🎯 CVE-2026-82764 MEDIUM 4.3 🔥 EPSS 3.6%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-82764: Schwachstellen-Eintrag (NVD)

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 🎯 High

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and …
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 4.3
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Erforderlich
S · Scope Unverändert
C · Vertraulichkeit Keine
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Veröffentlicht:14.09.2026
Aktualisiert:14.09.2026 12:17
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
9 🔴 Critical im Radar
9 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
9 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 145 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.506 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-15
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
9.8 CRITICAL
⚠️ KEV
EPSS 94.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges

Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel &amp;amp; WHM on Linux. The company confirmed that attackers have already exploited this flaw

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

OPSWAT researchers find two zero-days in TP-Link cameras Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 30.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation. The post Acronis Patches Exploited Vulnerability in cPanel Backup Plugin appeared first on SecurityWeek. Weiterlesen

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 88.7%
CVE-2026-58704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Android 0-day Vulnerability on Google Pixel Devices Actively Exploited in Attacks

Google has confirmed that a high-severity Android zero-day flaw affecting its Pixel smartphones is being actively exploited in the wild, and it has shipped emergency patches as part of the September 2026 Pixel Update Bulletin. Tracked as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 94.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns. “Exploitation of this vul

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 25.1%
CVE-2026-23980 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

Apache Superset SQL Injection Flaw Gets Public PoC Exploit

A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running versions earlier than 6.0.0. The Apache Superset project disclosed this issue in February.

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 88.7%
CVE-2026-58704 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google patches Pixel modem zero-day exploited in targeted attacks

Google has fixed a high-severity Pixel modem vulnerability that may already have been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw was fixed as part of the September 2026 Pixel security update, which brings su

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-73454 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73454 | Arista EOS up to 4.36.0.1F gRPC Network Security Interface privileges management (EUVD-2026-80253)

A vulnerability categorized as critical has been discovered in Arista EOS up to 4.36.0.1F. This impacts an unknown function of the component gRPC Network Security Interface. The manipulation results in improper privilege management. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2026-73439 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73439 | Arista EOS up to 4.33.8M/4.34.6M/4.35.5M/4.36.0.1F gNSI Pathz Policy Enforcement privileges management (EUVD-2026-80252)

A vulnerability was found in Arista EOS up to 4.33.8M/4.34.6M/4.35.5M/4.36.0.1F. It has been declared as very critical. The impacted element is an unknown function of the component gNSI Pathz Policy Enforcement. Executing a manipulation can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.5%
CVE-2026-89186 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89186 | ZenHive mpp up to 0.16.1 lib/mpp/plug.ex MPP.Plug.verify_credential information disclosure (EUVD-2026-80254)

A vulnerability was found in ZenHive mpp up to 0.16.1. It has been rated as problematic. This affects the function MPP.Plug.verify_credential of the file lib/mpp/plug.ex. The manipulation leads to information disclosure. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-89774 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89774 | Linux Kernel up to 6.18.39 Bluetooth sco_conn_ready sk use after free (EUVD-2026-80255)

A vulnerability was found in Linux Kernel up to 5.15.211/6.1.177/6.6.144/6.12.96/6.18.39 and classified as very critical. Impacted is the function sco_conn_ready of the component Bluetooth. Such manipulation of the argument sk leads to use

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27%
CVE-2026-88255 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-88255 | ZenHive mpp up to 0.16.1 Duplicate Submission Gate lib/mpp/replay.ex reserve_hash_atomic input validation (EUVD-2026-80256)

A vulnerability was found in ZenHive mpp up to 0.16.1. It has been classified as problematic. The affected element is the function reserve_hash_atomic of the file lib/mpp/replay.ex of the component Duplicate Submission Gate. Performing a ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 23.7%
CVE-2026-90894 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Apple

Parallels Desktop Vulnerability Lets Non-Admin Mac Users Execute Code as Root

A critical local privilege escalation vulnerability in Parallels Desktop for Mac could allow a non-administrator user or unprivileged process to execute attacker-controlled code with root privileges. Tracked as CVE-2026-90894 and called “Pa

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-90894 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access

A critical local privilege-escalation vulnerability in Parallels Desktop for Mac could allow an unprivileged local user to execute attacker-controlled code with root privileges, placing developer workstations and shared macOS systems at ris

