🎯 CVE-2026-83970 HIGH 7.8 🔥 EPSS 26.5%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-83970: Schwachstellen-Eintrag (NVD)

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Klassifikation & Betroffenheit:
microsoft windows_10_1607 *microsoft windows_10_1809 *microsoft windows_10_21h2 *microsoft windows_10_22h2 *microsoft windows_11_23h2 *microsoft windows_11_24h2 *microsoft windows_11_25h2 *microsoft windows_11_26h1 *
Improper Restriction of Operations within the Bounds of a Memory Buffer 🎯 High

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

🛡️ Empfohlene Mitigation: Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. For example, many languages that perform their own memory management, such as Java and Perl, are not subject to buffer overflows. Other languages, such as Ada and C#, typically provide overflow prot…
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.8
AV · Angriffsvektor Lokal
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:08.09.2026
Aktualisiert:12.09.2026 04:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 145 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.506 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-15
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
3.1 LOW
EPSS 2.8%
CVE-2026-49869 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869 CVE-2026-49869 is an authentication bypass in Kestra OSS that escalates to unauthenticated remote code execution, rated Critical at CVSS 3.1 10.0 and

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2026-75015 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-75015 | Apache Syncope missing encryption (CNNVD-2026-93574773)

A vulnerability was found in Apache Syncope. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to missing encryption of sensitive data. This vulnerability is handled as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 18.1%
CVE-2022-44031 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44031 | Redmine up to 4.2.8/5.0.3 Textile Formatter cross site scripting (EUVD-2022-46993 / Nessus ID 257919)

A vulnerability identified as problematic has been detected in Redmine up to 4.2.8/5.0.3. The affected element is an unknown function of the component Textile Formatter. This manipulation causes cross site scripting. This vulnerability is t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2022-44030 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44030 | Redmine up to 5.0.3 permission (EUVD-2022-46992)

A vulnerability was found in Redmine up to 5.0.3. It has been rated as critical. This affects an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2022-44030. The attack is only possible with

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25%
CVE-2022-44029 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44029 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46991)

A vulnerability identified as problematic has been detected in NetScout nGeniusONE up to 6.3.2 P9. This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulnerability is documented as CVE-2022-4402

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2022-44028 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44028 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46990)

A vulnerability was found in NetScout nGeniusONE up to 6.3.2 P9. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability is cataloged as CVE-2022-44028. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-92298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92298 | EspoCRM up to 10.0.8 rand random values (EUVD-2026-80078)

A vulnerability classified as problematic has been found in EspoCRM up to 10.0.8. This affects the function rand. Performing a manipulation results in insufficiently random values. This vulnerability is cataloged as CVE-2026-92298. It is po

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-92216 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92216 | a2ui-project a2ui up to 0.10.7 Binder generic-binder.ts openUrl redirect (Issue 2296 / EUVD-2026-80077)

A vulnerability classified as problematic was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-92299 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92299 | Jitsi Electron SDK up to 10.0.4 Screen Sharing IPC Route getDesktopSources permission (EUVD-2026-80079)

A vulnerability classified as problematic was found in Jitsi Electron SDK up to 10.0.4. This impacts the function getDesktopSources of the component Screen Sharing IPC Route. Executing a manipulation can lead to permission issues. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.2%
CVE-2026-92220 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92220 | vllm-project vLLM 0.26.0/0.27.0 MoRIIO Acknowledgement moriio_connector.py request_id/kv_transfer_params resource consumption (ID 50674 / EUVD-2026-80081)

A vulnerability identified as problematic has been detected in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-92217 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92217 | a2ui-project a2ui up to 0.10.6 Message Parsing message-processor.ts processMessages dynamically-determined object attributes (Issue 2297 / EUVD-2026-80080)

A vulnerability, which was classified as critical, has been found in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20.6%
CVE-2026-92221 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92221 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 app_global_admin_model.php generate_index_pasien cari sql injection (EUVD-2026-80082)

A vulnerability labeled as problematic has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-73450 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73450 | Arista EOS up to 4.36.1F state issue (EUVD-2026-80083)

