🎯 CVE-2026-80491 HIGH 8.6 🔥 EPSS 23.2%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-80491: Schwachstellen-Eintrag (NVD)

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 🎯 High

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as…

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, consider using persistence layers such as Hibernate or Enterprise Java Beans, which can provide significant protection against SQL injection if used proper…
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.6
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Verändert
C · Vertraulichkeit Hoch
I · Integrität Keine
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Veröffentlicht:12.09.2026
Aktualisiert:12.09.2026 16:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 164 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.525 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-13
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Klimaanlage: Sicherheitslücke in Midea Portasplit wird geschlossen

Angreifer können die Klimaanlage Midea Portasplit ohne Anmeldung per Bluetooth steuern. Ein neues Firmware-Update korrigiert das. (Sicherheitslücke, Bluetooth) Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-87468 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87468 | Google Chrome up to 152.0.7977.82 Site Isolation improper authorization

A vulnerability labeled as critical has been found in Google Chrome. This impacts an unknown function of the component Site Isolation. The manipulation results in improper authorization. This vulnerability is cataloged as CVE-2026-87468. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-87493 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87493 | Google Chrome up to 152.0.7977.82 FileSystem authorization

A vulnerability was found in Google Chrome. It has been classified as critical. Impacted is an unknown function of the component FileSystem. Performing a manipulation results in missing authorization. This vulnerability is known as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2026-86808 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86808 | moltis-org moltis up to 20260818.10 vault.rs vault_unlock_handler/vault_recovery_handler missing authentication (Issue 1177)

A vulnerability classified as critical was found in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authenticatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-86083 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86083 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 Legacy Expression Engine isolated-vm-bridge.ts JSON.stringify code injection

A vulnerability was found in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. It has been declared as problematic. Impacted is the function JSON.stringify of the file @n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts of the component Legacy

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.4%
CVE-2026-86079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86079 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 Elasticsearch Nodes GenericFunctions.ts path traversal (WID-SEC-2026-3165)

A vulnerability described as critical has been identified in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. The affected element is an unknown function of the file packages/nodes-base/nodes/Elastic/Elasticsearch/GenericFunctions.ts of the compone

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-86082 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86082 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 OpenAI Chat Model Node loadModels.ts assertOpenAiCredentialAllowsUrl baseURL access control

A vulnerability marked as problematic has been reported in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. Impacted is the function assertOpenAiCredentialAllowsUrl of the file packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModel

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.9%
CVE-2026-86080 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86080 | n8n-io n8n up to 1.123.75/2.37.6/2.38.1 GitHub Trigger GithubTriggerHelpers.ts improper authentication

A vulnerability identified as critical has been detected in n8n-io n8n up to 1.123.75/2.37.6/2.38.1. This vulnerability affects unknown code of the file packages/nodes-base/nodes/Github/GithubTriggerHelpers.ts of the component GitHub Trigge

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2026-73313 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73313 | XenForo up to 2.3.12 Passkey TFA Provider improper authentication

A vulnerability identified as critical has been detected in XenForo up to 2.3.12. This issue affects some unknown processing of the component Passkey TFA Provider. The manipulation leads to improper authentication. This vulnerability is doc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.9%
CVE-2026-9215 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9215 | NETGEAR XR1000/XR1000v2/XR500 cross-site request forgery (EUVD-2026-73163)

A vulnerability classified as problematic has been found in NETGEAR XR1000, XR1000v2 and XR500. This vulnerability affects unknown code. Performing a manipulation results in cross-site request forgery. This vulnerability is reported as CVE-

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.8%
CVE-2026-86672 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86672 | ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf Backup example.7z information disclosure (Issue 14)

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. It has been classified as problematic. Affected is an unknown function of the file example.7z of the component Backup Handler.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2026-86674 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86674 | ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf login.php session_start session fixiation (Issue 16)

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. It has been declared as critical. Affected by this vulnerability is the function session_start of the file login.php. The mani

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.1%
CVE-2026-86668 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86668 | aircheng-org iWebShop-5 up to 5.15 controllers/pic.php uploadFile outerSrc/selectPhoto cross site scripting

A vulnerability, which was classified as problematic, was found in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto l

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.3%
CVE-2026-9216 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9216 | NETGEAR RAX30/RAX35/RAX38/RAX40/RAXE300 Management UI stack-based overflow

