CVE-2026-78428: Schwachstellen-Eintrag (NVD)
For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-30 | 2026-09-18 |
|---|---|---|
| ≥90 % | 0 | 0 |
| ≥50 % | 0 | 0 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 300 |
CVE-2026-90803 | GNU Binutils 2.47 ld bfd/elf64-x86-64.c elf_x86_64_relocate_section roff buffer overflow (Bug 34444)
A vulnerability was found in GNU Binutils 2.47. It has been declared as problematic. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the arg
CVE-2026-89013 | Dolibarr up to 23.0.4 Document Storage Endpoints htdocs/document.php hashp authorization
A vulnerability was found in Dolibarr up to 23.0.4. It has been rated as problematic. This affects an unknown function of the file htdocs/document.php of the component Document Storage Endpoints. Performing a manipulation of the argument ha
CVE-2026-90802 | GNU Binutils 2.47 ld bfd/libbfd.c bfd_putl64 null pointer dereference (Bug 34443)
A vulnerability was found in GNU Binutils 2.47. It has been classified as problematic. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. This vulnerability a
CVE-2026-90801 | GNU Binutils 2.47 ld bfd/cache.c cache_bwrite nbytes buffer overflow (Bug 34442)
A vulnerability was found in GNU Binutils 2.47 and classified as problematic. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. This vulne
CVE-2026-81917 | Concrete CMS up to 9.5.2 Document Library block cross site scripting
A vulnerability categorized as problematic has been discovered in Concrete CMS up to 9.5.2. This vulnerability affects unknown code of the component Document Library block. Executing a manipulation can lead to cross site scripting. This vul
CVE-2026-81918 | Concrete CMS up to 9.5.2 Page Attribute Display Block cross site scripting
A vulnerability identified as problematic has been detected in Concrete CMS up to 9.5.2. This issue affects some unknown processing of the component Page Attribute Display Block. The manipulation leads to cross site scripting. This vulnerab
CVE-2026-81911 | Concrete CMS up to 9.5.2 Boards canEditBoardContents collection cross site scripting
A vulnerability marked as problematic has been reported in Concrete CMS up to 9.5.2. This affects the function canEditBoardContents of the component Boards. Performing a manipulation of the argument collection results in cross site scriptin
CVE-2026-81916 | Concrete CMS up to 9.5.2 Express Entry Authorization privileges management
A vulnerability, which was classified as problematic, was found in Concrete CMS up to 9.5.2. Impacted is an unknown function of the component Express Entry Authorization. Such manipulation leads to improper privilege management. This vulner
CVE-2026-74761 | Apache ActiveMQ improper authentication
A vulnerability classified as critical was found in Apache ActiveMQ. The impacted element is an unknown function. Executing a manipulation can lead to improper authentication. This vulnerability appears as CVE-2026-74761. The attack may be
CVE-2026-75035 | SUSE Rancher up to 2.15.0 Token store privileges management
A vulnerability was found in SUSE Rancher up to 2.15.0. It has been rated as problematic. This affects an unknown function of the component Token store. This manipulation causes improper privilege management. This vulnerability is handled a
CVE-2026-67593 | Apache ActiveMQ Artemis Openwire Protocol authorization
A vulnerability categorized as critical has been discovered in Apache ActiveMQ Artemis. This affects an unknown part of the component Openwire Protocol. Executing a manipulation can lead to missing authorization. This vulnerability is regis
CVE-2026-57967 | Apache ActiveMQ Artemis missing authentication
A vulnerability was found in Apache ActiveMQ Artemis. It has been rated as very critical. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authentication. This vulnerability is cataloged as
CVE-2026-87544 | Google Chrome up to 152.0.7977.82 Extensions improper authorization
