CVE-2026-71807: Schwachstellen-Eintrag (NVD)
In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details (/task/getTask/{taskId}) and trigger unauthorized workflow executions (/task/startWorkFlow).
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-18701 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Subsystem denial of service
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7 and classified as problematic. Affected by this issue is some unknown functionality of the component Query Subsystem. Such manipulation leads to denial of service. This vulnerab
CVE-2026-18705 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Atlas Vector Search privileges management
A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as problematic. The impacted element is an unknown function of the component Atlas Vector Search. Performing a manipulation results in improper privil
CVE-2026-18704 | MongoDB up to 8.3.7 Aggregation Framework improper authorization
A vulnerability marked as problematic has been reported in MongoDB up to 8.3.7. Affected by this issue is some unknown functionality of the component Aggregation Framework. Performing a manipulation results in improper authorization. This v
CVE-2026-18700 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Geospatial Validation use after free
A vulnerability labeled as problematic has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Geospatial Validation. Such manipulation leads to use after free.
CVE-2026-18698 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 improper authorization
A vulnerability identified as very critical has been detected in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. This manipulation causes improper authorization. This vulnerability appears as CVE-2026-18698. The a
CVE-2026-18696 | MongoDB up to 7.0.39/8.0.28/8.3.7 Authorization Check applyOps improper authorization
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been rated as critical. This affects the function applyOps of the component Authorization Check. The manipulation leads to improper authorization. This vulnerability is
CVE-2026-18697 | MongoDB up to 7.0.39/8.0.28/8.3.7 Aggregation Framework denial of service
A vulnerability categorized as problematic has been discovered in MongoDB up to 7.0.39/8.0.28/8.3.7. This impacts an unknown function of the component Aggregation Framework. The manipulation results in denial of service. This vulnerability
CVE-2026-18699 | MongoDB up to 7.0.39/8.0.28/8.3.7 Query Planner denial of service
A vulnerability classified as problematic has been found in MongoDB up to 7.0.39/8.0.28/8.3.7. Affected by this vulnerability is an unknown functionality of the component Query Planner. Performing a manipulation results in denial of service
CVE-2026-18702 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Diagnostic Logging improper authorization
A vulnerability classified as critical was found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected by this issue is some unknown functionality of the component Diagnostic Logging. Executing a manipulation can lead to improper authorizat
CVE-2026-18703 | MongoDB Server up to 8.3.7 certificate validation
A vulnerability, which was classified as problematic, was found in MongoDB Server up to 8.3.7. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper certificate validation. This vulnerabil
CVE-2022-44249 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 UploadFirmwareFile FileName command injection (EUVD-2022-47198)
A vulnerability identified as critical has been detected in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected is the function UploadFirmwareFile. This manipulation of the argument FileName causes command injection. The identification of this
CVE-2022-44250 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setOpModeCfg Hostname command injection (EUVD-2022-47199)
A vulnerability labeled as critical has been found in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this vulnerability is the function setOpModeCfg. Such manipulation of the argument Hostname leads to command injection. This vulnerabi
CVE-2022-44236 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 weak password (EUVD-2022-47186)
A vulnerability classified as critical has been found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. Impacted is an unknown function. This manipulation causes weak password requirements. This vulnerability is registered as CVE-2022-44236
Detecting and Containing CVE-2026-19490: A Defender's Checklist for NetScaler SAML Bypass
Detecting and Containing CVE-2026-19490: A Defender's Checklist for NetScaler SAML Bypass Most authentication bypasses announce themselves through failed logins. CVE-2026-19490 does the opposite. An attacker who exploits it produces a
CVE-2022-44235 | Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807 cross site scripting (EUVD-2022-47185)