A vulnerability has been found in NETGEAR RAX30, RAX35, RAX38, RAX40 and RAXE300 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Management UI. This manipulation causes stack-based buf

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-28606 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28606 | Google Android 15/16/16-qpr2/17 Pairing AdapterService.java handleBondStateChanged privileges management

A vulnerability, which was classified as very critical, has been found in Google Android 15/16/16-qpr2/17. This vulnerability affects the function handleBondStateChanged of the file AdapterService.java of the component Pairing. The manipula

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.1%
CVE-2026-86074 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86074 | n8n-io n8n up to 2.37.6/2.38.1 Instance AI Credential Setup credential-utils.ts redirect (WID-SEC-2026-3165)

A vulnerability was found in n8n-io n8n up to 2.37.6/2.38.1. It has been classified as problematic. Affected is an unknown function of the file packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts of the component Instance AI C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-86073 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86073 | n8n-io n8n up to 2.37.6/2.38.0 OAuth Token Endpoint improper authorization

A vulnerability was found in n8n-io n8n up to 2.37.6/2.38.0. It has been classified as problematic. Impacted is an unknown function of the component OAuth Token Endpoint. This manipulation causes improper authorization. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-73310 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73310 | XenForo up to 2.3.12 OAuth2 Token Endpoint improper authorization

A vulnerability was found in XenForo up to 2.3.12 and classified as problematic. Affected is an unknown function of the component OAuth2 Token Endpoint. The manipulation results in improper authorization. This vulnerability is identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-73309 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73309 | XenForo up to 2.3.12 OAuth2 Token Endpoint client_secret/code_verifier improper authorization

A vulnerability, which was classified as critical, was found in XenForo up to 2.3.12. This affects an unknown function of the component OAuth2 Token Endpoint. Executing a manipulation of the argument client_secret/code_verifier can lead to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2026-86804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86804 | seakee CPA-Manager-Plus up to 1.11.10 HTTP handler.go CPAResource improper authorization

A vulnerability marked as problematic has been reported in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.5%
CVE-2026-80958 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80958 | Linux Kernel up to 6.18.49/7.2.3 dm-pcache cache_replay out-of-bounds

A vulnerability described as problematic has been identified in Linux Kernel up to 6.18.49/7.2.3. This vulnerability affects the function cache_replay of the component dm-pcache. Such manipulation leads to out-of-bounds read. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18%
CVE-2026-80954 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80954 | Linux Kernel up to 7.2.3 i3c i3c_device_get_supported_xfer_mode null pointer dereference

A vulnerability described as very critical has been identified in Linux Kernel up to 7.2.3. Affected by this vulnerability is the function i3c_device_get_supported_xfer_mode of the component i3c. The manipulation results in null pointer der

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.5%
CVE-2026-80953 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80953 | Linux Kernel up to 6.18.49/7.2.3 i3c adi_i3c_master_probe race condition (Nessus ID 345376)

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.49/7.2.3. Affected is the function adi_i3c_master_probe of the component i3c. The manipulation leads to race condition. This vulnerability is referenced as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.3%
CVE-2026-80950 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80950 | Linux Kernel up to 6.18.49/7.2.3 I3C Driver use after free

A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.49/7.2.3. This affects an unknown function of the component I3C Driver. Performing a manipulation results in use after free. This vulnerability was nam

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.5%
CVE-2026-80945 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80945 | Linux Kernel up to 6.18.50/7.2.3 iaa iaa_comp_adecompress buffer overflow

A vulnerability was found in Linux Kernel up to 6.18.50/7.2.3. It has been declared as very critical. Impacted is the function iaa_comp_adecompress of the component iaa. The manipulation results in buffer overflow. This vulnerability is kno

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.4%
CVE-2026-80943 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80943 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 rtlwifi rtl92du_tx_fill_desc tids out-of-bounds

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. This vulnerability affects the function rtl92du_tx_fill_desc of the component rtlwifi. Executing a manipulation of the argument tids can lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.2%
CVE-2026-80937 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80937 | Linux Kernel up to 6.18.49/7.2.3 mt7915 mt7915_mcu_get_eeprom addr out-of-bounds write

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.49/7.2.3. This issue affects the function mt7915_mcu_get_eeprom of the component mt7915. This manipulation of the argument addr causes out-of-bounds write.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.9%
CVE-2026-80952 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80952 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 i3c i3c_master_unregister_i3c_devs information disclosure

A vulnerability described as problematic has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function i3c_master_unregister_i3c_devs of the component i3c. Executing a manipulation can lead to information discl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30%
CVE-2026-80955 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80955 | Linux Kernel up to 6.18.49/7.2.3 dm-pcache kset_replay seg_gen use after free

A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. This impacts the function kset_replay of the component dm-pcache. The manipulation of the argument seg_gen leads to use after free. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.7%
CVE-2026-80947 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80947 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 rtl8xxxu rtl8xxxu_rx_urb_work use after free

A vulnerability identified as very critical has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Impacted is the function rtl8xxxu_rx_urb_work of the component rtl8xxxu. This manipulation causes use after free. The identification

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 5.9%
CVE-2026-12706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8750-1: FFmpeg vulnerabilities

Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-12706) Xingha

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 5.9%
CVE-2026-12706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8750-1: FFmpeg vulnerabilities

Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-12706) Xingha

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.8%
CVE-2026-80980 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80980 | Linux Kernel up to 6.18.49/7.2.3 SMC Connection smc_cdc_msg_validate race condition (Nessus ID 345372)

A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. This affects the function smc_cdc_msg_validate of the component SMC Connection. Such manipulation leads to race condition. This vulnerability is tr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.9%
CVE-2026-89629 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89629 | Linux Kernel up to 6.18.49/7.2.3 HID/corsair-void out-of-bounds (Nessus ID 345373)

A vulnerability classified as problematic has been found in Linux Kernel up to 6.18.49/7.2.3. Affected by this issue is some unknown functionality of the component HID/corsair-void. Performing a manipulation results in out-of-bounds read. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.2%
CVE-2026-89542 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89542 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SUNRPC gss_krb5_unwrap_v2 out-of-bounds (Nessus ID 345375)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function gss_krb5_unwrap_v2 of the component SUNRPC. Executing a manipulation can lead to out-of-bounds read. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.2%
CVE-2026-89651 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89651 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Ceph handle_session out-of-bounds (Nessus ID 345379)

A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The impacted element is the function handle_session of the component Ceph. The manipulation leads to out-of-bounds read. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.2%
CVE-2026-89665 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89665 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 NFSv2 Decoder fs/nfs/nfs2xdr.c svcxdr_decode_sattr useconds integer overflow (Nessus ID 345378)

A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Impacted is the function svcxdr_decode_sattr of the file fs/nfs/nfs2xdr.c of the component NFSv2 Decoder. Executing a manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.1%
CVE-2026-89585 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89585 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 charlcd charlcd.c charlcd_init use after free (Nessus ID 345377)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. Impacted is the function charlcd_init of the file charlcd.c of the component charlcd. Performing a manipulation results in use after

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.6%
CVE-2026-80997 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80997 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 IPA Modem TX Queue ipa_start_xmit race condition (Nessus ID 345381)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function ipa_start_xmit of the component IPA Modem TX Queue. This manipulation causes race condition. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.5%
CVE-2026-89732 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89732 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 f_fs ffs_ep0_read locking (Nessus ID 345380)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. The impacted element is the function ffs_ep0_read of the component f_fs. The manipulation leads to improper locking. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.3%
CVE-2026-80991 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80991 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ravb ravb_ptp_interrupt use after free (Nessus ID 345383)

A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This issue affects the function ravb_ptp_interrupt of the component ravb. This manipulation causes use after free. The identificati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.6%
CVE-2026-89266 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89266 | nothings stb_vorbis up to 1.22 start_decoder heap-based overflow (Nessus ID 345382)

A vulnerability has been found in nothings stb_vorbis up to 1.22 and classified as critical. Affected by this issue is the function start_decoder. Performing a manipulation results in heap-based buffer overflow. This vulnerability is catalo

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.5%
CVE-2026-80932 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80932 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Vsock Virtio virtio_vsock_remove use after free

A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This vulnerability affects the function virtio_vsock_remove of the component Vsock Virtio. This manipulation causes use after free. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.4%
CVE-2026-80936 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80936 | Linux Kernel up to 6.18.49/7.2.3 mt7925 kernel/workqueue.c mt792x_stop use after free

A vulnerability labeled as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. This vulnerability affects the function mt792x_stop of the file kernel/workqueue.c of the component mt7925. The manipulation results in use after f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.1%
CVE-2026-80933 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80933 | Linux Kernel up to 6.18.49/7.2.3 mt7996 buffer overflow

A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been rated as very critical. Affected by this vulnerability is an unknown functionality of the component mt7996. Performing a manipulation results in buffer overflow. Thi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.5%
CVE-2026-80931 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80931 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 w1 w1_f19_i2c_master_transfer buffer overflow

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been declared as very critical. Affected is the function w1_f19_i2c_master_transfer of the component w1. Such manipulation leads to buffer overflow. This vulnera

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.2%
CVE-2026-80928 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80928 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 smack smack_file_send_sigiotask use after free

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This affects the function smack_file_send_sigiotask of the component smack. The manipulation results in use after free. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.4%
CVE-2026-80929 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80929 | Linux Kernel up to 6.18.49/7.2.3 sysctl pid_table_root_permissions privileges management

A vulnerability described as very critical has been identified in Linux Kernel up to 6.18.49/7.2.3. This affects the function pid_table_root_permissions of the component sysctl. The manipulation results in improper privilege management. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.5%
CVE-2026-79742 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79742 | IBM Langflow OSS up to 1.11.5 code injection

A vulnerability has been found in IBM Langflow OSS up to 1.11.5 and classified as critical. This vulnerability affects unknown code. The manipulation leads to code injection. This vulnerability is documented as CVE-2026-79742. The attack ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.1%
CVE-2026-80926 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80926 | Linux Kernel up to 6.18.50/7.2.4/7.3-rc1 ksmbd smb2_oplock_break_noti use after free

A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.50/7.2.4/7.3-rc1. This issue affects the function smb2_oplock_break_noti of the component ksmbd. The manipulation leads to use after free. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.9%
CVE-2026-52295 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52295 | FFmpeg 7.0 libavformat-iamf_writer.c buffer overflow

A vulnerability was found in FFmpeg 7.0. It has been classified as problematic. Impacted is an unknown function of the file libavformat/iamf_writer.c of the component libavformat-iamf_writer.c. The manipulation leads to buffer overflow. Thi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.8%
CVE-2026-89610 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89610 | Linux Kernel NTFS memory corruption (Nessus ID 345384)

A vulnerability identified as very critical has been detected in Linux Kernel. The impacted element is an unknown function of the component NTFS. Performing a manipulation results in memory corruption. This vulnerability is known as CVE-202

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.9%
CVE-2026-79515 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79515 | Nothings stb stbtt_GetGlyphShape out-of-bounds (31c1ad3 / Nessus ID 345385)

A vulnerability classified as problematic has been found in Nothings stb. This impacts the function stbtt_GetGlyphShape. Performing a manipulation results in out-of-bounds read. This vulnerability was named CVE-2026-79515. The attack may be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24%
CVE-2026-89734 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89734 | Linux Kernel up to 6.18.49/7.2.3 UVC uvcg_video_init null pointer dereference (Nessus ID 345386)

A vulnerability classified as very critical has been found in Linux Kernel up to 6.18.49/7.2.3. Impacted is the function uvcg_video_init of the component UVC. This manipulation causes null pointer dereference. This vulnerability appears as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.4%
CVE-2026-89473 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89473 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 bq25890 bq25890_fw_probe denial of service (Nessus ID 345387)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. Affected by this issue is the function bq25890_fw_probe of the component bq25890. Such manipulation leads to denial of service. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.3%
CVE-2019-9494 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2019-9494 | hostapd/wpa_supplicant up to 2.7 SAE information disclosure (SA_19_16 / Nessus ID 345520)

A vulnerability identified as problematic has been detected in hostapd and wpa_supplicant up to 2.7. This affects an unknown function of the component SAE. This manipulation causes information disclosure. This vulnerability is handled as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.2%
CVE-2025-55763 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8749-1: CivetWeb vulnerabilities

It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 2.2%
CVE-2025-55763 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

USN-8749-1: CivetWeb vulnerabilities

It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.8%
CVE-2026-69414 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity

... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
5.8 MEDIUM
EPSS 3.7%
CVE-2026-42533 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

DSA-6496-1 nginx - security update

Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code. CVE-2026-42533 A heap buffer overfl

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.