A vulnerability was found in Google Chrome. It has been classified as critical. This impacts an unknown function of the component Extensions. This manipulation causes improper authorization. This vulnerability is registered as CVE-2026-8754
CVE-2026-12647 | Ivanti Neurons for ITSM up to 2026.1 missing authentication
A vulnerability described as critical has been identified in Ivanti Neurons for ITSM up to 2026.1. Impacted is an unknown function. Such manipulation leads to missing authentication. This vulnerability is documented as CVE-2026-12647. The a
CVE-2026-12650 | Ivanti Neurons for ITSM up to 2026.1 deserialization
A vulnerability was found in Ivanti Neurons for ITSM up to 2026.1 and classified as critical. This affects an unknown function. The manipulation results in deserialization. This vulnerability was named CVE-2026-12650. The attack may be perf
CVE-2026-12646 | Ivanti Neurons for ITSM up to 2026.1 missing authentication
A vulnerability, which was classified as critical, was found in Ivanti Neurons for ITSM up to 2026.1. The affected element is an unknown function. Executing a manipulation can lead to missing authentication. This vulnerability is handled as
CVE-2026-12645 | Ivanti Neurons for ITSM up to 2026.1 missing authentication (CNNVD-2026-98054320)
A vulnerability, which was classified as critical, has been found in Ivanti Neurons for ITSM up to 2026.1. Impacted is an unknown function. Performing a manipulation results in missing authentication. This vulnerability is known as CVE-2026
CVE-2026-86426 | LibreNMS up to 26.7.x REST API improper authentication
A vulnerability marked as critical has been reported in LibreNMS up to 26.7.x. Affected is an unknown function of the component REST API. Performing a manipulation results in improper authentication. This vulnerability is known as CVE-2026-
CVE-2026-47753 | LXC Incus up to 7.0.x Backup backend.go (*backend).CreateInstanceFromBackup null pointer dereference
A vulnerability, which was classified as critical, was found in LXC Incus up to 7.0.x. This affects the function (*backend).CreateInstanceFromBackup of the file internal/server/storage/backend.go of the component Backup Handler. The manipul
CVE-2026-75033 | SUSE Rancher up to 2.15.0 Namespace Creation authorization
A vulnerability described as problematic has been identified in SUSE Rancher up to 2.15.0. Affected is an unknown function of the component Namespace Creation. Executing a manipulation can lead to authorization bypass. This vulnerability is
CVE-2026-71403 | SUSE Rancher up to 2.15.0 User Update username/principalIds privileges management
A vulnerability was found in SUSE Rancher up to 2.15.0. It has been declared as problematic. This issue affects some unknown processing of the component User Update. Executing a manipulation of the argument username/principalIds can lead to
CVE-2026-85170 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Mail Composer server-side request forgery
A vulnerability categorized as critical has been discovered in n8n-io n8n. Impacted is an unknown function of the component Mail Composer. Executing a manipulation can lead to server-side request forgery. This vulnerability is tracked as CV
CVE-2026-85169 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 $fromAI handler sandbox
A vulnerability described as critical has been identified in n8n-io n8n. The affected element is the function $fromAI of the component $fromAI handler. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-85
CVE-2026-48754 | lxc incus up to 7.0.0 createDependentVolumesFromBackup null pointer dereference
A vulnerability was found in lxc incus up to 7.0.0 and classified as problematic. Affected by this vulnerability is the function createDependentVolumesFromBackup. Executing a manipulation can lead to null pointer dereference. This vulnerabi
CVE-2026-44252 | Wazuh up to 4.14.4 Manager ossec.conf privileges management
A vulnerability classified as very critical was found in Wazuh up to 4.14.4. The affected element is an unknown function of the file ossec.conf of the component Manager. Executing a manipulation can lead to improper privilege management. Th