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 94.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

Acronis Backup Plugin Vulnerability in cPanel and Plesk Exploited in the Wild

Acronis has released security updates for its Backup plugin for cPanel &amp;amp; WHM and Backup extension for Plesk after identifying limited, targeted exploitation of a high-severity local privilege-escalation vulnerability in the wild. Tr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 25.1%
CVE-2026-23980 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Apache

PoC Exploit Released for Apache Superset SQL Injection Vulnerability

A public proof-of-concept (PoC) exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset versions prior to 6.0.0. The vulnerability could enable authenticated users with read-level permissions to

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 27%
CVE-2026-5430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.9%
CVE-2024-44981 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44981 | Linux Kernel up to 6.10.6 workqueue shift_and_mask denial of service (90a6a844b2d9/38f7e14519d3 / WID-SEC-2024-2057)

A vulnerability classified as problematic has been found in Linux Kernel up to 6.10.6. The impacted element is the function shift_and_mask of the component workqueue. The manipulation leads to denial of service. This vulnerability is traded

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.3%
CVE-2024-44980 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44980 | Linux Kernel up to 6.10.6 DRM memory leak (f7ecdd9853dd/f4b2a0ae1a31 / Nessus ID 212724)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.10.6. This impacts an unknown function of the component DRM. This manipulation causes memory leak. This vulnerability is handled as CVE-2024-44980. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21%
CVE-2024-44979 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44979 | Linux Kernel up to 6.10.6 DRM xe_gt_pagefault memory leak (b09ef3b762a7/a6f78359ac75 / Nessus ID 212724)

A vulnerability described as problematic has been identified in Linux Kernel up to 6.10.6. The affected element is the function xe_gt_pagefault of the component DRM. Executing a manipulation can lead to memory leak. This vulnerability appea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.7%
CVE-2024-44977 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44977 | Linux Kernel up to 6.1.106/6.6.47/6.10.6 AMD GPU out-of-bounds write (Nessus ID 208099 / WID-SEC-2024-2057)

A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.106/6.6.47/6.10.6. Impacted is an unknown function of the component AMD GPU. Performing a manipulation results in out-of-bounds write. This vulnerability is repo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.6%
CVE-2024-44978 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44978 | Linux Kernel up to 6.10.6 DRM xe_exec_queue_put use after free (98aa0330f200/9e7f30563677 / Nessus ID 212724)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.10.6. This affects the function xe_exec_queue_put of the component DRM. The manipulation results in use after free. This vulnerability is cataloged as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 4.7%
CVE-2024-44976 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44976 | Linux Kernel up to 6.10.6 DMA Table drivers/ata/pata_macio.c denial of service (709e4c8f78e1/822c8020aebc / WID-SEC-2024-2057)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.10.6. This issue affects some unknown processing of the file drivers/ata/pata_macio.c of the component DMA Table Handler. Such manipulation leads to denial of servic

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 5.6%
CVE-2024-44973 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44973 | Linux Kernel up to 6.10.4 mm/slub.c do_slab_free denial of service (b35cd7f1e969/a371d558e6f3 / Nessus ID 212724)

A vulnerability was found in Linux Kernel up to 6.10.4. It has been rated as problematic. This impacts the function do_slab_free of the file mm/slub.c. Performing a manipulation results in denial of service. This vulnerability is cataloged

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.2%
CVE-2024-44972 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44972 | Linux Kernel up to 6.6.45/6.10.4 btrfs extent_write_locked_range buffer overflow (ba4dedb71356/d3b403209f76/97713b1a2ced / Nessus ID 212724)

This issue looks like a false-positive. Please review the listed sources and think about not using this entry. Weiterlesen

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 25.1%
CVE-2026-23980 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Apache

Public PoC Released for Apache Superset SQL Injection Vulnerability

A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset versions before 6.0.0. The flaw could allow authenticated users with read-level access to trigger error-based SQ

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 94.3%
CVE-2026-87886 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild

Acronis has released security updates for its Backup plugin for cPanel &amp;amp; WHM and Backup extension for Plesk after detecting limited, targeted exploitation of a high-severity local privilege-escalation vulnerability in the wild. Trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