A vulnerability was found in Beijing Zed-3 VoIP Simpliclty ASG 8.5.0.17807. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting. This vulnerability
CVE-2022-44232 | libming 0.4.8 decompile.c getInt denial of service (EUVD-2022-47182)
A vulnerability was found in libming 0.4.8. It has been classified as problematic. The affected element is the function getInt of the file decompile.c. The manipulation leads to denial of service. This vulnerability is traded as CVE-2022-44
CVE-2022-44216 | Gnuboard 5.5.4/5.5.5 Change Password permission (EUVD-2022-47166)
A vulnerability was found in Gnuboard 5.5.4/5.5.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. Such manipulation leads to permission issues. This vulnerabil
CVE-2022-44215 | Titan FTP Server up to 19.0 redirect (EUVD-2022-47165)
A vulnerability classified as problematic was found in Titan FTP Server up to 19.0. This issue affects some unknown processing. The manipulation results in open redirect. This vulnerability is identified as CVE-2022-44215. The attack can on
CVE-2022-44213 | ZKTeco ZKBio ECO ADMS up to 3.1-164 cross site scripting (EUVD-2022-47163)
A vulnerability was found in ZKTeco ZKBio ECO ADMS up to 3.1-164 and classified as problematic. This affects an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44213. Th
CVE-2022-44212 | GL.iNet Goodcloud 1.0 Admin Panel access control (EUVD-2022-47162)
A vulnerability labeled as critical has been found in GL.iNet Goodcloud 1.0. This issue affects some unknown processing of the component Admin Panel. Such manipulation leads to improper access controls. This vulnerability is listed as CVE-2
CVE-2022-44211 | GL.iNet Goodcloud 1.1 Setting access control (EUVD-2022-47161)
A vulnerability identified as critical has been detected in GL.iNet Goodcloud 1.1. This vulnerability affects unknown code of the component Setting Handler. This manipulation causes improper access controls. This vulnerability is tracked as
CVE-2022-44201 | D-Link DIR823G 1.02B05 command injection (EUVD-2022-47151)
A vulnerability was found in D-Link DIR823G 1.02B05 and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to command injection. The identification of this vulnerability is CVE-20
CVE-2022-44200 | Netgear R7000P 1.3.0.8/1.3.1.64 stamode_dns1_pri/stamode_dns1_sec buffer overflow (EUVD-2022-47150)
A vulnerability, which was classified as critical, was found in Netgear R7000P 1.3.0.8/1.3.1.64. Affected is an unknown function. Such manipulation of the argument stamode_dns1_pri/stamode_dns1_sec leads to buffer overflow. This vulnerabili
CVE-2022-44199 | Netgear R7000P 1.3.1.64 openvpn_server_ip buffer overflow (EUVD-2022-47149)
A vulnerability, which was classified as critical, has been found in Netgear R7000P 1.3.1.64. This impacts an unknown function. This manipulation of the argument openvpn_server_ip causes buffer overflow. This vulnerability is handled as CVE
CVE-2022-44198 | Netgear R7000P 1.3.1.64 openvpn_push1 buffer overflow (EUVD-2022-47148)
A vulnerability classified as critical was found in Netgear R7000P 1.3.1.64. This affects an unknown function. The manipulation of the argument openvpn_push1 results in buffer overflow. This vulnerability is known as CVE-2022-44198. Access
CVE-2022-44197 | Netgear R7000P 1.3.0.8 openvpn_server_ip buffer overflow (EUVD-2022-47147)
A vulnerability classified as critical has been found in Netgear R7000P 1.3.0.8. The impacted element is an unknown function. The manipulation of the argument openvpn_server_ip leads to buffer overflow. This vulnerability is traded as CVE-2
CVE-2022-44196 | Netgear R7000P 1.3.0.8 openvpn_push1 buffer overflow (EUVD-2022-47146)
A vulnerability described as critical has been identified in Netgear R7000P 1.3.0.8. The affected element is an unknown function. Executing a manipulation of the argument openvpn_push1 can lead to buffer overflow. This vulnerability appears
CVE-2022-44194 | Netgear R7000P 1.3.0.8 apmode_dns1_pri/apmode_dns1_sec buffer overflow (EUVD-2022-47144)
A vulnerability marked as critical has been reported in Netgear R7000P 1.3.0.8. Impacted is an unknown function. Performing a manipulation of the argument apmode_dns1_pri/apmode_dns1_sec results in buffer overflow. This vulnerability is rep
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance Software Remote Access SSL VPN service denial of service
A vulnerability was found in Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software and classified as critical. Affected by this issue is some unknown functionality of the component Remote Acc
CVE-2026-69116 | xpf0000 FlyEnv up to 4.17.x Html Sanitization injection
A vulnerability, which was classified as problematic, has been found in xpf0000 FlyEnv up to 4.17.x. This vulnerability affects unknown code of the component Html Sanitization. Performing a manipulation results in injection. This vulnerabil
CVE-2026-69114 | Spacebar Server Message Deletion Handlers permission
