scope Pattern Matcher. The manipulation leads to improper input validation. This vulner
CVE-2026-12910 | GitLab prior 19.1.8/19.2.6/19.3.2 SAML SSO missing authentication (WID-SEC-2026-3315)
A vulnerability categorized as critical has been discovered in GitLab. This affects an unknown function of the component SAML SSO. The manipulation results in missing authentication. This vulnerability is reported as CVE-2026-12910. The att
CVE-2024-11222 | GitLab up to 19.1.7/19.2.5/19.3.1 Pipeline Creation race condition (WID-SEC-2026-3315)
A vulnerability was found in GitLab up to 19.1.7/19.2.5/19.3.1. It has been classified as critical. This affects an unknown function of the component Pipeline Creation. Performing a manipulation results in race condition. This vulnerability
CVE-2025-14871 | GitLab up to 19.1.7/19.2.5/19.3.1 GraphQL allocation of resources (WID-SEC-2026-3315)
A vulnerability, which was classified as critical, was found in GitLab up to 19.1.7/19.2.5/19.3.1. Impacted is an unknown function of the component GraphQL. The manipulation results in allocation of resources. This vulnerability was named C
CVE-2026-19248 | Qt QDomDocument denial of service (WID-SEC-2026-3332)
A vulnerability classified as problematic was found in Qt. The affected element is an unknown function of the component QDomDocument. The manipulation results in denial of service. This vulnerability is known as CVE-2026-19248. It is possib
CVE-2026-89787 | Linux Kernel up to 7.2.5 ext4 fs/ext4/namei.c ext4_match name_len use after free (EUVD-2026-80308)
A vulnerability was found in Linux Kernel up to 7.2.5. It has been classified as very critical. This impacts the function ext4_match of the file fs/ext4/namei.c of the component ext4. The manipulation of the argument name_len leads to use a
CVE-2026-89789 | Linux Kernel up to 7.2.5 gtp gtp.c gtp_newlink use after free (EUVD-2026-80310)
A vulnerability classified as very critical was found in Linux Kernel up to 7.2.5. The impacted element is the function gtp_newlink of the file gtp.c of the component gtp. Such manipulation leads to use after free. This vulnerability is doc
CVE-2026-89788 | Linux Kernel up to 7.2.5/7.3-rc1 ksmbd fs/smb/server/smb2pdu.c smb2_tree_connect use after free (EUVD-2026-80309)
A vulnerability was found in Linux Kernel up to 7.2.5/7.3-rc1 and classified as very critical. This affects the function smb2_tree_connect of the file fs/smb/server/smb2pdu.c of the component ksmbd. Executing a manipulation can lead to use
CVE-2026-89791 | Linux Kernel up to 6.18.51/7.2.4/7.3-rc1 perf perf_mmap_close use after free (EUVD-2026-80312)
A vulnerability was found in Linux Kernel up to 6.18.51/7.2.4/7.3-rc1 and classified as very critical. Affected by this vulnerability is the function perf_mmap_close of the component perf. The manipulation results in use after free. This vu
CVE-2026-89792 | Linux Kernel up to 7.2.5/7.3-rc1 ksmbd out-of-bounds (EUVD-2026-80314)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.2.5/7.3-rc1. This impacts an unknown function of the component ksmbd. Executing a manipulation can lead to out-of-bounds read. This vulnerability appears a
CVE-2026-89790 | Linux Kernel up to 6.18.51/7.2.5 IPv6 net/ipv6/route.c rt6_upper_bound_set divide by zero (EUVD-2026-80311)
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.18.51/7.2.5. This affects the function rt6_upper_bound_set of the file net/ipv6/route.c of the component IPv6. Performing a manipulation results in
CVE-2026-18140 | AWS aws-smithy-json up to 0.62.6 Unknown-Key Skip Path recursion (Nessus ID 346043)
A vulnerability was found in AWS aws-smithy-json up to 0.62.6. It has been declared as problematic. The impacted element is an unknown function of the component Unknown-Key Skip Path. Such manipulation leads to uncontrolled recursion. This
CVE-2026-53939 | OpenIDC cjose up to 0.6.1/0.6.2.5 _cjose_jwe_set_cek_aes_cbc random values (Nessus ID 346044)
A vulnerability labeled as problematic has been found in OpenIDC cjose up to 0.6.1/0.6.2.5. Affected by this vulnerability is the function _cjose_jwe_set_cek_aes_cbc. Such manipulation leads to insufficiently random values. This vulnerabili
CVE-2026-53938 | OpenIDC cjose 0.6.2.2 JWE Decryption cjose_jwe_import/cjose_jwe_decrypt encrypted_key heap-based overflow (Nessus ID 346044)