September-Updates schließen 180 Sicherheitslücken in Android – Pixel Update stopft 0-Day-Lücke

Mit dem Android Security Bulletin für September 2026 dokumentiert Google die Schwachstellen des Mobilbetriebssystems, die dessen Entwickler in den offenliegenden Quelltexten beseitigt haben. Üblicherweise geschieht dies am ersten Montag des

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

September-Updates schließen 180 Sicherheitslücken in Android – Pixel Update stopft 0-Day-Lücke

Mit dem Android Security Bulletin für September 2026 dokumentiert Google die Schwachstellen des Mobilbetriebssystems, die dessen Entwickler in den offenliegenden Quelltexten beseitigt haben. Üblicherweise geschieht dies am ersten Montag des

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-28616 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28616 | Google Android Setup Wizard privileges management

A vulnerability was found in Google Android. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Setup Wizard. This manipulation causes improper privilege management. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.8%
CVE-2026-28612 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28612 | Google Android 16/16-qpr2/17 ActivityStarter ActivityStarter.java resolveActivity redirect

A vulnerability identified as problematic has been detected in Google Android 16/16-qpr2/17. This vulnerability affects the function resolveActivity of the file ActivityStarter.java of the component ActivityStarter. Performing a manipulatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.3%
CVE-2026-28609 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28609 | Google Android 14/15/16/16-qpr2 MatroskaExtractor.cpp out-of-bounds write

A vulnerability classified as very critical has been found in Google Android 14/15/16/16-qpr2. Affected by this issue is some unknown functionality of the file MatroskaExtractor.cpp. Performing a manipulation results in out-of-bounds write.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-28604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28604 | Google Android up to 17 use after free

A vulnerability classified as very critical was found in Google Android 14/15/16/16-qpr2/17. This affects an unknown part. Executing a manipulation can lead to use after free. The identification of this vulnerability is CVE-2026-28604. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2026-28620 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28620 | Google Android 16/16-qpr2/17 privileges management

A vulnerability described as very critical has been identified in Google Android 16/16-qpr2/17. The affected element is an unknown function. The manipulation results in improper privilege management. This vulnerability is known as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-28614 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28614 | Google Android up to 17 SlicePermissionActivity SlicePermissionActivity.java onCreate privileges management

A vulnerability marked as problematic has been reported in Google Android 14/15/16/16-qpr2/17. Impacted is the function onCreate of the file SlicePermissionActivity.java of the component SlicePermissionActivity. The manipulation leads to im

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-28613 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28613 | Google Android up to 17 ChannelImpl ChannelImpl.java initAppLinkTypeAndIntent input validation

A vulnerability labeled as critical has been found in Google Android 14/15/16/16-qpr2/17. This issue affects the function initAppLinkTypeAndIntent of the file ChannelImpl.java of the component ChannelImpl. Executing a manipulation can lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-28617 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28617 | Google Android 15/16/16-qpr2/17 WifiNetworkSuggestionsManager WifiNetworkSuggestionsManager.java resource consumption

A vulnerability categorized as problematic has been discovered in Google Android 15/16/16-qpr2/17. This affects an unknown part of the file WifiNetworkSuggestionsManager.java of the component WifiNetworkSuggestionsManager. Such manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-28618 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28618 | Google Android 16/16-QPR2/17 oapv.c dec_frm_prepare heap-based overflow

A vulnerability was found in Google Android 16/16-QPR2/17. It has been classified as very critical. Affected is the function dec_frm_prepare of the file oapv.c. The manipulation leads to heap-based buffer overflow. This vulnerability is lis

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.6%
CVE-2026-28611 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28611 | Google Android 15/16 NFC Payment Session NfcService.java privileges management

A vulnerability has been found in Google Android 15/16 and classified as very critical. This affects an unknown function of the file NfcService.java of the component NFC Payment Session. Performing a manipulation results in improper privile

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-28607 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28607 | Google Android 15/16/16-qpr2/17 privileges management

A vulnerability, which was classified as very critical, was found in Google Android 15/16/16-qpr2/17. The impacted element is an unknown function. Such manipulation leads to improper privilege management. This vulnerability is referenced as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.1%
CVE-2026-28603 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28603 | Google Android up to 17 AppRestrictionsFragment.java assertSafeToStartCustomActivity privileges management

