🎯 CVE-2026-84933
📄 .md Alle CVEs anzeigen ✕

CVE-2026-84933: Schwachstellen-Eintrag (NVD)

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

Klassifikation & Betroffenheit:
nodejs undici *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8 (Commit) 🩹 5e541e0b9df7563e5766bbd469fbfe383d9ae6ca (Commit)
📰 Eigene Berichterstattung: ➔ CVE-2026-84933 | undici prior 7.29.1/8.10.2 Cache Interceptor information disclo
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 8.2
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Veröffentlicht:04.09.2026
Aktualisiert:15.09.2026 14:38
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 123 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.484 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-16
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 28.1%
CVE-2026-68772 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-68772 | ZenML up to 0.94.6 CloudpickleMaterializer cloudpickle_materializer.py cloudpickle.load deserialization

A vulnerability was found in ZenML up to 0.94.6. It has been rated as problematic. Impacted is the function cloudpickle.load of the file cloudpickle_materializer.py of the component CloudpickleMaterializer. Performing a manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-5855 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-5855 | Contiki-NG LwM2M TLV parser lwm2m-tlv.c lwm2m_tlv_read length out-of-bounds

A vulnerability, which was classified as very critical, has been found in Contiki-NG. This impacts the function lwm2m_tlv_read of the file os/services/lwm2m/lwm2m-tlv.c of the component LwM2M TLV parser. Performing a manipulation of the arg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.7%
CVE-2026-5856 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-5856 | Contiki-NG mDNS Resolver resolv.c skip_name out-of-bounds

A vulnerability was found in Contiki-NG. It has been classified as critical. This affects the function skip_name of the file os/services/resolv/resolv.c of the component mDNS Resolver. This manipulation causes out-of-bounds read. The identi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.1%
CVE-2026-53977 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53977 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Route bootstrap-runtime.js improper authentication

A vulnerability was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. It has been rated as critical. The affected element is an unknown function of the file bootstrap-runtime.js of the component Route Handler. The manipulation leads to i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.9%
CVE-2026-53975 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53975 | Bohdan Triapitsyn OpenChamber up to 1.11.7 Command Execution /api/fs/exec spawn os command injection

A vulnerability, which was classified as critical, was found in Bohdan Triapitsyn OpenChamber up to 1.11.7. This vulnerability affects the function spawn of the file /api/fs/exec of the component Command Execution. The manipulation results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-53976 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-53976 | Bohdan Triapitsyn OpenChamber up to 1.11.7 File Serving /api/fs/read resolveReadPathFromContext allowOutsideWorkspace path traversal

A vulnerability has been found in Bohdan Triapitsyn OpenChamber up to 1.11.7 and classified as critical. This issue affects the function resolveReadPathFromContext of the file /api/fs/read of the component File Serving. This manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-70617 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70617 | Spacebar Server Channels Recipient Endpoint authorization (dcfd910)

A vulnerability marked as critical has been reported in Spacebar Server. Affected by this vulnerability is an unknown functionality of the component Channels Recipient Endpoint. Performing a manipulation results in missing authorization. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-70618 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70618 | Spacebar Server Roles Member-Ids Endpoint improper authorization

A vulnerability classified as problematic has been found in Spacebar Server. This affects an unknown part of the component Roles Member-Ids Endpoint. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2022-4995 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-4995 | Weaver Network E-cology up to 10.51 uploaderOperate.jsp secId/plandetailid unrestricted upload

A vulnerability, which was classified as critical, has been found in Weaver Network E-cology up to 10.51. This issue affects some unknown processing of the file /workrelate/plan/util/uploaderOperate.jsp. The manipulation of the argument sec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2022-44193 💻 Lokal 🔓 Keine Authentifizierung nötig
Apache

CVE-2022-44193 | Netgear R7000P 1.3.1.64 /usr/sbin/httpd starthour/startminute /endhour/endminute buffer overflow (EUVD-2022-47143)

A vulnerability labeled as critical has been found in Netgear R7000P 1.3.1.64. This issue affects some unknown processing of the file /usr/sbin/httpd. Such manipulation of the argument starthour/startminute /endhour/endminute leads to buffe

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 21.4%
CVE-2022-44191 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44191 | Netgear R7000P 1.3.1.64 KEY1/KEY2 buffer overflow (EUVD-2022-47141)

A vulnerability identified as critical has been detected in Netgear R7000P 1.3.1.64. This vulnerability affects unknown code. This manipulation of the argument KEY1/KEY2 causes buffer overflow. This vulnerability is registered as CVE-2022-4

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2022-44190 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44190 | Netgear R7000P 1.3.1.64 enable_band_steering buffer overflow (EUVD-2022-47140)

A vulnerability categorized as critical has been discovered in Netgear R7000P 1.3.1.64. This affects an unknown part. The manipulation of the argument enable_band_steering results in buffer overflow. This vulnerability is cataloged as CVE-2

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2022-44188 💻 Lokal 🔓 Keine Authentifizierung nötig
Apache

CVE-2022-44188 | Netgear R7000P 1.3.0.8 /usr/sbin/httpd enable_band_steering buffer overflow (EUVD-2022-47138)

A vulnerability was found in Netgear R7000P 1.3.0.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /usr/sbin/httpd. The manipulation of the argument enable_band_steering leads to buffer over

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-69110 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69110 | Microck opencode-studio up to 2.4.3 missing authentication

A vulnerability categorized as critical has been discovered in Microck opencode-studio up to 2.4.3. Affected by this issue is some unknown functionality. The manipulation results in missing authentication. This vulnerability was named CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.5%
CVE-2026-69100 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-69100 | dromara lamp-cloud up to 5.6.2 GlueFactory os command injection

A vulnerability was found in dromara lamp-cloud up to 5.6.2. It has been declared as very critical. Affected is an unknown function of the component GlueFactory. Executing a manipulation can lead to os command injection. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2025-71399 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-71399 | better-auth Better Auth up to 1.4.4 Router privileges management (EUVD-2025-210590)

A vulnerability classified as critical has been found in better-auth Better Auth up to 1.4.4. This affects an unknown function of the component Router. The manipulation leads to improper privilege management. This vulnerability is traded as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-67326 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67326 | gitpython-developers GitPython up to 3.1.49 Config Writer config_writer section injection (EUVD-2026-51814 / Nessus ID 331643)

A vulnerability, which was classified as critical, was found in gitpython-developers GitPython up to 3.1.49. The impacted element is the function config_writer of the component Config Writer. Executing a manipulation of the argument section

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.8%
CVE-2026-67309 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67309 | Traefik up to 3.7.7 RewriteTarget Middleware path traversal (EUVD-2026-51815)

A vulnerability identified as critical has been detected in Traefik up to 3.7.7. Affected by this vulnerability is an unknown functionality of the component RewriteTarget Middleware. Performing a manipulation results in path traversal. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.5%
CVE-2026-20316 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20316 | Cisco Secure Firewall Management Center up to 10.0.1 Web Interface information disclosure (EUVD-2026-50404)

A vulnerability was found in Cisco Secure Firewall Management Center. It has been classified as problematic. Affected is an unknown function of the component Web Interface. Performing a manipulation results in information disclosure. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 29%
CVE-2026-92592 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92592 | craftcms Craft CMS up to 4.18.5/5.10.12 Twig template system redirect (EUVD-2026-81292)

A vulnerability identified as problematic has been detected in craftcms Craft CMS up to 4.18.5/5.10.12. The affected element is the function system of the component Twig template. The manipulation of the argument redirect leads to open redi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-92593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92593 | craftcms Craft CMS up to 5.10.12 Redirect renderObjectTemplate returnUrl/redirect special elements in template engine (EUVD-2026-81293)

A vulnerability was found in craftcms Craft CMS up to 5.10.12. It has been rated as critical. This issue affects the function View::renderObjectTemplate of the component Redirect Handler. Performing a manipulation of the argument returnUrl/

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-92594 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92594 | Craft CMS up to 5.10.x GraphQL Resolver Gql::canQueryUsers improper authorization (EUVD-2026-81294)

A vulnerability marked as problematic has been reported in Craft CMS up to 5.10.x. This vulnerability affects the function Gql::canQueryUsers of the component GraphQL Resolver. The manipulation leads to improper authorization. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2026-92595 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92595 | Nodemailer up to 9.1.0 Content Resolution MailMessage.resolveContent data/key/callback server-side request forgery (EUVD-2026-81295)