A vulnerability was found in Arista EOS up to 4.32.x/4.33.9M/4.34.7.1M/4.35.5M/4.36.1F and classified as critical. Impacted is an unknown function. Executing a manipulation can lead to state issue. This vulnerability appears as CVE-2026-734

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.1%
CVE-2026-84961 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84961 | undici up to 7.29.0/8.10.1 BalancedPool BalancedPool constructor connect/tls certificate validation

A vulnerability marked as problematic has been reported in undici up to 7.29.0/8.10.1. Affected by this issue is the function BalancedPool constructor of the component BalancedPool. Performing a manipulation of the argument connect/tls resu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-2026-85014 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85014 | undici up to 7.29.0/8.10.1 Socket Close denial of service

A vulnerability labeled as problematic has been found in undici up to 7.29.0/8.10.1. Affected by this vulnerability is an unknown functionality of the component Socket Close Handler. Such manipulation leads to denial of service. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32%
CVE-2026-84947 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84947 | Node.js Undici up to 7.29.0/8.10.1 Dump Interceptor input validation (EUVD-2026-71517)

A vulnerability categorized as problematic has been discovered in Node.js Undici up to 7.29.0/8.10.1. The affected element is an unknown function of the component Dump Interceptor. Executing a manipulation can lead to improper input validat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-79418 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79418 | EMX Tecnologia Gestao X up to 8.4 Help Chat cross site scripting

A vulnerability was found in EMX Tecnologia Gestao X up to 8.4. It has been declared as problematic. This impacts an unknown function of the component Help Chat. The manipulation results in cross site scripting. This vulnerability is known

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.2%
CVE-2026-84657 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84657 | Jenkins up to 2.567.x CLI permission

A vulnerability has been found in Jenkins up to 2.567.x and classified as problematic. Impacted is an unknown function of the component CLI. Performing a manipulation results in permission issues. This vulnerability is known as CVE-2026-846

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-3416 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-3416 | WSO2 API Manager/API Control Plane API Publisher random values

A vulnerability was found in WSO2 API Manager and API Control Plane. It has been rated as problematic. The impacted element is an unknown function of the component API Publisher. The manipulation leads to insufficiently random values. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18%
CVE-2026-84655 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84655 | Jenkins Project up to 2.567.x REST API injection

A vulnerability classified as very critical was found in Jenkins Project Jenkins up to 2.567.x. Affected is an unknown function of the component REST API. Executing a manipulation can lead to injection. This vulnerability appears as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-84656 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84656 | Jenkins Project Jenkins Plugin up to 2.567.x permission

A vulnerability, which was classified as problematic, was found in Jenkins Project Jenkins Plugin up to 2.567.x. This issue affects some unknown processing. Such manipulation leads to permission issues. This vulnerability is traded as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2024-44971 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44971 | Linux Kernel up to 6.10.4 bcm_sf2_mdio_register memory leak (Nessus ID 208425 / WID-SEC-2024-2057)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 5.10.223/5.15.164/6.1.104/6.6.45/6.10.4. The impacted element is the function bcm_sf2_mdio_register. Such manipulation leads to memory leak. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 20.6%
CVE-2024-44970 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44970 | Linux Kernel up to 6.1.104/6.6.45/6.10.4 mlx5_wq_ll_pop privilege escalation (Nessus ID 208425 / WID-SEC-2024-2057)

A vulnerability was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4. It has been declared as problematic. This affects the function mlx5_wq_ll_pop. Such manipulation leads to privilege escalation. This vulnerability is listed as CVE-2024-

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.5%
CVE-2024-44969 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44969 | Linux Kernel up to 6.10.4 buffer overflow (Nessus ID 208672 / WID-SEC-2024-2057)

A vulnerability was found in Linux Kernel up to 6.10.4. It has been rated as critical. The affected element is an unknown function. This manipulation causes buffer overflow. This vulnerability is registered as CVE-2024-44969. The attack req

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 27.6%
CVE-2024-44967 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44967 | Linux Kernel up to 6.1.104/6.6.45/6.10.4 mgag200 devm_add_action_or_reset privilege escalation (Nessus ID 212724 / WID-SEC-2024-2057)

A vulnerability classified as problematic was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4. This affects the function devm_add_action_or_reset of the component mgag200. Such manipulation leads to privilege escalation. This vulnerabilit

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 21.7%
CVE-2024-44968 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44968 | Linux Kernel up to 6.1.104/6.6.45/6.10.4/6.11-rc1 smp_processor_id privilege escalation (Nessus ID 208953 / WID-SEC-2024-2057)

A vulnerability was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4/6.11-rc1. It has been classified as problematic. The impacted element is the function smp_processor_id. This manipulation causes privilege escalation. This vulnerability

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.6%
CVE-2024-44966 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44966 | Linux Kernel up to 5.15.164/6.1.105/6.6.46/6.10.5 binfmt_flat initialization (Nessus ID 209056 / WID-SEC-2024-2057)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.164/6.1.105/6.6.46/6.10.5. This issue affects some unknown processing of the component binfmt_flat. Executing a manipulation can lead to improper initia

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.2%
CVE-2024-44965 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2024-44965 | Linux Kernel up to 6.10.4 pti_clone_pgtable stack-based overflow (Nessus ID 208953 / WID-SEC-2024-2057)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.10.4. Affected by this issue is the function pti_clone_pgtable. The manipulation results in stack-based buffer overflow. This vulnerability is reported as CVE-2024-4

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.1%
CVE-2026-18798 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18798 | OpenSSL up to 3.5.7/3.6.3/4.0.1 QUIC port_default_packet_handler double free (Nessus ID 345934 / WID-SEC-2026-3034)

A vulnerability was found in OpenSSL up to 3.5.7/3.6.3/4.0.1. It has been declared as critical. Affected by this issue is the function port_default_packet_handler of the component QUIC. Executing a manipulation can lead to double free. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 25.3%
CVE-2026-82232 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-82232 | Apache Syncope Task Search sort sql injection (CNNVD-2026-94660639)

A vulnerability, which was classified as critical, has been found in Apache Syncope. This issue affects some unknown processing of the component Task Search. This manipulation of the argument sort causes sql injection. This vulnerability is

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
8.2 HIGH
EPSS 25.8%
CVE-2026-55416 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55416 | Pimcore prior 11.5.19/12.3.10/2026.1.6 CustomReportsBundle Sql.php buildQueryString sql/from/where/groupby sql injection (CNNVD-2026-96012029)

A vulnerability has been found in Pimcore and classified as problematic. Affected by this vulnerability is the function Pimcore\Bundle\CustomReportsBundle\Tool\Adapter\Sql::buildQueryString of the file bundles/CustomReportsBundle/src/Tool/A

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.2%
CVE-2026-92008 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92008 | Mozilla Firefox up to 115.40/140.15/153.2/155 CanvasWebGL privileges management (Nessus ID 345908)

A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 115.40/140.15/153.2/155. This affects an unknown part of the component CanvasWebGL. The manipulation leads to improper privilege management. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-92007 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92007 | Mozilla Firefox up to 115.40/140.15/153.2/155 CanvasWebGL privileges management (Nessus ID 345908)

A vulnerability classified as critical was found in Mozilla Firefox up to 115.40/140.15/153.2/155. Affected by this issue is some unknown functionality of the component CanvasWebGL. Executing a manipulation can lead to improper privilege ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.5%
CVE-2026-92006 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92006 | Mozilla Firefox up to 115.40/140.15/153.2/155 CanvasWebGL privileges management (Nessus ID 345908)

A vulnerability classified as critical has been found in Mozilla Firefox up to 115.40/140.15/153.2/155. Affected by this vulnerability is an unknown functionality of the component CanvasWebGL. Performing a manipulation results in improper p

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-92005 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92005 | Mozilla Firefox up to 140.15/153.2/155 Web Codecs use after free (Nessus ID 345908)

A vulnerability described as critical has been identified in Mozilla Firefox up to 140.15/153.2/155. This affects an unknown part of the component Web Codecs. Executing a manipulation can lead to use after free. The identification of this v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-92073 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92073 | Mozilla Firefox up to 153.2/155 Enterprise Policies privileges management (Nessus ID 345908)

A vulnerability was found in Mozilla Firefox up to 153.2/155. It has been rated as critical. This impacts an unknown function of the component Enterprise Policies. This manipulation causes improper privilege management. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.7%
CVE-2022-44027 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44027 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46989)

A vulnerability categorized as problematic has been discovered in NetScout nGeniusONE up to 6.3.2 P9. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability is registered as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.1%
CVE-2022-44026 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44026 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46988)

A vulnerability was found in NetScout nGeniusONE up to 6.3.2 P9. It has been declared as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2022-44025 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44025 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46987)

A vulnerability was found in NetScout nGeniusONE up to 6.3.2 P9. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting. This vulnerability is tracked

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.5%
CVE-2022-44024 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44024 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46986)

A vulnerability was found in NetScout nGeniusONE up to 6.3.2 P9 and classified as problematic. Affected is an unknown function. The manipulation results in cross site scripting. This vulnerability is identified as CVE-2022-44024. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-91726 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91726 | Google Chrome up to 153.0.8010.36 WebGL out-of-bounds (EUVD-2026-79954)

A vulnerability categorized as critical has been discovered in Google Chrome. The affected element is an unknown function of the component WebGL. Such manipulation leads to out-of-bounds read. This vulnerability is uniquely identified as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.1%
CVE-2026-91717 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91717 | Google Chrome up to 153.0.8010.36 missing authentication (EUVD-2026-79971)

A vulnerability classified as problematic has been found in Google Chrome. This affects an unknown part. This manipulation causes missing authentication. This vulnerability is registered as CVE-2026-91717. The attack needs to be launched lo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-91735 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91735 | Google Chrome up to 153.0.8010.36 WebUI sandbox (EUVD-2026-79972)

A vulnerability classified as critical was found in Google Chrome. Affected by this issue is some unknown functionality of the component WebUI. Such manipulation leads to sandbox issue. This vulnerability is listed as CVE-2026-91735. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2026-91708 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91708 | Google Chrome up to 153.0.8010.36 Network race condition (EUVD-2026-79973)

A vulnerability, which was classified as problematic, was found in Google Chrome. Impacted is an unknown function of the component Network. Executing a manipulation can lead to race condition. This vulnerability appears as CVE-2026-91708. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-91740 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91740 | Google Chrome up to 153.0.8010.36 Skia uninitialized resource (EUVD-2026-79975)

A vulnerability was found in Google Chrome. It has been declared as problematic. Impacted is an unknown function of the component Skia. Such manipulation leads to uninitialized resource. This vulnerability is documented as CVE-2026-91740. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-91736 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91736 | Google Chrome up to 153.0.8010.36 DOM use after free (EUVD-2026-79974)

A vulnerability, which was classified as critical, was found in Google Chrome. This vulnerability affects unknown code of the component DOM. Executing a manipulation can lead to use after free. This vulnerability is registered as CVE-2026-9

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-91746 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-91746 | Google Chrome up to 153.0.8010.36 Compositing integer overflow (EUVD-2026-79979)

A vulnerability, which was classified as problematic, was found in Google Chrome. Affected by this issue is some unknown functionality of the component Compositing. Executing a manipulation can lead to integer overflow. This vulnerability i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.5%
CVE-2026-14199 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14199 | Grafana Enterprise/OSS up to 13.2.0 Auth Proxy privileges management (Nessus ID 342727 / WID-SEC-2026-3190)

A vulnerability classified as critical has been found in Grafana Enterprise and OSS up to 13.2.0. The impacted element is an unknown function of the component Auth Proxy. Performing a manipulation results in improper privilege management. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.6%
CVE-2026-63020 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63020 | F5 BIG-IP prior 17.1.3.4/17.5.1.8/21.0.0.3/21.1.0.1 Configuration Utility Page clickjacking

A vulnerability was found in F5 BIG-IP and classified as problematic. This vulnerability affects unknown code of the component Configuration Utility Page. Such manipulation leads to clickjacking. This vulnerability is uniquely identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.8%
CVE-2026-73750 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73750 | HPE AOS-CX up to 10.18.0001 Authentication access control

A vulnerability, which was classified as very critical, has been found in HPE AOS-CX up to 10.10.1180/10.13.1180/10.16.1051/10.17.1021/10.18.0001. Impacted is an unknown function of the component Authentication Module. The manipulation lead

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.1%
CVE-2026-52023 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52023 | Kamailio up to 6.1.1 ims_registrar_pcscf sec_agree.c parse_sec_agree denial of service (Nessus ID 342476)

A vulnerability labeled as problematic has been found in Kamailio up to 6.1.1. The impacted element is the function parse_sec_agree of the file sec_agree.c of the component ims_registrar_pcscf. Such manipulation leads to denial of service.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.6%
CVE-2026-61783 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61783 | Wazuh up to 4.14.6 RBAC ossec.conf mask_sensitive_config raw permission

A vulnerability, which was classified as problematic, has been found in Wazuh up to 4.14.6. This affects the function mask_sensitive_config of the file ossec.conf of the component RBAC. Performing a manipulation of the argument raw results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.1%
CVE-2026-75050 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75050 | JetBrains YouTrack allocation of resources

A vulnerability was found in JetBrains YouTrack and classified as critical. The impacted element is an unknown function. The manipulation results in allocation of resources. This vulnerability is reported as CVE-2026-75050. The attack can b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29%
CVE-2026-44901 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-44901 | Wazuh DAPI Protocol deserialization

A vulnerability, which was classified as very critical, has been found in Wazuh. Impacted is an unknown function of the component DAPI Protocol. This manipulation causes deserialization. This vulnerability is handled as CVE-2026-44901. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.3%
CVE-2025-65835 💻 Lokal 🔓 Keine Authentifizierung nötig
Google

CVE-2025-65835 | Cordova Plugin 6.0.4 on Android nl.xservices.plugins.ShareChooserPendingIntent denial of service

A vulnerability has been found in Cordova Plugin 6.0.4 on Android and classified as problematic. The affected element is an unknown function of the component nl.xservices.plugins.ShareChooserPendingIntent. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-66014 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66014 | JFrog Artifactory up to 7.161.14 privileges management

A vulnerability was found in JFrog Artifactory up to 7.161.14. It has been declared as critical. Impacted is an unknown function. Such manipulation leads to improper privilege management. This vulnerability is traded as CVE-2026-66014. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.6%
CVE-2026-12478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-12478 | Red Hat Linux 3.6.6 WebSocket Frame integer overflow

A vulnerability has been found in Red Hat Linux 3.6.6 and classified as critical. This issue affects some unknown processing of the component WebSocket Frame Handler. This manipulation causes integer overflow. This vulnerability appears as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.5%
CVE-2026-75501 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75501 | Calix EXOS up to 6.6.47 UPnP WANIPConnection service missing authentication (EUVD-2026-63988)

A vulnerability, which was classified as critical, has been found in Calix EXOS up to 6.6.47. Affected is an unknown function of the component UPnP WANIPConnection service. This manipulation causes missing authentication. The identification

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-76692 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-76692 | HPE EdgeConnect SD-WAN Gateways up to 9.4.8.2/9.5.8.1/9.6.3.1/9.7.0.0 missing initialization (EUVD-2026-79218)

A vulnerability was found in HPE EdgeConnect SD-WAN Gateways up to 9.4.8.2/9.5.8.1/9.6.3.1/9.7.0.0. It has been classified as critical. The affected element is an unknown function. Performing a manipulation results in missing initialization

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.1%
CVE-2026-55225 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-55225 | Strimzi Kafka Operator up to 1.0.0 Cluster Operator watchedNamespace privileges management (EUVD-2026-78883)

A vulnerability described as critical has been identified in Strimzi Kafka Operator up to 1.0.0. The impacted element is an unknown function of the component Cluster Operator. Such manipulation of the argument watchedNamespace leads to impr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.