A vulnerability, which was classified as problematic, has been found in Google Android 14/15/16/16-qpr2/17. The affected element is the function assertSafeToStartCustomActivity of the file AppRestrictionsFragment.java. This manipulation cau

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.4%
CVE-2026-28596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-28596 | Google Android 14/15/16/16-qpr2 GameManagerService.java parseInterventionFromXml resource consumption

A vulnerability was found in Google Android 14/15/16/16-qpr2. It has been classified as problematic. The impacted element is the function parseInterventionFromXml of the file GameManagerService.java. Performing a manipulation results in res

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 24.4%
CVE-2022-44139 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44139 | oretnom23 Apartment Visitor Management System 1.0 /avms/index.php sql injection (EUVD-2022-47089)

A vulnerability was found in oretnom23 Apartment Visitor Management System 1.0. It has been rated as critical. Impacted is an unknown function of the file /avms/index.php. Performing a manipulation results in sql injection. This vulnerabili

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 22.9%
CVE-2022-44137 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44137 | SourceCodester Sanitization Management System 1.0 sql injection (EUVD-2022-47087)

A vulnerability was found in SourceCodester Sanitization Management System 1.0. It has been rated as critical. Impacted is an unknown function. Performing a manipulation results in sql injection. This vulnerability is known as CVE-2022-4413

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 27.7%
CVE-2022-44120 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44120 | dedecmdv6 6.1.9 sys_sql_query.php sql injection (EUVD-2022-47071)

A vulnerability classified as critical has been found in dedecmdv6 6.1.9. The affected element is an unknown function of the file sys_sql_query.php. This manipulation causes sql injection. This vulnerability is tracked as CVE-2022-44120. Th

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29.2%
CVE-2022-44118 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44118 | dedecmdv6 6.1.9 file_manage_control.php privilege escalation (EUVD-2022-47069)

A vulnerability labeled as critical has been found in dedecmdv6 6.1.9. This vulnerability affects unknown code of the file file_manage_control.php. Executing a manipulation can lead to privilege escalation. The identification of this vulner

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2022-44109 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44109 | pdftojson 94204bb Stream::makeFilter stack-based overflow (EUVD-2022-47060)

A vulnerability was found in pdftojson 94204bb. It has been declared as critical. Affected by this vulnerability is the function Stream::makeFilter. The manipulation results in stack-based buffer overflow. This vulnerability was named CVE-2

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2022-44108 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44108 | pdftojson 94204bb Object.cc Object::copy(Object*) stack-based overflow (EUVD-2022-47059)

A vulnerability was found in pdftojson 94204bb. It has been classified as critical. Affected is the function Object::copy(Object*) of the file Object.cc. The manipulation leads to stack-based buffer overflow. This vulnerability is uniquely

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.8%
CVE-2022-44097 💻 Lokal 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2022-44097 | Book Store Management System 1.0 Admin Panel hard-coded credentials (EUVD-2022-47048)

A vulnerability has been found in Book Store Management System 1.0 and classified as critical. This issue affects some unknown processing of the component Admin Panel. Performing a manipulation results in hard-coded credentials. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.3 HIGH
🇪🇺 EUVD
EPSS 22.1%
CVE-2026-75757 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 ash-project

CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE

Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82605 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.

A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 6.7%
CVE-2026-82604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
BareBones

CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.

A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.2%
CVE-2026-82603 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 n/a

CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.

A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
🇪🇺 EUVD
EPSS 4.8%
CVE-2026-82602 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 3.8%
CVE-2026-82601 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 23.5%
CVE-2026-75760 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
🇪🇺 EUVD
EPSS 4.9%
CVE-2026-82580 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.0 MEDIUM
🇪🇺 EUVD
EPSS 5.2%
CVE-2026-82579 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul

Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.1 HIGH
🇪🇺 EUVD
EPSS 20.8%
CVE-2026-82564 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
🧪 ash-project

CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression

Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.9 MEDIUM
🇪🇺 EUVD
EPSS 5.2%
CVE-2026-82600 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
🧪 n/a

CVE-2026-82600 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.