A vulnerability described as critical has been identified in Nodemailer up to 9.1.0. This issue affects the function MailMessage.resolveContent of the component Content Resolution. The manipulation of the argument data/key/callback results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-92597 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92597 | Nodemailer up to 9.0.x Addressparser lib/addressparser input validation (EUVD-2026-81297)

A vulnerability was found in Nodemailer up to 9.0.x. It has been classified as critical. This affects an unknown function of the file lib/addressparser of the component Addressparser. The manipulation leads to improper input validation. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-92596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92596 | Nodemailer up to 9.0.x Addressparser resource consumption (EUVD-2026-81296)

A vulnerability was found in Nodemailer up to 9.0.x and classified as problematic. The impacted element is an unknown function of the component Addressparser. Executing a manipulation can lead to resource consumption. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-92598 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92598 | Nodemailer up to 9.0.x Domain Resolver encoding error (EUVD-2026-81298)

A vulnerability labeled as critical has been found in Nodemailer up to 9.0.x. This affects an unknown part of the component Domain Resolver. Executing a manipulation can lead to encoding error. This vulnerability is handled as CVE-2026-9259

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.2%
CVE-2026-92599 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92599 | hapijs joi up to 17.13.6/18.0.0-18.2.5 isoDate Joi.string.isoDate redos (EUVD-2026-81299)

A vulnerability was found in hapijs joi up to 17.13.6/18.0.0-18.2.5. It has been declared as problematic. This impacts the function Joi.string.isoDate of the component isoDate. The manipulation results in inefficient regular expression comp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.3%
CVE-2026-73447 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73447 | Arista EOS up to 4.36.0.1F Certz service/Bootz service os command injection (WID-SEC-2026-3287)

A vulnerability was found in Arista EOS up to 4.36.0.1F and classified as very critical. The impacted element is an unknown function of the component Certz service/Bootz service. Such manipulation leads to os command injection. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2026-73446 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73446 | Arista EOS up to 4.36.1F Broadcast Interface resource consumption (WID-SEC-2026-3287)

A vulnerability classified as critical has been found in Arista EOS up to 4.36.1F. The impacted element is an unknown function of the component Broadcast Interface. Performing a manipulation results in resource consumption. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.9%
CVE-2026-73444 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73444 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP improper authentication (WID-SEC-2026-3287)

A vulnerability marked as very critical has been reported in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. Impacted is an unknown function of the component VRRP. The manipulation leads to improper authentication. This vulnerability is t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 23.2%
CVE-2026-73443 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73443 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP authentication replay (WID-SEC-2026-3287)

A vulnerability, which was classified as critical, has been found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This impacts an unknown function of the component VRRP. The manipulation leads to authentication bypass by capture-replay

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2026-73442 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73442 | Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP missing encryption (WID-SEC-2026-3287)

A vulnerability classified as problematic was found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This affects an unknown function of the component VRRP. Executing a manipulation can lead to missing encryption of sensitive data. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-73440 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73440 | Arista EOS up to 4.36.1F SNMP improper authorization (WID-SEC-2026-3287)

A vulnerability was found in Arista EOS up to 4.32.x/4.33.9M/4.34.7.1M/4.35.5M/4.36.1F. It has been declared as critical. This affects an unknown function of the component SNMP. The manipulation results in improper authorization. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.6%
CVE-2026-73437 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73437 | Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M/4.36.1F DHCP denial of service (WID-SEC-2026-3287)

A vulnerability labeled as very critical has been found in Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M/4.36.1F. This issue affects some unknown processing of the component DHCP Handler. Executing a manipulation can lead to denial of service.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.4%
CVE-2026-19655 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19655 | Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M DHCP Relay Service input validation (WID-SEC-2026-3287)

A vulnerability marked as critical has been reported in Arista EOS up to 4.33.9M/4.34.7.1M/4.35.5M. Affected by this issue is some unknown functionality of the component DHCP Relay Service. This manipulation causes improper input validation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2020-20212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-20212 | MikroTik RouterOS 6.44.5 /nova/bin/console null pointer dereference

A vulnerability described as problematic has been identified in MikroTik RouterOS 6.44.5. The impacted element is an unknown function of the file /nova/bin/console. Such manipulation leads to null pointer dereference. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.1%
CVE-2020-20211 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-20211 | MikroTik RouterOS 6.44.5 /nova/bin/console denial of service