A vulnerability identified as critical has been detected in OpenIDC cjose 0.6.2.2. Affected is the function cjose_jwe_import/cjose_jwe_decrypt of the component JWE Decryption. This manipulation of the argument encrypted_key causes heap-base
CVE-2026-28627 | Google Android 16-qpr2/17 btm_sec.cc btm_sec_encrypt_change downgrade
A vulnerability labeled as problematic has been found in Google Android 16-qpr2/17. The impacted element is the function btm_sec_encrypt_change of the file btm_sec.cc. The manipulation results in algorithm downgrade. This vulnerability is r
CVE-2026-28642 | Google Android 14/15/16/16-qpr2 ActivityStarter ActivityStarter.java executeRequest privileges management
A vulnerability categorized as very critical has been discovered in Google Android 14/15/16/16-qpr2. This affects the function executeRequest of the file ActivityStarter.java of the component ActivityStarter. The manipulation results in imp
CVE-2026-28639 | Google Android up to 17 rw_mfc.cc rw_mfc_handle_read_op out-of-bounds write
A vulnerability was found in Google Android 14/15/16/16-qpr2/17. It has been rated as very critical. The impacted element is the function rw_mfc_handle_read_op of the file rw_mfc.cc. The manipulation leads to out-of-bounds write. This vulne
CVE-2026-28634 | Google Android up to 17 PhoneInterfaceManager PhoneInterfaceManager.java handleUssdRequest privileges management
A vulnerability was found in Google Android 14/15/16/16-qpr2/17. It has been declared as problematic. The affected element is the function handleUssdRequest of the file PhoneInterfaceManager.java of the component PhoneInterfaceManager. Exec
CVE-2026-28636 | Google Android 14/15/16/16-qpr2 PickActivity.java setupLayout privileges management
A vulnerability was found in Google Android 14/15/16/16-qpr2. It has been classified as very critical. Impacted is the function setupLayout of the file PickActivity.java. Performing a manipulation results in improper privilege management. T
CVE-2026-28624 | Google Android 16/16-qpr2/17 privileges management
A vulnerability has been found in Google Android 16/16-qpr2/17 and classified as very critical. This vulnerability affects unknown code. This manipulation causes improper privilege management. The identification of this vulnerability is CVE
CVE-2026-28626 | Google Android up to 17 Intent Redirection SetupPassthroughActivity.java onCreate redirect
A vulnerability, which was classified as problematic, was found in Google Android 14/15/16/16-qpr2/17. This affects the function onCreate of the file SetupPassthroughActivity.java of the component Intent Redirection. The manipulation result
CVE-2026-28638 | Google Android up to 17 XmpDataParser XmpDataParser.java information disclosure
A vulnerability, which was classified as problematic, has been found in Google Android 14/15/16/16-qpr2/17. Affected by this issue is some unknown functionality of the file XmpDataParser.java of the component XmpDataParser. The manipulation
CVE-2026-28630 | Google Android 17 ContactsPickerActivity ContactsPickerActivity.kt onCreate information disclosure
A vulnerability classified as problematic has been found in Google Android 17. Affected is the function onCreate of the file ContactsPickerActivity.kt of the component ContactsPickerActivity. Performing a manipulation results in information
CVE-2026-28622 | Google Android 17 MediaProvider MediaProvider.java getQueryBuilderInternal permission
A vulnerability described as problematic has been identified in Google Android 17. This impacts the function getQueryBuilderInternal of the file MediaProvider.java of the component MediaProvider. Such manipulation leads to permission issues
CVE-2026-28623 | Google Android 16/16-qPR2/17 Bluetooth BleRssiRangingCapabilities.java writeToParcel permission
A vulnerability marked as problematic has been reported in Google Android 16/16-qPR2/17. This affects the function writeToParcel of the file BleRssiRangingCapabilities.java of the component Bluetooth. This manipulation causes permission iss
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b
CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca
CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb
CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a
CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution