Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-86205 | h3js h3 up to 2.0.1-rc.17 Redirect Utility redirectBack (EUVD-2026-72105)
A vulnerability marked as problematic has been reported in h3js h3 up to 2.0.1-rc.17. The impacted element is the function redirectBack of the component Redirect Utility. Performing a manipulation results in open redirect. This vulnerabilit
CVE-2026-86252 | h3js h3 up to 1.15.8 injection (EUVD-2026-72108)
A vulnerability classified as problematic was found in h3js h3 up to 1.15.8. Affected is an unknown function. The manipulation results in injection. This vulnerability is known as CVE-2026-86252. It is possible to launch the attack remotely
CVE-2026-86251 | h3js h3 up to 1.15.8 serveStatic utility resolveDotSegments path traversal (EUVD-2026-72107)
A vulnerability classified as problematic has been found in h3js h3 up to 1.15.8. This impacts the function resolveDotSegments of the component serveStatic utility. The manipulation leads to path traversal. This vulnerability is traded as C
CVE-2026-86250 | h3js h3 up to 2.0.1-rc.17 Cookie setChunkedCookie/deleteChunkedCookie infinite loop (EUVD-2026-72106)
A vulnerability described as problematic has been identified in h3js h3 up to 2.0.1-rc.17. This affects the function setChunkedCookie/deleteChunkedCookie of the component Cookie Handler. Executing a manipulation can lead to infinite loop. T
CVE-2026-86253 | h3js h3 up to 1.15.5/2.0.1-rc.14 Static File Serving serveStatic path traversal (EUVD-2026-72109)
A vulnerability was found in h3js h3 up to 1.15.5/2.0.1-rc.14. It has been classified as problematic. Affected by this issue is the function serveStatic of the component Static File Serving. Performing a manipulation results in path travers
CVE-2026-86255 | wger-project wger up to 2.4 resource consumption (EUVD-2026-72111)
A vulnerability, which was classified as problematic, was found in wger-project wger up to 2.4. Affected by this issue is some unknown functionality. Such manipulation leads to resource consumption. This vulnerability is uniquely identified
CVE-2026-86254 | wger-project wger up to master wger/core/views/user.py is_same_gym authorization (EUVD-2026-72110)
A vulnerability, which was classified as problematic, has been found in wger-project wger up to master. Affected by this vulnerability is the function is_same_gym of the file wger/core/views/user.py. This manipulation causes authorization b
CVE-2026-86258 | Jupyter nbviewer up to 1.0.1 LocalFileHandler LocalFileHandler.can_show path traversal (EUVD-2026-72125)
A vulnerability marked as problematic has been reported in Jupyter nbviewer up to 1.0.1. Affected is the function LocalFileHandler.can_show of the component LocalFileHandler. The manipulation leads to path traversal. This vulnerability is d
CVE-2026-86257 | wger-project wger up to 2.5 TSV Export first_name/last_name injection (EUVD-2026-72113)
A vulnerability was found in wger-project wger up to 2.5 and classified as problematic. This vulnerability affects unknown code of the component TSV Export. Executing a manipulation of the argument first_name/last_name can lead to injection
CVE-2026-86256 | wger-project Wger up to 2.5.0 Impersonation wger/core/views/user.py trainer_login Next redirect (EUVD-2026-72112)
A vulnerability has been found in wger-project Wger up to 2.5.0 and classified as problematic. This affects the function trainer_login of the file wger/core/views/user.py of the component Impersonation. Performing a manipulation of the argu
CVE-2026-86213 | Mstfakts College-Management-System Search Front-end/university.php mysqli_query book_name/book_author sql injection (EUVD-2026-72127)
A vulnerability described as critical has been identified in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argu
CVE-2026-86259 | THU-MAIC OpenMAIC up to 1.0.0 baseUrl server-side request forgery (EUVD-2026-72126)
A vulnerability described as critical has been identified in THU-MAIC OpenMAIC up to 1.0.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument baseUrl results in server-side request forgery. This vu
CVE-2026-86214 | Mstfakts College-Management-System Front-end/login.php email improper authentication (EUVD-2026-72128)
A vulnerability classified as critical has been found in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. The identi
CVE-2026-19795 | IBM Qiskit SDK up to 2.5.1 deserialization
A vulnerability labeled as problematic has been found in IBM Qiskit SDK up to 2.5.1. Impacted is an unknown function. Executing a manipulation can lead to deserialization. This vulnerability is registered as CVE-2026-19795. The attack needs
CVE-2026-85241 | SpecterOps BloodHound up to 9.5.1 Graph Write Endpoint v2.go NewV2API improper authorization
A vulnerability, which was classified as critical, was found in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing
CVE-2026-85224 | D-Link DNS-320 ShareCenter 2.06B01 File Sharing /cgi/file_sharing.cgi fileurl os command injection (EUVD-2026-70768)
A vulnerability labeled as very critical has been found in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl ca
CVE-2026-85223 | D-Link DNS-340L 1.01B04 CGI /cgi-bin/dropbox.cgi callback_url/sync_interval os command injection
A vulnerability identified as very critical has been detected in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the a
CVE-2026-85208 | itsourcecode Online Medicine Delivery System 1.0 Order Management Controller controller.php?action=add doInsert image unrestricted upload
A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0 and classified as critical. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Manageme
Docker CVE-2026-34040: AuthZ-Bypass erlaubt Root-Container nach Größen-Check
LONDON (IT BOLTWISE) – Eine lang zurückliegende Schwachstelle im Docker Engine AuthZ-Middleware-Pfad ermöglicht nach aktueller Analyse einen Authentifizierungs-Umgehungsweg. Ein übergroßer API-Request wird vor dem Policy-Plugin abgeschnitte
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce
LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten
LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter
LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu
PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen
LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. The post CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft appeared firs
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung
Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thur
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap
[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service
Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen
WordPress: Super Forms und Elementor Pro von RCE-Angriffen betroffen
LONDON (IT BOLTWISE) – Angreifer nutzen zwei kritische Lücken in WordPress-Plugins, um ohne Anmeldung Dateien mit PHP-Inhalt hochzuladen und anschließend Remote Code Execution auszuführen. Laut Wordfence wurden bereits über 250.000 bzw. 190
[UPDATE] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C