A vulnerability marked as problematic has been reported in MikroTik RouterOS 6.44.5. The affected element is an unknown function of the file /nova/bin/console. This manipulation causes denial of service. This vulnerability appears as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.9%
CVE-2017-17537 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2017-17537 | MikroTik RouterBOARD 6.39.2/6.40.5 TCP Service 53 input validation (EDB-43200 / ID 860320)

A vulnerability was found in MikroTik RouterBOARD 6.39.2/6.40.5. It has been rated as problematic. This vulnerability affects unknown code of the component TCP Service 53. The manipulation leads to improper input validation. This vulnerabil

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2017-6297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2017-6297 | MikroTik RouterOS 6.37.4/6.83.3 L2TP Client IPsec 7pk security (BID-96447 / ID 103115)

A vulnerability categorized as critical has been discovered in MikroTik RouterOS 6.37.4/6.83.3. This affects an unknown part of the component L2TP Client. The manipulation results in 7pk security features (IPsec). This vulnerability was nam

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2023-27169 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-27169 | Xpand IT Write-Back Manager 2.3.1 hash predictable salt (EUVD-2023-30949)

A vulnerability marked as problematic has been reported in Xpand IT Write-Back Manager 2.3.1. This impacts an unknown function. Performing a manipulation results in use of a one-way hash with a predictable salt. This vulnerability was named

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.4%
CVE-2023-27170 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2023-27170 | Xpand IT Write-Back Manager 2.3.1 siteName path traversal (EUVD-2023-30950)

A vulnerability has been found in Xpand IT Write-Back Manager 2.3.1 and classified as critical. This issue affects some unknown processing. Performing a manipulation of the argument siteName results in path traversal. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2024-33668 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2024-33668 | Zammad up to 6.2.x Upload Cache excessive authentication

A vulnerability classified as problematic was found in Zammad up to 6.2.x. This affects an unknown part of the component Upload Cache. Executing a manipulation can lead to improper restriction of excessive authentication attempts. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2022-44187 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44187 | Netgear R7000P 1.3.0.8 wan_dns1_pri buffer overflow (EUVD-2022-47137)

A vulnerability was found in Netgear R7000P 1.3.0.8. It has been declared as critical. Affected by this vulnerability is the function wan_dns1_pri. Executing a manipulation can lead to buffer overflow. This vulnerability is tracked as CVE-2

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2022-44186 💻 Lokal 🔓 Keine Authentifizierung nötig
Apache

CVE-2022-44186 | Netgear R7000P 1.3.1.64 /usr/sbin/httpd wan_dns1_pri buffer overflow (EUVD-2022-47136)

A vulnerability was found in Netgear R7000P 1.3.1.64. It has been classified as critical. Affected is an unknown function of the file /usr/sbin/httpd. Performing a manipulation of the argument wan_dns1_pri results in buffer overflow. This v

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 19.4%
CVE-2022-44184 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2022-44184 | Netgear R7000P 1.3.0.8 /usr/sbin/httpd wan_dns1_sec buffer overflow (EUVD-2022-47134)

A vulnerability has been found in Netgear R7000P 1.3.0.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/httpd. Performing a manipulation of the argument wan_dns1_sec results in b

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 31.9%
CVE-2022-44183 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-44183 | Tenda AC18 15.03.05.19 formSetWifiGuestBasic buffer overflow (EUVD-2022-47133)

A vulnerability described as critical has been identified in Tenda AC18 15.03.05.19. Affected is the function formSetWifiGuestBasic. Executing a manipulation can lead to buffer overflow. The identification of this vulnerability is CVE-2022-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.9%
CVE-2026-85880 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-85880 | Microsoft Windows up to Server 2022 ALPC heap-based overflow (EUVD-2026-73365)

A vulnerability was found in Microsoft Windows up to Server 2022. It has been declared as very critical. The impacted element is an unknown function of the component ALPC. Such manipulation leads to heap-based buffer overflow. This vulnerab

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
5.8 MEDIUM
EPSS 3%
CVE-2026-61588 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61588 | djust-org djust up to 1.0.6 information disclosure (EUVD-2026-81304)

A vulnerability categorized as problematic has been discovered in djust-org djust up to 1.0.6. Affected by this vulnerability is an unknown functionality. Such manipulation leads to information disclosure. This vulnerability is traded as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.8%
CVE-2026-61589 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61589 | djust-org djust up to 1.0.6 Tenant Resolution ViewRuntime._build_request information disclosure (EUVD-2026-81306)