CVE-2026-46343 | Wazuh up to 4.14.5/5.0.0-beta1 Cluster Common common.py WazuhCommon.end_receiving_file path traversal
A vulnerability has been found in Wazuh up to 4.14.5/5.0.0-beta1 and classified as very critical. This impacts the function WazuhCommon.end_receiving_file of the file framework/wazuh/core/cluster/common.py of the component Cluster Common. T
CVE-2026-48756 | lxc incus up to 7.0.0 CreateCustomVolumeFromBackup null pointer dereference
A vulnerability was found in lxc incus up to 7.0.0. It has been classified as problematic. Affected by this issue is the function CreateCustomVolumeFromBackup. The manipulation leads to null pointer dereference. This vulnerability is docume
CVE-2026-70657 | 9001 Copyparty up to 1.20.16 access control
A vulnerability was found in 9001 Copyparty up to 1.20.16. It has been classified as problematic. This issue affects some unknown processing. Performing a manipulation results in improper access controls. This vulnerability is known as CVE-
CVE-2025-27771 | uptrain-ai UpTrain up to 0.7.1 add_prompts checks/metadata code injection (EUVD-2025-210735)
A vulnerability labeled as critical has been found in uptrain-ai UpTrain up to 0.7.1. This affects an unknown part of the component add_prompts. The manipulation of the argument checks/metadata results in code injection. This vulnerability
CVE-2025-27770 | uptrain-ai UpTrain up to 0.7.1 checks/metadata code injection
A vulnerability identified as critical has been detected in uptrain-ai UpTrain up to 0.7.1. Affected by this issue is some unknown functionality. The manipulation of the argument checks/metadata leads to code injection. This vulnerability i
CVE-2026-45699 | Netatalk up to 4.4.2 copydir stack-based overflow
A vulnerability was found in Netatalk up to 4.4.2. It has been declared as critical. The impacted element is the function copydir. Such manipulation leads to stack-based buffer overflow. This vulnerability is referenced as CVE-2026-45699. T
CVE-2025-27621 | UpTrain AI up to 0.7.1 Backend uptrain-access-token cross-domain policy
A vulnerability categorized as problematic has been discovered in UpTrain AI UpTrain up to 0.7.1. Affected by this vulnerability is an unknown functionality of the component Backend. Executing a manipulation of the argument uptrain-access-t
CVE-2025-27772 | uptrain-ai UpTrain up to 0.7.1 checks/metadata code injection
A vulnerability classified as critical was found in uptrain-ai UpTrain up to 0.7.1. Affected by this vulnerability is an unknown functionality. The manipulation of the argument checks/metadata results in code injection. This vulnerability i
CVE-2026-73846 | ondata ckan-mcp-server up to 0.4.111 Cache src/utils/cache.ts canonicalizeParams data authenticity
A vulnerability described as critical has been identified in ondata ckan-mcp-server up to 0.4.111. This vulnerability affects the function canonicalizeParams of the file src/utils/cache.ts of the component Cache. Executing a manipulation ca
CVE-2026-49986 | cdeust Cortex up to 3.17.0 Root Validation visualize_bootstrap.py _is_cortex_root CLAUDE_PROJECT_DIR code injection
A vulnerability was found in cdeust Cortex up to 3.17.0. It has been rated as problematic. This impacts the function _is_cortex_root of the file mcp_server/server/visualize_bootstrap.py of the component Root Validation. The manipulation of
CVE-2026-49826 | Concourse up to 8.2.2 redirect
A vulnerability categorized as problematic has been discovered in Concourse up to 8.2.2. Affected is an unknown function. The manipulation results in open redirect. This vulnerability was named CVE-2026-49826. The attack may be performed fr
CVE-2026-46380 | compliance-trestle Remote Fetching Subsystem server-side request forgery
A vulnerability was found in compliance-trestle. It has been rated as critical. This affects an unknown function of the component Remote Fetching Subsystem. Performing a manipulation results in server-side request forgery. This vulnerabilit