A vulnerability classified as problematic was found in Spacebar Server. This affects an unknown part of the component Message Deletion Handlers. Such manipulation leads to permission issues. This vulnerability is traded as CVE-2026-69114. T
CVE-2026-71967 | OP-TEE OS up to 4.10.0 Widevine PTA is_user_ta_ctx null pointer dereference
A vulnerability was found in OP-TEE OS up to 4.10.0. It has been declared as critical. Affected is the function is_user_ta_ctx of the component Widevine PTA. Such manipulation leads to null pointer dereference. This vulnerability is listed
CVE-2026-18694 | MongoDB up to 7.0.39/8.0.28/8.3.7 Geospatial Query Processing memory corruption
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been declared as critical. The impacted element is an unknown function of the component Geospatial Query Processing. Executing a manipulation can lead to memory corrupti
CVE-2026-18695 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 denial of service
A vulnerability, which was classified as problematic, has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7. Affected is an unknown function. Performing a manipulation results in denial of service. This vulnerability is identified as C
CVE-2026-69112 | Hugging Face Accelerate up to 1.14.0 Sharded Checkpoint Index weight_map path traversal
A vulnerability, which was classified as critical, was found in Hugging Face Accelerate up to 1.14.0. Affected by this issue is the function load_checkpoint_in_model/load_checkpoint_and_dispatch of the component Sharded Checkpoint Index. Su
CVE-2026-18691 | MongoDB Server up to 7.0.39/8.0.28/8.3.7 Intra-cluster Connection Setup improper authentication
A vulnerability has been found in MongoDB Server up to 7.0.39/8.0.28/8.3.7 and classified as critical. This issue affects some unknown processing of the component Intra-cluster Connection Setup. This manipulation causes improper authenticat
CVE-2026-18692 | MongoDB Server up to 8.3.7 Timeseries use after free
A vulnerability was found in MongoDB Server up to 8.3.7 and classified as critical. Impacted is an unknown function of the component Timeseries Handler. Such manipulation leads to use after free. This vulnerability is listed as CVE-2026-186
CVE-2026-18693 | MongoDB up to 7.0.39/8.0.28/8.3.7 Timeseries memory corruption
A vulnerability was found in MongoDB up to 7.0.39/8.0.28/8.3.7. It has been classified as critical. The affected element is an unknown function of the component Timeseries Handler. Performing a manipulation results in memory corruption. Thi
CVE-2026-76460 | Cisco Identity Services Engine Software API improper authentication
A vulnerability classified as very critical was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector. This affects an unknown function of the component API. Such manipulation leads to improper authentication.
CVE-2026-68772 | ZenML up to 0.94.6 CloudpickleMaterializer cloudpickle_materializer.py cloudpickle.load deserialization
A vulnerability was found in ZenML up to 0.94.6. It has been rated as problematic. Impacted is the function cloudpickle.load of the file cloudpickle_materializer.py of the component CloudpickleMaterializer. Performing a manipulation results
CVE-2026-5855 | Contiki-NG LwM2M TLV parser lwm2m-tlv.c lwm2m_tlv_read length out-of-bounds
A vulnerability, which was classified as very critical, has been found in Contiki-NG. This impacts the function lwm2m_tlv_read of the file os/services/lwm2m/lwm2m-tlv.c of the component LwM2M TLV parser. Performing a manipulation of the arg
CVE-2026-5856 | Contiki-NG mDNS Resolver resolv.c skip_name out-of-bounds
A vulnerability was found in Contiki-NG. It has been classified as critical. This affects the function skip_name of the file os/services/resolv/resolv.c of the component mDNS Resolver. This manipulation causes out-of-bounds read. The identi
CVE-2026-53977 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Route bootstrap-runtime.js improper authentication
A vulnerability was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. It has been rated as critical. The affected element is an unknown function of the file bootstrap-runtime.js of the component Route Handler. The manipulation leads to i
CVE-2026-53975 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Command Execution /api/fs/exec spawn os command injection
A vulnerability, which was classified as critical, was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. This vulnerability affects the function spawn of the file /api/fs/exec of the component Command Execution. The manipulation results
CVE-2026-53976 | Bohdan Triapitsyn OpenChamber up to 1.11.7 File Serving /api/fs/read resolveReadPathFromContext allowOutsideWorkspace path traversal
A vulnerability has been found in Bohdan Triapitsyn OpenChamber up to 1.11.7 and classified as critical. This issue affects the function resolveReadPathFromContext of the file /api/fs/read of the component File Serving. This manipulation of
CVE-2026-70617 | Spacebar Server Channels Recipient Endpoint authorization (dcfd910)