A vulnerability, which was classified as problematic, was found in djust-org djust up to 1.0.6. Impacted is the function ViewRuntime._build_request of the component Tenant Resolution. Such manipulation leads to information disclosure. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.2%
CVE-2026-61596 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61596 | djust-org djust up to 1.0.6 Render Entry Points get_object/has_object_permission authorization (EUVD-2026-81305)

A vulnerability, which was classified as critical, has been found in djust-org djust up to 1.0.6. This issue affects the function get_object/has_object_permission of the component Render Entry Points. This manipulation causes authorization

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-61599 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61599 | djust-org djust up to 1.0.6 Live Transport __import__ view input validation (EUVD-2026-81307)

A vulnerability classified as critical was found in djust-org djust up to 1.0.6. This vulnerability affects the function __import__ of the component Live Transport. The manipulation of the argument view results in improper input validation.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2026-57173 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-57173 | vllm-project vLLM up to 0.23.x Audio Decoder /v1/chat/completions AudioMediaIO.load_bytes resource consumption (EUVD-2026-80880)

A vulnerability, which was classified as problematic, has been found in vllm-project vLLM up to 0.23.x. This affects the function AudioMediaIO.load_bytes of the file /v1/chat/completions of the component Audio Decoder. Performing a manipula

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.6%
CVE-2026-59193 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-59193 | getgrav Grav up to 1.x ZIP Archive extractTo denial of service (EUVD-2026-42951)

A vulnerability identified as problematic has been detected in getgrav Grav up to 1.x. This affects the function extractTo of the component ZIP Archive Handler. The manipulation leads to denial of service. This vulnerability is documented a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.3%
CVE-2026-63128 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63128 | modelcontextprotocol rust-sdk up to 1.x Streamable HTTP Server tower.rs handle_post initialization (EUVD-2026-80823)

A vulnerability was found in modelcontextprotocol rust-sdk up to 1.x. It has been declared as problematic. This issue affects the function StreamableHttpService::handle_post of the file crates/rmcp/src/transport/streamable_http_server/tower

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2026-63127 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63127 | Model Context Protocol RMCP SDK up to 1.x OAuth Implementation auth.rs discover_oauth_server_via_resource_metadata improper authorization (EUVD-2026-80824)

A vulnerability classified as problematic was found in Model Context Protocol RMCP SDK up to 1.x. This impacts the function discover_oauth_server_via_resource_metadata of the file crates/rmcp/src/transport/auth.rs of the component OAuth Imp

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-63671 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-63671 | nuxt-content mdc up to 0.22.0 Sanitizer parseMarkdown allowDangerousHtml cross site scripting (EUVD-2026-80789)

A vulnerability, which was classified as problematic, has been found in nuxt-content mdc up to 0.22.0. The impacted element is the function parseMarkdown of the component Sanitizer. This manipulation of the argument allowDangerousHtml cause

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.2%
CVE-2026-61709 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-61709 | OpenFGA up to 1.18.0 ListUsers API list_users_rpc.go expandIntersection improper authorization (EUVD-2026-80777)

A vulnerability categorized as problematic has been discovered in OpenFGA up to 1.18.0. This affects the function expandIntersection of the file pkg/server/commands/listusers/list_users_rpc.go of the component ListUsers API. Executing a man

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.9%
CVE-2026-58657 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-58657 | Grav up to 2.0.0-rc.9 Media Action processMediaActions resize injection (EUVD-2026-42267)

A vulnerability labeled as problematic has been found in Grav up to 2.0.0-rc.9. This affects the function Excerpts::processMediaActions of the component Media Action Handler. The manipulation of the argument resize results in injection. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.5%
CVE-2026-65388 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65388 | Apple containerization up to 0.40.x information disclosure (EUVD-2026-81274)

A vulnerability classified as problematic has been found in Apple containerization up to 0.40.x. Impacted is an unknown function. This manipulation causes information disclosure. The identification of this vulnerability is CVE-2026-65388. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26%
CVE-2026-92802 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-92802 | kanbn kan up to 0.6.0 GitHub Project Import Endpoint improper authorization (EUVD-2026-81062)

A vulnerability identified as problematic has been detected in kanbn kan up to 0.6.0. This affects an unknown part of the component GitHub Project Import Endpoint. This manipulation causes improper authorization. This vulnerability is track

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.