CVE-2026-73664 | FreePBX up to 17.0.10 publicKeySave AJAX endpoint Backup.class.php improper authorization
A vulnerability categorized as very critical has been discovered in FreePBX up to 17.0.10. This affects an unknown part of the file Backup.class.php of the component publicKeySave AJAX endpoint. Executing a manipulation can lead to improper
CVE-2026-73428 | Basecamp Trix up to 2.1.17 HTMLParser/StringPiece StringPiece.fromJSON HTML injection
A vulnerability has been found in Basecamp Trix up to 2.1.17 and classified as problematic. The affected element is the function StringPiece.fromJSON of the component HTMLParser/StringPiece. The manipulation leads to HTML injection. This vu
CVE-2026-73489 | Eugeny Russh up to 0.62.3 Parser encrypted.rs out-of-bounds
A vulnerability, which was classified as problematic, has been found in Eugeny Russh up to 0.62.3. This issue affects some unknown processing of the file russh/src/server/encrypted.rs of the component Parser. Performing a manipulation resul
CVE-2026-73420 | NextAuth.js auth-core-next-auth Email Normalization defaultNormalizer improper authentication
A vulnerability classified as critical was found in NextAuth.js auth-core-next-auth. This vulnerability affects the function defaultNormalizer of the component Email Normalization. Such manipulation leads to improper authentication. This vu
CVE-2026-73417 | Jupyter JupyterLab up to 4.5.9/4.6.1 Notebook Extension index.ts code injection
A vulnerability labeled as problematic has been found in Jupyter JupyterLab up to 4.5.9/4.6.1. Affected is an unknown function of the file packages/notebook-extension/src/index.ts of the component Notebook Extension. Executing a manipulatio
CVE-2026-73660 | FreePBX prior 16.0.6/17.0.5.4 Text-To-Speech module agi-bin/propolys-tts.agi os command injection
A vulnerability has been found in FreePBX and classified as problematic. This affects an unknown function of the file agi-bin/propolys-tts.agi of the component Text-To-Speech module. The manipulation leads to os command injection. This vuln
CVE-2026-73416 | JupyterLab up to 4.5.9/4.6.1 PyPI Extension Manager manager.py privileges management
A vulnerability was found in JupyterLab up to 4.5.9/4.6.1 and classified as problematic. This issue affects some unknown processing of the file jupyterlab/extensions/manager.py of the component PyPI Extension Manager. Executing a manipulati
CVE-2026-73661 | FreePBX up to 16.0.46/17.0.29 Framework Restore.php runRestore improper authentication
A vulnerability classified as problematic was found in FreePBX up to 16.0.46/17.0.29. Impacted is the function runRestore of the file amp_conf/htdocs/admin/libraries/Builtin/Restore.php of the component Framework Module. Such manipulation l
CVE-2026-73663 | FreePBX up to 16.0.10/17.0.3 missedcall module missedcallnotify.php sql injection
A vulnerability, which was classified as critical, has been found in FreePBX up to 16.0.10/17.0.3. The affected element is an unknown function of the file agi-bin/missedcallnotify.php of the component missedcall module. Performing a manipul
CVE-2026-73656 | Triggerdotdev Trigger.dev up to 4.5.5 Background Worker Deployment Service createDeploymentBackgroundWorkerV4.server.ts CreateDeploymentBackgroundWorkerServiceV4.call privileges management
A vulnerability, which was classified as critical, has been found in Triggerdotdev Trigger.dev up to 4.5.5. Impacted is the function CreateDeploymentBackgroundWorkerServiceV4.call of the file apps/webapp/app/v3/services/createDeploymentBack
CVE-2026-73662 | FreePBX up to 17.0.6 Music on Hold Music.class.php validateCustomConfiguration os command injection
A vulnerability classified as problematic has been found in FreePBX up to 17.0.6. This issue affects the function validateCustomConfiguration of the file Music.class.php of the component Music on Hold. This manipulation causes os command in