A vulnerability marked as critical has been reported in Spacebar Server. Affected by this vulnerability is an unknown functionality of the component Channels Recipient Endpoint. Performing a manipulation results in missing authorization. Th
CVE-2026-70618 | Spacebar Server Roles Member-Ids Endpoint improper authorization
A vulnerability classified as problematic has been found in Spacebar Server. This affects an unknown part of the component Roles Member-Ids Endpoint. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026
CVE-2022-4995 | Weaver Network E-cology up to 10.51 uploaderOperate.jsp secId/plandetailid unrestricted upload
A vulnerability, which was classified as critical, has been found in Weaver Network E-cology up to 10.51. This issue affects some unknown processing of the file /workrelate/plan/util/uploaderOperate.jsp. The manipulation of the argument sec
CVE-2022-44193 | Netgear R7000P 1.3.1.64 /usr/sbin/httpd starthour/startminute /endhour/endminute buffer overflow (EUVD-2022-47143)
A vulnerability labeled as critical has been found in Netgear R7000P 1.3.1.64. This issue affects some unknown processing of the file /usr/sbin/httpd. Such manipulation of the argument starthour/startminute /endhour/endminute leads to buffe
CVE-2022-44191 | Netgear R7000P 1.3.1.64 KEY1/KEY2 buffer overflow (EUVD-2022-47141)
A vulnerability identified as critical has been detected in Netgear R7000P 1.3.1.64. This vulnerability affects unknown code. This manipulation of the argument KEY1/KEY2 causes buffer overflow. This vulnerability is registered as CVE-2022-4
CVE-2022-44190 | Netgear R7000P 1.3.1.64 enable_band_steering buffer overflow (EUVD-2022-47140)
A vulnerability categorized as critical has been discovered in Netgear R7000P 1.3.1.64. This affects an unknown part. The manipulation of the argument enable_band_steering results in buffer overflow. This vulnerability is cataloged as CVE-2
CVE-2022-44188 | Netgear R7000P 1.3.0.8 /usr/sbin/httpd enable_band_steering buffer overflow (EUVD-2022-47138)
A vulnerability was found in Netgear R7000P 1.3.0.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /usr/sbin/httpd. The manipulation of the argument enable_band_steering leads to buffer over
CVE-2026-69110 | Microck opencode-studio up to 2.4.3 missing authentication
A vulnerability categorized as critical has been discovered in Microck opencode-studio up to 2.4.3. Affected by this issue is some unknown functionality. The manipulation results in missing authentication. This vulnerability was named CVE-2
CVE-2026-69100 | dromara lamp-cloud up to 5.6.2 GlueFactory os command injection
A vulnerability was found in dromara lamp-cloud up to 5.6.2. It has been declared as very critical. Affected is an unknown function of the component GlueFactory. Executing a manipulation can lead to os command injection. This vulnerability
CVE-2025-71399 | better-auth Better Auth up to 1.4.4 Router privileges management (EUVD-2025-210590)
A vulnerability classified as critical has been found in better-auth Better Auth up to 1.4.4. This affects an unknown function of the component Router. The manipulation leads to improper privilege management. This vulnerability is traded as
CVE-2026-67326 | gitpython-developers GitPython up to 3.1.49 Config Writer config_writer section injection (EUVD-2026-51814 / Nessus ID 331643)
A vulnerability, which was classified as critical, was found in gitpython-developers GitPython up to 3.1.49. The impacted element is the function config_writer of the component Config Writer. Executing a manipulation of the argument section
CVE-2026-67309 | Traefik up to 3.7.7 RewriteTarget Middleware path traversal (EUVD-2026-51815)
A vulnerability identified as critical has been detected in Traefik up to 3.7.7. Affected by this vulnerability is an unknown functionality of the component RewriteTarget Middleware. Performing a manipulation results in path traversal. This
CVE-2026-20316 | Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure (EUVD-2026-50404)
A vulnerability was found in Cisco Secure Firewall Management Center. It has been classified as problematic. Affected is an unknown function of the component Web Interface. Performing a manipulation results in information disclosure. This v
CVE-2026-92592 | craftcms Craft CMS up to 4.18.5/5.10.12 Twig template system redirect (EUVD-2026-81292)
A vulnerability identified as problematic has been detected in craftcms Craft CMS up to 4.18.5/5.10.12. The affected element is the function system of the component Twig template. The manipulation of the argument redirect leads to open redi
CVE-2026-92593 | craftcms Craft CMS up to 5.10.12 Redirect renderObjectTemplate returnUrl/redirect special elements in template engine (EUVD-2026-81293)
A vulnerability was found in craftcms Craft CMS up to 5.10.12. It has been rated as critical. This issue affects the function View::renderObjectTemplate of the component Redirect Handler. Performing a manipulation of the argument returnUrl/