CVE-2026-73421 | nextauthjs next-auth up to 5.0.0-beta.31 Session Parsing improper authorization
A vulnerability marked as critical has been reported in nextauthjs next-auth up to 5.0.0-beta.31. Affected by this vulnerability is the function auth of the component Session Parsing. The manipulation leads to improper authorization. This v
CVE-2026-20361 | Cisco Nexus Dashboard up to 4.2.1 sql injection (Nessus ID 348238)
A vulnerability has been found in Cisco Nexus Dashboard and classified as critical. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerability is referenced as CVE-2026-20361. Remote exploitatio
CVE-2026-20326 | Cisco Nexus Dashboard up to 4.2.1 missing authentication (Nessus ID 348238)
A vulnerability classified as very critical was found in Cisco Nexus Dashboard. This vulnerability affects unknown code. Such manipulation leads to missing authentication. This vulnerability is uniquely identified as CVE-2026-20326. The att
CVE-2026-20325 | Cisco Nexus Dashboard up to 4.2.1 command injection (Nessus ID 348238)
A vulnerability classified as very critical has been found in Cisco Nexus Dashboard. This affects an unknown part. This manipulation causes command injection. This vulnerability is handled as CVE-2026-20325. The attack can be initiated remo
CVE-2026-20322 | Cisco Nexus Dashboard up to 4.2.1 access control (Nessus ID 348238)
A vulnerability described as very critical has been identified in Cisco Nexus Dashboard. Affected by this issue is some unknown functionality. The manipulation results in improper access controls. This vulnerability is known as CVE-2026-203
CVE-2024-1086: Celah Keamanan Kernel Linux Berisiko Tinggi Akses Root
Apa itu CVE-2024-1086? CVE-2024-1086 adalah kerentanan keamanan kritis pada kernel Linux. Kerentanan ini sangat serius, memungkinkan penyerang lokal meningkatkan hak akses hingga tingkat root, mengambil alih kendali penuh sistem terinfeksi.
CVE-2026-59714 | open-webui Open WebUI Chat Completion API improper authorization
A vulnerability marked as critical has been reported in open-webui Open WebUI. The affected element is an unknown function of the component Chat Completion API. The manipulation leads to improper authorization. This vulnerability is referen
CVE-2026-45725 | oscal-compass compliance-trestle up to 3.12.1/4.0.2 Remote Fetching Cache Mechanism path traversal
A vulnerability classified as problematic was found in oscal-compass compliance-trestle up to 3.12.1/4.0.2. This impacts an unknown function of the component Remote Fetching Cache Mechanism. Such manipulation leads to path traversal. This v
CVE-2026-73655 | Trigger.dev up to 4.5.1 Google Authentication googleAuth.server.ts addGoogleStrategy improper authentication
A vulnerability marked as critical has been reported in Trigger.dev up to 4.5.1. Affected by this issue is the function addGoogleStrategy of the file apps/webapp/app/services/googleAuth.server.ts of the component Google Authentication. Perf
CVE-2026-73649 | shepherdwind Velocity.js up to 2.1.6 Property-Read Expressions references.ts getReferences os command injection
A vulnerability, which was classified as critical, was found in shepherdwind Velocity.js up to 2.1.6. This issue affects the function getReferences of the file src/compile/references.ts of the component Property-Read Expressions. Executing
CVE-2026-73644 | OpenIdentityPlatform OpenDJ up to 5.1.1 SASL PlainSASLMechanismHandler.java improper authorization
A vulnerability was found in OpenIdentityPlatform OpenDJ up to 5.1.1. It has been classified as very critical. The impacted element is an unknown function of the file opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASL
CVE-2026-45774 | oscal-compass compliance-trestle up to 3.12.1/4.0.2 Profile Import Mechanism resolve imports[].href path traversal
A vulnerability labeled as problematic has been found in oscal-compass compliance-trestle up to 3.12.1/4.0.2. Impacted is the function resolve of the component Profile Import Mechanism. Executing a manipulation of the argument imports[].hre